ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1583.004
Server
CampaignNight Dragon

During Night Dragon, threat actors purchased hosted services to use for C2.

T1583.004
Server
CampaignOperation Wocao

For Operation Wocao, the threat actors purchased servers with Bitcoin to use during the operation.

T1583.006
Web Services
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used file hosting services like DropBox and OneDrive.

T1583.006
Web Services
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used Dropbox to host lure documents and their first-stage downloader.

T1583.006
Web Services
CampaignArcaneDoor

ArcaneDoor included the use of OpenConnect VPN Server instances for conducting actions on victim devices.

T1583.006
Web Services
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries configured the FortiGate devices to send notifications to an attacker-controlled Slack channel. During the 2025 Poland Wiper Attacks, the adversaries had also staged tools and files on services such as Dropbox and Pastebin.

T1583.007
Serverless
CampaignAPT41 DUST

APT41 DUST used infrastructure hosted behind Cloudflare or utilized Cloudflare Workers for command and control.

T1584
Compromise Infrastructure
CampaignIndian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions included the use of compromised infrastructure, such as DVR and IP camera devices, for command and control purposes in ShadowPad activity.

T1584
Compromise Infrastructure
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 compromised third-party infrastructure in physical proximity to targets of interest for follow-on activities.

T1584.001
Domains
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure.

T1584.001
Domains
CampaignC0021

For C0021, the threat actors used legitimate but compromised domains to host malicious payloads.

T1584.001
Domains
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 compromised domains to use for C2.

T1584.001
Domains
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compromised infrastructure to use for C2.

T1584.001
Domains
CampaignC0010

During C0010, UNC3890 actors likely compromised the domain of a legitimate Israeli shipping company.

T1584.003
Virtual Private Server
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors abused Virtual Private Servers to store malicious files.

T1584.003
Virtual Private Server
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries used compromised VPS servers for C2.

T1584.004
Server
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools.

T1584.004
Server
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors compromised a server they used as part of the campaign's infrastructure.

T1584.004
Server
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary operated dedicated penetration testing servers accessible via MCP to support remote command execution, simultaneous tool coordination, and persistent operational state maintenance across campaign sessions.

T1584.004
Server
CampaignJuicy Mix

During Juicy Mix, OilRig compromised an Israeli job portal to use for a C2 server.

T1584.004
Server
CampaignOuter Space

During Outer Space, OilRig compromised an Israeli human resources site to use as a C2 server.

T1584.004
Server
CampaignNight Dragon

During Night Dragon, threat actors compromised web servers to use for C2.

T1584.005
Botnet
CampaignQuad7 Activity

Quad7 Activity has compromised various branded SOHO routers to form a botnet that has been leveraged in password spraying activity.

T1584.006
Web Services
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors abused compromised AWS buckets to store files.

T1584.008
Network Devices
CampaignKV Botnet Activity

KV Botnet Activity focuses on compromise of small office-home office (SOHO) network devices to build the subsequent botnet.

T1584.008
Network Devices
CampaignCutting Edge

During Cutting Edge, threat actors used compromised and out-of-support Cyberoam VPN appliances for C2.

T1584.008
Network Devices
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries used compromised Cisco routers for network communications.

T1584.008
Network Devices
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation used compromised small office/home office (SOHO) devices to interact with vulnerable Versa Director servers.

T1584.008
Network Devices
CampaignQuad7 Activity

Quad7 Activity has compromised network devices, such as IP cameras, Network Attached Storage (NAS) devices, and SOHO routers, to leverage for follow-on activity.

T1584.008
Network Devices
CampaignFLORAHOX Activity

FLORAHOX Activity has compromised network routers and IoT devices for the ORB network.

T1585
Establish Accounts
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors created Salesforce trial accounts to register their malicious applications.

T1585.001
Social Media Accounts
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group created fake LinkedIn accounts for their targeting efforts.

T1585.001
Social Media Accounts
CampaignOperation Ghost

For Operation Ghost, APT29 registered Twitter accounts to host C2 nodes.

T1585.002
Email Accounts
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group created fake email accounts to correspond with fake LinkedIn personas; Lazarus Group also established email accounts to match those of the victim as part of their BEC attempt.

T1585.002
Email Accounts
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors created Proton mail accounts for communication with organizations infected with ransomware.

T1585.002
Email Accounts
CampaignOperation Honeybee

During Operation Honeybee, attackers created email addresses to register for a free account for a control server used for the implants.

T1585.002
Email Accounts
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors established email addresses to register domains for their operations.

T1585.002
Email Accounts
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used free email providers such as Gmail for spearphishing.

T1585.002
Email Accounts
CampaignFunnyDream

For FunnyDream, the threat actors likely established an identified email account to register a variety of domains that were used during the campaign.

T1585.002
Email Accounts
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors registered emails shinycorp@tuta[.]com and shinygroup@tuta[.]com to send victims extortion demands.

T1585.002
Email Accounts
CampaignOperation Wocao

For Operation Wocao, the threat actors registered email accounts to use during the campaign.

T1585.003
Cloud Accounts
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace established OneDrive accounts to host malicious payloads.

T1585.003
Cloud Accounts
CampaignOuter Space

During Outer Space, OilRig created M365 email accounts to be used as part of C2.

T1586.002
Email Accounts
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used compromised accounts to send spearphishing emails.

T1586.002
Email Accounts
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used compromised emails to create Salesforce trial accounts.

T1586.003
Cloud Accounts
CampaignAPT41 DUST

APT41 DUST used compromised Google Workspace accounts for command and control.

T1587.001
Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations.

T1587.001
Malware
CampaignRedPenguin

During RedPenguin, UNC3886 deployed custom malware based on the publicly-available TINYSHELL backdoor.

T1587.001
Malware
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used the Rising Sun modular backdoor.

T1587.001
Malware
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles developed, prior to the attack, malware capabilities that would require access to specific and specialized hardware and software.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.