ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1015×

64 examples

TechniqueUsed byProcedure example
T1578.002
Create Cloud Instance
GroupScattered Spider

Scattered Spider has created Amazon EC2 instances within the victim's environment.

T1580
Cloud Infrastructure Discovery
GroupScattered Spider

Scattered Spider enumerates cloud environments including Amazon Web Services (AWS) S3 buckets to identify server and backup management infrastructure, resource access, databases and storage containers .

T1583.001
Domains
GroupScattered Spider

Scattered Spider has registered domains to spoof legitimate corporate login portals.

T1585.001
Social Media Accounts
GroupScattered Spider

Scattered Spider has created matching fake social media profiles to support new accounts created in victim environments.

T1588.001
Malware
GroupScattered Spider

Scattered Spider has obtained malware to use at multiple stages of operations including information stealers, remote access tools, and ransomware.

T1588.002
Tool
GroupScattered Spider

Scattered Spider has obtained tools for use throughout the attack lifecycle to include remote access software, protocol tunneling and proxy tools, exploitation frameworks, and reconnaissance tools.

T1589
Gather Victim Identity Information
GroupScattered Spider

Scattered Spider has used information from previous data breaches to identify employee names to be used in social engineering.

T1598
Phishing for Information
GroupScattered Spider

Scattered Spider has used a combination of credential phishing and social engineering to capture one-time-password (OTP) codes.

T1598.003
Spearphishing Link
GroupScattered Spider

Scattered Spider has used domains mirroring corporate login portals to socially engineer victims into providing credentials.

T1598.004
Spearphishing Voice
GroupScattered Spider

Scattered Spider has used help desk voice-based phishing and also called employees at target organizations and compelled them to navigate to fake login portals using adversary-in-the-middle toolkits.

T1621
Multi-Factor Authentication Request Generation
GroupScattered Spider

Scattered Spider has used multifactor authentication (MFA) fatigue by sending repeated MFA authentication requests to targets.

T1657
Financial Theft
GroupScattered Spider

Scattered Spider has deployed ransomware on compromised hosts and threatened to leak stolen data for financial gain.

T1684.001
Impersonation
GroupScattered Spider

Scattered Spider utilized social engineering to compel IT help desk personnel to reset passwords and MFA tokens. Scattered Spider has also used Microsoft Teams to pose as internal IT support or help desk personnel.

T1685
Disable or Modify Tools
GroupScattered Spider

Scattered Spider has uninstalled and disabled security tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.