Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.008 Masquerade File Type |
GroupBlackByte | BlackByte masqueraded configuration files containing encryption keys as PNG files. |
| T1036.008 Masquerade File Type |
GroupVolt Typhoon | Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension. |
| T1036.008 Masquerade File Type |
GroupMustang Panda | Mustang Panda has masqueraded malicious executables as legitimate files that download PlugX malware. |
| T1036.008 Masquerade File Type |
GroupMirrorFace | MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files. |
| T1036.010 Masquerade Account Name |
GroupAPT3 | APT3 has been known to create or enable accounts, such as |
| T1036.010 Masquerade Account Name |
GroupDragonfly | Dragonfly has created accounts disguised as legitimate backup and service accounts as well as an email administration account. |
| T1036.010 Masquerade Account Name |
GroupStorm-1811 | Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing. |
| T1036.010 Masquerade Account Name |
GroupMagic Hound | Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines. |
| T1037 Boot or Logon Initialization Scripts |
GroupAPT41 | APT41 used a hidden shell script in `/etc/rc.d/init.d` to leverage the `ADORE.XSEC`backdoor and `Adore-NG` rootkit. |
| T1037 Boot or Logon Initialization Scripts |
GroupRocke | Rocke has installed an "init.d" startup script to maintain persistence. |
| T1037 Boot or Logon Initialization Scripts |
GroupUNC3886 | UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices. |
| T1037 Boot or Logon Initialization Scripts |
GroupAPT29 | APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup. |
| T1037.001 Logon Script (Windows) |
GroupAPT28 | An APT28 loader Trojan adds the Registry key |
| T1037.001 Logon Script (Windows) |
GroupCobalt Group | Cobalt Group has added persistence by registering the file name for the next stage malware under |
| T1037.004 RC Scripts |
GroupUNC3886 | UNC3886 has placed a bash installation script into `/etc/rc.local.d/` to establish persistence. |
| T1037.004 RC Scripts |
GroupAPT29 | APT29 has installed a run command on a compromised system to enable malware execution on system startup. |
| T1037.004 RC Scripts |
GroupVelvet Ant | Velvet Ant used a modified `/etc/rc.local` file on compromised F5 BIG-IP devices to maintain persistence. |
| T1039 Data from Network Shared Drive |
GroupmenuPass | menuPass has collected data from remote systems by mounting network shares with |
| T1039 Data from Network Shared Drive |
GroupGamaredon Group | Gamaredon Group malware has collected Microsoft Office documents from mapped network drives. |
| T1039 Data from Network Shared Drive |
GroupRedCurl | RedCurl has collected data about network drives. |
| T1039 Data from Network Shared Drive |
GroupChimera | Chimera has collected data of interest from network shares. |
| T1039 Data from Network Shared Drive |
GroupBRONZE BUTLER | BRONZE BUTLER has exfiltrated files stolen from file shares. |
| T1039 Data from Network Shared Drive |
GroupAPT28 | APT28 has collected files from network shared drives. |
| T1039 Data from Network Shared Drive |
GroupFox Kitten | Fox Kitten has searched network shares to access sensitive documents. |
| T1039 Data from Network Shared Drive |
GroupSowbug | Sowbug extracted Word documents from a file server on a victim network. |
| T1040 Network Sniffing |
GroupKimsuky | Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols. |
| T1040 Network Sniffing |
GroupSalt Typhoon | Salt Typhoon has used a variety of tools and techniques to capture packet data between network interfaces. |
| T1040 Network Sniffing |
GroupSandworm Team | Sandworm Team has used intercepter-NG to sniff passwords in network traffic. |
| T1040 Network Sniffing |
GroupUNC3886 | UNC3886 has used the LOOKOVER sniffer to sniff TACACS+ authentication packets. |
| T1040 Network Sniffing |
GroupDarkVishnya | DarkVishnya used network sniffing to obtain login data. |
| T1040 Network Sniffing |
GroupAPT28 | APT28 deployed the open source tool Responder to conduct NetBIOS Name Service poisoning, which captured usernames and hashed passwords that allowed access to legitimate credentials. APT28 close-access teams have used Wi-Fi pineapples to intercept Wi-Fi signals and user credentials. |
| T1040 Network Sniffing |
GroupVelvet Ant | Velvet Ant has used a custom tool, "VELVETTAP", to perform packet capture from compromised F5 BIG-IP devices. |
| T1040 Network Sniffing |
GroupAPT33 | APT33 has used SniffPass to collect credentials by sniffing network traffic. |
| T1041 Exfiltration Over C2 Channel |
GroupBlackByte | BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure. |
| T1041 Exfiltration Over C2 Channel |
GroupGALLIUM | GALLIUM used Web shells and HTRAN for C2 and to exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT3 | APT3 has a tool that exfiltrates data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupKimsuky | Kimsuky has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT32 | APT32's backdoor has exfiltrated data using the already opened channel with its C&C server. |
| T1041 Exfiltration Over C2 Channel |
GroupMuddyWater | MuddyWater has used C2 infrastructure to receive exfiltrated data. |
| T1041 Exfiltration Over C2 Channel |
GroupGamaredon Group | A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server. |
| T1041 Exfiltration Over C2 Channel |
GroupSandworm Team | Sandworm Team has sent system information to its C2 server using HTTP. |
| T1041 Exfiltration Over C2 Channel |
GroupCURIUM | CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader. |
| T1041 Exfiltration Over C2 Channel |
GroupMustang Panda | Mustang Panda has exfiltrated stolen data and files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
GroupZIRCONIUM | ZIRCONIUM has exfiltrated files via the Dropbox API C2. |
| T1041 Exfiltration Over C2 Channel |
GroupScattered Spider | Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT39 | APT39 has exfiltrated stolen victim data through C2 communications. |
| T1041 Exfiltration Over C2 Channel |
GroupContagious Interview | Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview October 2024Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1041 Exfiltration Over C2 Channel |
GroupHigaisa | Higaisa exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
GroupKe3chang | Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations. |
| T1041 Exfiltration Over C2 Channel |
GroupConfucius | Confucius has exfiltrated stolen files to its C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.