Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareGlassWorm | GlassWorm has spread through Visual Studio extensions. GlassWorm has also spread through JavaScript projects hosted on Github. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareShai-Hulud | Shai-Hulud has published itself on compromised code repository maintainers within infected packages in attempts to propagate to other victims. Shai-Hulud has also modified versions of code packages. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareXCSSET | XCSSET adds malicious code to a host's Xcode projects by enumerating CocoaPods |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareMini Shai-Hulud | Mini Shai-Hulud has published itself on compromised victim code repositories to propagate malicious versions of packages to other victims. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareCanisterWorm | CanisterWorm has spread through an automated process that infects and publishes npm packages. |
| T1195.002 Compromise Software Supply Chain |
MalwareCCBkdr | CCBkdr was added to a legitimate, signed version 5.33 of the CCleaner software and distributed on CCleaner's distribution site. |
| T1195.002 Compromise Software Supply Chain |
MalwareGoldenSpy | GoldenSpy has been packaged with a legitimate tax preparation software. |
| T1195.002 Compromise Software Supply Chain |
MalwareSUNSPOT | SUNSPOT malware was designed and used to insert SUNBURST into software builds of the SolarWinds Orion IT management product. |
| T1197 BITS Jobs |
MalwareProLock | ProLock can use BITS jobs to download its malicious payload. |
| T1197 BITS Jobs |
MalwareUBoatRAT | UBoatRAT takes advantage of the /SetNotifyCmdLine option in BITSAdmin to ensure it stays running on a system to maintain persistence. |
| T1197 BITS Jobs |
MalwareMarkiRAT | MarkiRAT can use BITS Utility to connect with the C2 server. |
| T1197 BITS Jobs |
MalwareBazar | Bazar has been downloaded via Windows BITS functionality. |
| T1197 BITS Jobs |
MalwareCobalt Strike | Cobalt Strike can download a hosted "beacon" payload using BITSAdmin. |
| T1197 BITS Jobs |
MalwareEgregor | Egregor has used BITSadmin to download and execute malicious DLLs. |
| T1197 BITS Jobs |
MalwareJPIN | A JPIN variant downloads the backdoor payload via the BITS service. |
| T1197 BITS Jobs |
ToolBITSAdmin | BITSAdmin can be used to create BITS Jobs to launch a malicious process. |
| T1201 Password Policy Discovery |
MalwareKwampirs | Kwampirs collects password policy information with the command |
| T1201 Password Policy Discovery |
ToolNet | The |
| T1201 Password Policy Discovery |
ToolPoshC2 | PoshC2 can use |
| T1201 Password Policy Discovery |
ToolCrackMapExec | CrackMapExec can discover the password policies applied to the target system. |
| T1202 Indirect Command Execution |
MalwareRevenge RAT | Revenge RAT uses the Forfiles utility to execute commands on the system. |
| T1202 Indirect Command Execution |
ToolForfiles | Forfiles can be used to subvert controls and possibly conceal command execution by not directly invoking cmd. |
| T1203 Exploitation for Client Execution |
MalwareVersaMem | VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers. |
| T1203 Exploitation for Client Execution |
MalwareHAWKBALL | HAWKBALL has exploited Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2018-0802 to deliver the payload. |
| T1203 Exploitation for Client Execution |
MalwareBankshot | Bankshot leverages a known zero-day vulnerability in Adobe Flash to execute the implant into the victims’ machines. |
| T1203 Exploitation for Client Execution |
MalwareWoody RAT | Woody RAT has relied on CVE-2022-30190 (Follina) for execution during delivery. |
| T1203 Exploitation for Client Execution |
MalwareInvisiMole | InvisiMole has installed legitimate but vulnerable Total Video Player software and wdigest.dll library drivers on compromised hosts to exploit stack overflow and input validation vulnerabilities for code execution. |
| T1203 Exploitation for Client Execution |
MalwareXbash | Xbash can attempt to exploit known vulnerabilities in Hadoop, Redis, or ActiveMQ when it finds those services running in order to conduct further execution. |
| T1203 Exploitation for Client Execution |
MalwareDealersChoice | DealersChoice leverages vulnerable versions of Flash to perform execution. |
| T1203 Exploitation for Client Execution |
MalwareXLoader | XLoader has exploited Office vulnerabilities during local execution such as CVE-2017-11882 and CVE-2018-0798. |
| T1203 Exploitation for Client Execution |
MalwareSpeakUp | SpeakUp attempts to exploit the following vulnerabilities in order to execute its malicious script: CVE-2012-0874, CVE-2010-1871, CVE-2017-10271, CVE-2018-2894, CVE-2016-3088, JBoss AS 3/4/5/6, and the Hadoop YARN ResourceManager. |
| T1203 Exploitation for Client Execution |
MalwareCobalt Strike | Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460. |
| T1203 Exploitation for Client Execution |
MalwareEvilBunny | EvilBunny has exploited CVE-2011-4369, a vulnerability in the PRC component in Adobe Reader. |
| T1203 Exploitation for Client Execution |
MalwareSUPERNOVA | SUPERNOVA was installed via exploitation of a SolarWinds Orion API authentication bypass vulnerability (CVE-2020-10148). |
| T1203 Exploitation for Client Execution |
MalwareRamsay | Ramsay has been embedded in documents exploiting CVE-2017-0199, CVE-2017-11882, and CVE-2017-8570. |
| T1203 Exploitation for Client Execution |
MalwareAgent Tesla | Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery. |
| T1204 User Execution |
MalwareRaspberry Robin | Raspberry Robin execution can rely on users directly interacting with malicious LNK files. |
| T1204 User Execution |
MalwareLumma Stealer | Lumma Stealer has been distributed through a fake CAPTCHA that presents instructions to the victim to open Windows Run window (“Windows Button + R”) and paste clipboard contents (“CTRL + V”) and press “Enter” to execute a Base64-encoded PowerShell. |
| T1204.001 Malicious Link |
MalwareBumblebee | Bumblebee has relied upon a user downloading a file from a OneDrive link for execution. |
| T1204.001 Malicious Link |
MalwarePony | Pony has attempted to lure targets into clicking links in spoofed emails from legitimate banks. |
| T1204.001 Malicious Link |
MalwareROAMINGHOUSE | ROAMINGHOUSE has been executed through luring victims into clicking links to download malicious ZIP files. |
| T1204.001 Malicious Link |
MalwareNETWIRE | NETWIRE has been executed through convincing victims into clicking malicious links. |
| T1204.001 Malicious Link |
MalwareEmotet | Emotet has relied upon users clicking on a malicious link delivered through spearphishing. |
| T1204.001 Malicious Link |
MalwareGootloader | Gootloader has been executed through malicious links presented to users as internet search results. |
| T1204.001 Malicious Link |
MalwareSquirrelwaffle | Squirrelwaffle has relied on victims to click on a malicious link send via phishing campaigns. |
| T1204.001 Malicious Link |
MalwareSnip3 | Snip3 has been executed through luring victims into clicking malicious links. |
| T1204.001 Malicious Link |
MalwareGuLoader | GuLoader has relied upon users clicking on links to malicious documents. |
| T1204.001 Malicious Link |
MalwareObliqueRAT | ObliqueRAT has gained execution on targeted systems through luring users to click on links to malicious URLs. |
| T1204.001 Malicious Link |
MalwareSocGholish | SocGholish has lured victims into interacting with malicious links on compromised websites for execution. |
| T1204.001 Malicious Link |
MalwareSpicyOmelette | SpicyOmelette has been executed through malicious links within spearphishing emails. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.