Real-world descriptions of how a group, tool or campaign used a technique.
64 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1578.002 Create Cloud Instance |
GroupScattered Spider | Scattered Spider has created Amazon EC2 instances within the victim's environment. |
| T1580 Cloud Infrastructure Discovery |
GroupScattered Spider | Scattered Spider enumerates cloud environments including Amazon Web Services (AWS) S3 buckets to identify server and backup management infrastructure, resource access, databases and storage containers . |
| T1583.001 Domains |
GroupScattered Spider | Scattered Spider has registered domains to spoof legitimate corporate login portals. |
| T1585.001 Social Media Accounts |
GroupScattered Spider | Scattered Spider has created matching fake social media profiles to support new accounts created in victim environments. |
| T1588.001 Malware |
GroupScattered Spider | Scattered Spider has obtained malware to use at multiple stages of operations including information stealers, remote access tools, and ransomware. |
| T1588.002 Tool |
GroupScattered Spider | Scattered Spider has obtained tools for use throughout the attack lifecycle to include remote access software, protocol tunneling and proxy tools, exploitation frameworks, and reconnaissance tools. |
| T1589 Gather Victim Identity Information |
GroupScattered Spider | Scattered Spider has used information from previous data breaches to identify employee names to be used in social engineering. |
| T1598 Phishing for Information |
GroupScattered Spider | Scattered Spider has used a combination of credential phishing and social engineering to capture one-time-password (OTP) codes. |
| T1598.003 Spearphishing Link |
GroupScattered Spider | Scattered Spider has used domains mirroring corporate login portals to socially engineer victims into providing credentials. |
| T1598.004 Spearphishing Voice |
GroupScattered Spider | Scattered Spider has used help desk voice-based phishing and also called employees at target organizations and compelled them to navigate to fake login portals using adversary-in-the-middle toolkits. |
| T1621 Multi-Factor Authentication Request Generation |
GroupScattered Spider | Scattered Spider has used multifactor authentication (MFA) fatigue by sending repeated MFA authentication requests to targets. |
| T1657 Financial Theft |
GroupScattered Spider | Scattered Spider has deployed ransomware on compromised hosts and threatened to leak stolen data for financial gain. |
| T1684.001 Impersonation |
GroupScattered Spider | Scattered Spider utilized social engineering to compel IT help desk personnel to reset passwords and MFA tokens. Scattered Spider has also used Microsoft Teams to pose as internal IT support or help desk personnel. |
| T1685 Disable or Modify Tools |
GroupScattered Spider | Scattered Spider has uninstalled and disabled security tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.