ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1218.010
Regsvr32
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used `regsvr32` to execute malware.

T1218.010
Regsvr32
CampaignC0015

During C0015, the threat actors employed code that used `regsvr32` for execution.

T1218.011
Rundll32
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`.

T1218.011
Rundll32
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used a backdoor which could execute a supplied DLL using `rundll32.exe`.

T1218.011
Rundll32
CampaignOperation Spalax

During Operation Spalax, the threat actors used `rundll32.exe` to execute malicious installers.

T1218.011
Rundll32
CampaignC0018

During C0018, the threat actors used `rundll32` to run Mimikatz.

T1218.011
Rundll32
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution utilizes rundll32.exe to execute the final Pikabot payload, using the named exports `Crash` or `Limit` depending on the variant.

T1218.011
Rundll32
CampaignC0021

During C0021, the threat actors used `rundll32.exe` to execute the Cobalt Strike Beacon loader DLL.

T1218.011
Rundll32
CampaignC0015

During C0015, the threat actors loaded DLLs via `rundll32` using the `svchost` process.

T1218.011
Rundll32
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads.

T1218.014
MMC
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used Microsoft Management Console Snap-In Control files, or MSC files, executed via MMC to run follow-on PowerShell commands during RedDelta Modified PlugX Infection Chain Operations.

T1218.015
Electron Applications
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leveraged the 3CX application's electron framework to execute its malicious libraries under the official 3CX electron application.

T1219
Remote Access Tools
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used remote access tools including PuTTY.

T1219
Remote Access Tools
CampaignNight Dragon

During Night Dragon, threat actors used several remote administration tools as persistent infiltration channels.

T1219.001
IDE Tunneling
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors created Visual Studio Code dev tunnels to access targeted endpoints through the browser-based version of Visual Studio Code.

T1219.001
IDE Tunneling
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace abused Visual Studio Code (VS Code) remote tunnels to gain access and execute code on compromised machines.

T1219.002
Remote Desktop Software
CampaignC0018

During C0018, the threat actors used AnyDesk to transfer tools between systems.

T1219.002
Remote Desktop Software
CampaignC0015

During C0015, the threat actors installed the AnyDesk remote desktop application onto the compromised network.

T1219.002
Remote Desktop Software
CampaignC0027

During C0027, Scattered Spider directed victims to run remote monitoring and management (RMM) tools.

T1220
XSL Script Processing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used a remote XSL script to download a Base64-encoded DLL custom downloader.

T1221
Template Injection
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used DOCX files to retrieve a malicious document template/DOTM file.

T1221
Template Injection
CampaignFrankenstein

During Frankenstein, the threat actors used trojanized documents that retrieved remote templates from an adversary-controlled website.

T1222.002
Linux and Mac Permissions
CampaignKV Botnet Activity

KV Botnet Activity altered permissions on downloaded tools and payloads to enable execution on victim machines.

T1480
Execution Guardrails
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda included the use of Cloudflare geofencing mechanisms to limit payload download activity during RedDelta Modified PlugX Infection Chain Operations.

T1482
Domain Trust Discovery
CampaignC0015

During C0015, the threat actors used the command `nltest /domain_trusts /all_trusts` to enumerate domain trusts.

T1482
Domain Trust Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains.

T1482
Domain Trust Discovery
CampaignLeviathan Australian Intrusions

Leviathan performed Active Directory enumeration of victim environments during Leviathan Australian Intrusions.

T1484.001
Group Policy Modification
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, modified group policy to enable ransomware distribution.

T1484.001
Group Policy Modification
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had leveraged Group Policy Objects to distribute wiper malware to victim devices through a network share.

T1484.001
Group Policy Modification
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Group Policy Objects (GPOs) to deploy and execute malware.

T1484.002
Trust Modification
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 changed domain federation trust settings using Azure AD administrative permissions to configure the domain to accept authorization tokens signed by their own SAML signing certificate.

T1485
Data Destruction
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized wiper malware to overwrite files using a 16-byte buffer that fully overwrites files 16 bytes or smaller or partially overwrites files greater than 16 bytes to speed up the process.

T1485
Data Destruction
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed CaddyWiper on the victim’s IT environment systems to wipe files related to the OT capabilities, along with mapped drives, and physical drive partitions.

T1486
Data Encrypted for Impact
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors deployed ransomware including 4L4MD4R and Warlock.

T1486
Data Encrypted for Impact
CampaignC0018

During C0018, the threat actors used AvosLocker ransomware to encrypt files on the compromised network.

T1486
Data Encrypted for Impact
CampaignC0015

During C0015, the threat actors used Conti ransomware to encrypt a compromised network.

T1486
Data Encrypted for Impact
CampaignHomeLand Justice

During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems.

T1490
Inhibit System Recovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries deleted Windows Volume Shadow Copies using `vssadmin delete shadows`.

T1495
Firmware Corruption
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, adversaries performed a factory-reset on compromised devices that hampered forensic investigations.

T1496.001
Compute Hijacking
CampaignShadowRay

During ShadowRay, threat actors leveraged graphics processing units (GPU) on compromised nodes for cryptocurrency mining.

T1497
Virtualization/Sandbox Evasion
CampaignOperation Spalax

During Operation Spalax, the threat actors used droppers that would run anti-analysis checks before executing malware on a compromised host.

T1497.001
System Checks
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that conducted a variety of system checks to detect sandboxes or VMware services.

T1497.001
System Checks
CampaignFrankenstein

During Frankenstein, the threat actors used a script that ran WMI queries to check if a VM or sandbox was running, including VMWare and Virtualbox. The script would also call WMI to determine the number of cores allocated to the system; if less than two the script would stop execution.

T1497.003
Time Based Checks
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that collected `GetTickCount` and `GetSystemTimeAsFileTime` data to detect sandbox or VMware services.

T1505.001
SQL Stored Procedures
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used various MS-SQL stored procedures.

T1505.003
Web Shell
CampaignFrostyGoop Incident

FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence.

T1505.003
Web Shell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access.

T1505.003
Web Shell
CampaignCutting Edge

During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING.

T1505.003
Web Shell
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access.

T1505.003
Web Shell
CampaignHomeLand Justice

For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.