ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1074.001
Local Data Staging
MalwareSLOWPULSE

SLOWPULSE can write logged ACE credentials to `/home/perl/PAUS.pm` in append mode, using the format string `%s:%s\n`.

T1074.001
Local Data Staging
MalwareADVSTORESHELL

ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory.

T1074.001
Local Data Staging
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has created a staging file in `/tmp` for collected data.

T1074.001
Local Data Staging
MalwareDuqu

Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it.

T1074.002
Remote Data Staging
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 staged data and files in password-protected archives on a victim's OWA server.

T1074.002
Remote Data Staging
CampaignNight Dragon

During Night Dragon, threat actors copied files to company web servers and subsequently downloaded them.

T1074.002
Remote Data Staging
GroupmenuPass

menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration.

T1074.002
Remote Data Staging
GroupFIN6

FIN6 actors have compressed data from remote systems and moved it to another staging system before exfiltration.

T1074.002
Remote Data Staging
GroupSea Turtle

Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet.

T1074.002
Remote Data Staging
GroupLeviathan

Leviathan has staged data remotely prior to exfiltration.

T1074.002
Remote Data Staging
GroupMoustachedBouncer

MoustachedBouncer has used plugins to save captured screenshots to `.\AActdata\` on an SMB share.

T1074.002
Remote Data Staging
GroupChimera

Chimera has staged stolen data on designated servers in the target environment.

T1074.002
Remote Data Staging
GroupMirrorFace

MirrorFace has gathered data and files of interest on a single victim machine.

T1074.002
Remote Data Staging
GroupToddyCat

ToddyCat manually transferred collected files to an exfiltration host using xcopy.

T1074.002
Remote Data Staging
GroupAPT28

APT28 has staged archives of collected data on a target's Outlook Web Access (OWA) server.

T1074.002
Remote Data Staging
GroupThreat Group-3390

Threat Group-3390 has moved staged encrypted archives to Internet-facing servers that had previously been compromised with China Chopper prior to exfiltration.

T1074.002
Remote Data Staging
GroupFIN8

FIN8 aggregates staged data from a network into a single location.

T1074.002
Remote Data Staging
Malwareccf32

ccf32 has copied files to a remote machine infected with Chinoxy or another backdoor.

T1078
Valid Accounts
CampaignRedPenguin

During RedPenguin, UNC3886 used legitimate credentials to gain priviliged access to Juniper routers.

T1078
Valid Accounts
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks.

T1078
Valid Accounts
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used valid accounts on the corporate network to escalate privileges, move laterally, and establish persistence within the corporate network.

T1078
Valid Accounts
Campaign3CX Supply Chain Attack

During 3CX Supply Chain Attack, AppleJeus has gained access to the 3CX corporate environment through legitimate VPN credentials.

T1078
Valid Accounts
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used harvested credentials to authenticate against internal APIs, database systems, container registries, and logging infrastructure across targeted networks.

T1078
Valid Accounts
CampaignHomeLand Justice

During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts.

T1078
Valid Accounts
CampaignC0032

During the C0032 campaign, TEMP.Veles used compromised VPN accounts.

T1078
Valid Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally.

T1078
Valid Accounts
CampaignNight Dragon

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.

T1078
Valid Accounts
CampaignOperation Wocao

During Operation Wocao, threat actors used valid VPN credentials to gain initial access.

T1078
Valid Accounts
CampaignLeviathan Australian Intrusions

Leviathan used captured, valid account information to log into victim web applications and appliances during Leviathan Australian Intrusions.

T1078
Valid Accounts
GroupIndrik Spider

Indrik Spider has used valid accounts for initial access and lateral movement. Indrik Spider has also maintained access to the victim environment through the VPN infrastructure.

T1078
Valid Accounts
GroupBlackByte

BlackByte has gained access to victim environments through legitimate VPN credentials.

T1078
Valid Accounts
GroupGALLIUM

GALLIUM leveraged valid accounts to maintain access to a victim network.

T1078
Valid Accounts
GroupVolt Typhoon

Volt Typhoon relies primarily on valid credentials for persistence.

T1078
Valid Accounts
GroupAPT41

APT41 used compromised credentials to log on to other systems.

T1078
Valid Accounts
GroupDragonfly

Dragonfly has compromised user credentials and used valid accounts for operations.

T1078
Valid Accounts
GroupmenuPass

menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments.

T1078
Valid Accounts
GroupFIN6

To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes.

T1078
Valid Accounts
GroupFIN7

FIN7 has harvested valid administrative credentials for lateral movement.

T1078
Valid Accounts
GroupSandworm Team

Sandworm Team have used previously acquired legitimate credentials prior to attacks.

T1078
Valid Accounts
GroupAPT18

APT18 actors leverage legitimate credentials to log into external remote services.

T1078
Valid Accounts
GroupScattered Spider

Scattered Spider has used compromised credentials for initial access.

T1078
Valid Accounts
GroupAPT39

APT39 has used stolen credentials to compromise Outlook Web Access (OWA).

T1078
Valid Accounts
GroupUNC3886

UNC3886 has used tools to hijack valid SSH accounts.

T1078
Valid Accounts
GroupAkira

Akira uses valid account information to remotely access victim networks, such as VPN credentials.

T1078
Valid Accounts
GroupOilRig

OilRig has used compromised credentials to access other systems on a victim network.

T1078
Valid Accounts
GroupCarbanak

Carbanak actors used legitimate credentials of banking employees to perform operations that sent them millions of dollars.

T1078
Valid Accounts
GroupSea Turtle

Sea Turtle used compromised credentials to maintain long-term access to victim environments.

T1078
Valid Accounts
GroupSuckfly

Suckfly used legitimate account credentials that they dumped to navigate the internal victim network as though they were the legitimate account owner.

T1078
Valid Accounts
GroupPOLONIUM

POLONIUM has used valid compromised credentials to gain access to victim environments.

T1078
Valid Accounts
GroupKe3chang

Ke3chang has used credential dumpers or stealers to obtain legitimate credentials, which they used to gain access to victim accounts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.