ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1190
Exploit Public-Facing Application
CampaignFLORAHOX Activity

FLORAHOX Activity has exploited and infected vulnerable routers to recruit additional network devices into the ORB.

T1195.002
Compromise Software Supply Chain
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus first compromised an “end-of-life" trading software application which was downloaded and executed inside the 3CX enterprise environment. The second compromise modified the Windows and macOS build environments used to distribute the 3CX software to their customer base.

T1195.002
Compromise Software Supply Chain
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software.

T1199
Trusted Relationship
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained access through compromised accounts at cloud solution partners, and used compromised certificates issued by Mimecast to authenticate to Mimecast customer systems.

T1201
Password Policy Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net accounts` command as part of their advanced reconnaissance.

T1203
Exploitation for Client Execution
CampaignFrankenstein

During Frankenstein, the threat actors exploited CVE-2017-11882 to execute code on the victim's machine.

T1203
Exploitation for Client Execution
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used the GrimResource exploitation technique via specially crafted MSC files for arbitrary code execution during RedDelta Modified PlugX Infection Chain Operations.

T1203
Exploitation for Client Execution
CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution.

T1203
Exploitation for Client Execution
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors exploited Adobe Flash vulnerability CVE-2011-0611, Microsoft Windows Help vulnerability CVE-2010-1885, and several Internet Explorer vulnerabilities, including CVE-2011-1255, CVE-2012-1889, and CVE-2014-0322.

T1203
Exploitation for Client Execution
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website.

T1204
User Execution
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution requires users to interact with malicious attachments in order to start Pikabot installation.

T1204.001
Malicious Link
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access.

T1204.001
Malicious Link
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda distributed hyperlinks that would result in an MSC file running a PowerShell command to download and install a remotely-hosted MSI file during RedDelta Modified PlugX Infection Chain Operations.

T1204.001
Malicious Link
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors relied on a victim clicking on a malicious link sent via email.

T1204.001
Malicious Link
CampaignOperation Spalax

During Operation Spalax, the threat actors relied on a victim to click on a malicious link distributed via phishing emails.

T1204.001
Malicious Link
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution distributed a PDF attachment containing a malicious link to a Pikabot installer.

T1204.001
Malicious Link
CampaignC0021

During C0021, the threat actors lured users into clicking a malicious link which led to the download of a ZIP archive containing a malicious .LNK file.

T1204.001
Malicious Link
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace lured users into executing malicious payloads with links to resources hosted on OneDrive.

T1204.001
Malicious Link
CampaignNight Dragon

During Night Dragon, threat actors enticed users to click on links in spearphishing emails to download malware.

T1204.001
Malicious Link
CampaignC0011

During C0011, Transparent Tribe relied on student targets to click on a malicious link sent via email.

T1204.002
Malicious File
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors.

T1204.002
Malicious File
CampaignFrankenstein

During Frankenstein, the threat actors relied on a victim to enable macros within a malicious Microsoft Word document likely sent via email.

T1204.002
Malicious File
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda distributed malicious LNK objects for user execution during RedDelta Modified PlugX Infection Chain Operations.

T1204.002
Malicious File
CampaignOperation Sharpshooter

During Operation Sharpshooter, the threat actors relied on victims executing malicious Microsoft Word or PDF files.

T1204.002
Malicious File
CampaignOperation Honeybee

During Operation Honeybee, threat actors relied on a victim to enable macros within a malicious Word document.

T1204.002
Malicious File
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors relied on potential victims to open a malicious Microsoft Word document sent via email.

T1204.002
Malicious File
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them.

T1204.002
Malicious File
CampaignOperation Spalax

During Operation Spalax, the threat actors relied on a victim to open a PDF document and click on an embedded malicious link to download malware.

T1204.002
Malicious File
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution delivered Pikabot installers as password-protected ZIP files containing heavily obfuscated JavaScript, or IMG files containing an LNK mimicking a Word document and a malicious DLL.

T1204.002
Malicious File
CampaignC0015

During C0015, the threat actors relied on users to enable macros within a malicious Microsoft Word document.

T1204.002
Malicious File
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace lured victims into executing malicious payloads by opening email attachments.

T1204.002
Malicious File
CampaignC0011

During C0011, Transparent Tribe relied on a student target to open a malicious document delivered via email.

T1205
Traffic Signaling
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged malware capable of inpecting packets for a magic-string to activate backdoor functionalities.

T1205
Traffic Signaling
CampaignCutting Edge

During Cutting Edge, threat actors sent a magic 48-byte sequence to enable the PITSOCK backdoor to communicate via the `/tmp/clientsDownload.sock` socket.

T1212
Exploitation for Credential Access
CampaignLeviathan Australian Intrusions

Leviathan exploited vulnerable network appliances during Leviathan Australian Intrusions, leading to the collection and exfiltration of valid credentials.

T1213
Data from Information Repositories
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 accessed victims' internal knowledge repositories (wikis) to view sensitive corporate information on products, services, and internal business operations.

T1213.002
Sharepoint
CampaignC0027

During C0027, Scattered Spider accessed victim SharePoint environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides.

T1213.003
Code Repositories
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 downloaded source code from code repositories.

T1213.004
Customer Relationship Management Software
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors accessed and exfiltrated sensitive information from compromised Salesforce instances.

T1213.006
Databases
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal databases and systems to extract proprietary information, system configurations, and sensitive operational data.

T1213.006
Databases
CampaignAPT41 DUST

APT41 DUST collected data from victim Oracle databases using SQLULDR2.

T1213.006
Databases
CampaignLeviathan Australian Intrusions

Leviathan gathered information from SQL servers and Building Management System (BMS) servers during Leviathan Australian Intrusions.

T1217
Browser Information Discovery
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leveraged ICONICSTEALER to steal browser information to include browser history located on the infected host.

T1217
Browser Information Discovery
CampaignJuicy Mix

During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) data stealers to collect cookies, browsing history, and credentials.

T1217
Browser Information Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace exported Chrome web data including contact information, keywords, autofill data, and stored credit card information.

T1217
Browser Information Discovery
CampaignOuter Space

During Outer Space, OilRig used a Chrome data dumper named MKG.

T1218.005
Mshta
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors executed JavaScript code via `mshta.exe`.

T1218.005
Mshta
CampaignC0015

During C0015, the threat actors used `mshta` to execute DLLs.

T1218.007
Msiexec
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda initial payloads downloaded a Windows Installer MSI file that in turn dropped follow-on files leading to installation of PlugX during RedDelta Modified PlugX Infection Chain Operations.

T1218.007
Msiexec
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus delivered components using a Windows Installer package (.msi). The MSI installer extracted several files and executed the 3CXDesktopApp.exe, which loaded the malicious library file ffmpeg.dll.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.