Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1190 Exploit Public-Facing Application |
CampaignFLORAHOX Activity | FLORAHOX Activity has exploited and infected vulnerable routers to recruit additional network devices into the ORB. |
| T1195.002 Compromise Software Supply Chain |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus first compromised an “end-of-life" trading software application which was downloaded and executed inside the 3CX enterprise environment. The second compromise modified the Windows and macOS build environments used to distribute the 3CX software to their customer base. |
| T1195.002 Compromise Software Supply Chain |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software. |
| T1199 Trusted Relationship |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained access through compromised accounts at cloud solution partners, and used compromised certificates issued by Mimecast to authenticate to Mimecast customer systems. |
| T1201 Password Policy Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net accounts` command as part of their advanced reconnaissance. |
| T1203 Exploitation for Client Execution |
CampaignFrankenstein | During Frankenstein, the threat actors exploited CVE-2017-11882 to execute code on the victim's machine. |
| T1203 Exploitation for Client Execution |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used the GrimResource exploitation technique via specially crafted MSC files for arbitrary code execution during RedDelta Modified PlugX Infection Chain Operations. |
| T1203 Exploitation for Client Execution |
CampaignRedPenguin | During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution. |
| T1203 Exploitation for Client Execution |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors exploited Adobe Flash vulnerability CVE-2011-0611, Microsoft Windows Help vulnerability CVE-2010-1885, and several Internet Explorer vulnerabilities, including CVE-2011-1255, CVE-2012-1889, and CVE-2014-0322. |
| T1203 Exploitation for Client Execution |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website. |
| T1204 User Execution |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution requires users to interact with malicious attachments in order to start Pikabot installation. |
| T1204.001 Malicious Link |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access. |
| T1204.001 Malicious Link |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda distributed hyperlinks that would result in an MSC file running a PowerShell command to download and install a remotely-hosted MSI file during RedDelta Modified PlugX Infection Chain Operations. |
| T1204.001 Malicious Link |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors relied on a victim clicking on a malicious link sent via email. |
| T1204.001 Malicious Link |
CampaignOperation Spalax | During Operation Spalax, the threat actors relied on a victim to click on a malicious link distributed via phishing emails. |
| T1204.001 Malicious Link |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution distributed a PDF attachment containing a malicious link to a Pikabot installer. |
| T1204.001 Malicious Link |
CampaignC0021 | During C0021, the threat actors lured users into clicking a malicious link which led to the download of a ZIP archive containing a malicious .LNK file. |
| T1204.001 Malicious Link |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace lured users into executing malicious payloads with links to resources hosted on OneDrive. |
| T1204.001 Malicious Link |
CampaignNight Dragon | During Night Dragon, threat actors enticed users to click on links in spearphishing emails to download malware. |
| T1204.001 Malicious Link |
CampaignC0011 | During C0011, Transparent Tribe relied on student targets to click on a malicious link sent via email. |
| T1204.002 Malicious File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors. |
| T1204.002 Malicious File |
CampaignFrankenstein | During Frankenstein, the threat actors relied on a victim to enable macros within a malicious Microsoft Word document likely sent via email. |
| T1204.002 Malicious File |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda distributed malicious LNK objects for user execution during RedDelta Modified PlugX Infection Chain Operations. |
| T1204.002 Malicious File |
CampaignOperation Sharpshooter | During Operation Sharpshooter, the threat actors relied on victims executing malicious Microsoft Word or PDF files. |
| T1204.002 Malicious File |
CampaignOperation Honeybee | During Operation Honeybee, threat actors relied on a victim to enable macros within a malicious Word document. |
| T1204.002 Malicious File |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors relied on potential victims to open a malicious Microsoft Word document sent via email. |
| T1204.002 Malicious File |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them. |
| T1204.002 Malicious File |
CampaignOperation Spalax | During Operation Spalax, the threat actors relied on a victim to open a PDF document and click on an embedded malicious link to download malware. |
| T1204.002 Malicious File |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution delivered Pikabot installers as password-protected ZIP files containing heavily obfuscated JavaScript, or IMG files containing an LNK mimicking a Word document and a malicious DLL. |
| T1204.002 Malicious File |
CampaignC0015 | During C0015, the threat actors relied on users to enable macros within a malicious Microsoft Word document. |
| T1204.002 Malicious File |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace lured victims into executing malicious payloads by opening email attachments. |
| T1204.002 Malicious File |
CampaignC0011 | During C0011, Transparent Tribe relied on a student target to open a malicious document delivered via email. |
| T1205 Traffic Signaling |
CampaignRedPenguin | During RedPenguin, UNC3886 leveraged malware capable of inpecting packets for a magic-string to activate backdoor functionalities. |
| T1205 Traffic Signaling |
CampaignCutting Edge | During Cutting Edge, threat actors sent a magic 48-byte sequence to enable the PITSOCK backdoor to communicate via the `/tmp/clientsDownload.sock` socket. |
| T1212 Exploitation for Credential Access |
CampaignLeviathan Australian Intrusions | Leviathan exploited vulnerable network appliances during Leviathan Australian Intrusions, leading to the collection and exfiltration of valid credentials. |
| T1213 Data from Information Repositories |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 accessed victims' internal knowledge repositories (wikis) to view sensitive corporate information on products, services, and internal business operations. |
| T1213.002 Sharepoint |
CampaignC0027 | During C0027, Scattered Spider accessed victim SharePoint environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides. |
| T1213.003 Code Repositories |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 downloaded source code from code repositories. |
| T1213.004 Customer Relationship Management Software |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors accessed and exfiltrated sensitive information from compromised Salesforce instances. |
| T1213.006 Databases |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal databases and systems to extract proprietary information, system configurations, and sensitive operational data. |
| T1213.006 Databases |
CampaignAPT41 DUST | APT41 DUST collected data from victim Oracle databases using SQLULDR2. |
| T1213.006 Databases |
CampaignLeviathan Australian Intrusions | Leviathan gathered information from SQL servers and Building Management System (BMS) servers during Leviathan Australian Intrusions. |
| T1217 Browser Information Discovery |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leveraged ICONICSTEALER to steal browser information to include browser history located on the infected host. |
| T1217 Browser Information Discovery |
CampaignJuicy Mix | During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) data stealers to collect cookies, browsing history, and credentials. |
| T1217 Browser Information Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace exported Chrome web data including contact information, keywords, autofill data, and stored credit card information. |
| T1217 Browser Information Discovery |
CampaignOuter Space | During Outer Space, OilRig used a Chrome data dumper named MKG. |
| T1218.005 Mshta |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors executed JavaScript code via `mshta.exe`. |
| T1218.005 Mshta |
CampaignC0015 | During C0015, the threat actors used `mshta` to execute DLLs. |
| T1218.007 Msiexec |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda initial payloads downloaded a Windows Installer MSI file that in turn dropped follow-on files leading to installation of PlugX during RedDelta Modified PlugX Infection Chain Operations. |
| T1218.007 Msiexec |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus delivered components using a Windows Installer package (.msi). The MSI installer extracted several files and executed the 3CXDesktopApp.exe, which loaded the malicious library file ffmpeg.dll. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.