Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.004 Server |
CampaignNight Dragon | During Night Dragon, threat actors purchased hosted services to use for C2. |
| T1583.004 Server |
CampaignOperation Wocao | For Operation Wocao, the threat actors purchased servers with Bitcoin to use during the operation. |
| T1583.006 Web Services |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used file hosting services like DropBox and OneDrive. |
| T1583.006 Web Services |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors used Dropbox to host lure documents and their first-stage downloader. |
| T1583.006 Web Services |
CampaignArcaneDoor | ArcaneDoor included the use of OpenConnect VPN Server instances for conducting actions on victim devices. |
| T1583.006 Web Services |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries configured the FortiGate devices to send notifications to an attacker-controlled Slack channel. During the 2025 Poland Wiper Attacks, the adversaries had also staged tools and files on services such as Dropbox and Pastebin. |
| T1583.007 Serverless |
CampaignAPT41 DUST | APT41 DUST used infrastructure hosted behind Cloudflare or utilized Cloudflare Workers for command and control. |
| T1584 Compromise Infrastructure |
CampaignIndian Critical Infrastructure Intrusions | Indian Critical Infrastructure Intrusions included the use of compromised infrastructure, such as DVR and IP camera devices, for command and control purposes in ShadowPad activity. |
| T1584 Compromise Infrastructure |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 compromised third-party infrastructure in physical proximity to targets of interest for follow-on activities. |
| T1584.001 Domains |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure. |
| T1584.001 Domains |
CampaignC0021 | For C0021, the threat actors used legitimate but compromised domains to host malicious payloads. |
| T1584.001 Domains |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 compromised domains to use for C2. |
| T1584.001 Domains |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compromised infrastructure to use for C2. |
| T1584.001 Domains |
CampaignC0010 | During C0010, UNC3890 actors likely compromised the domain of a legitimate Israeli shipping company. |
| T1584.003 Virtual Private Server |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors abused Virtual Private Servers to store malicious files. |
| T1584.003 Virtual Private Server |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries used compromised VPS servers for C2. |
| T1584.004 Server |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools. |
| T1584.004 Server |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors compromised a server they used as part of the campaign's infrastructure. |
| T1584.004 Server |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary operated dedicated penetration testing servers accessible via MCP to support remote command execution, simultaneous tool coordination, and persistent operational state maintenance across campaign sessions. |
| T1584.004 Server |
CampaignJuicy Mix | During Juicy Mix, OilRig compromised an Israeli job portal to use for a C2 server. |
| T1584.004 Server |
CampaignOuter Space | During Outer Space, OilRig compromised an Israeli human resources site to use as a C2 server. |
| T1584.004 Server |
CampaignNight Dragon | During Night Dragon, threat actors compromised web servers to use for C2. |
| T1584.005 Botnet |
CampaignQuad7 Activity | Quad7 Activity has compromised various branded SOHO routers to form a botnet that has been leveraged in password spraying activity. |
| T1584.006 Web Services |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors abused compromised AWS buckets to store files. |
| T1584.008 Network Devices |
CampaignKV Botnet Activity | KV Botnet Activity focuses on compromise of small office-home office (SOHO) network devices to build the subsequent botnet. |
| T1584.008 Network Devices |
CampaignCutting Edge | During Cutting Edge, threat actors used compromised and out-of-support Cyberoam VPN appliances for C2. |
| T1584.008 Network Devices |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries used compromised Cisco routers for network communications. |
| T1584.008 Network Devices |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used compromised small office/home office (SOHO) devices to interact with vulnerable Versa Director servers. |
| T1584.008 Network Devices |
CampaignQuad7 Activity | Quad7 Activity has compromised network devices, such as IP cameras, Network Attached Storage (NAS) devices, and SOHO routers, to leverage for follow-on activity. |
| T1584.008 Network Devices |
CampaignFLORAHOX Activity | FLORAHOX Activity has compromised network routers and IoT devices for the ORB network. |
| T1585 Establish Accounts |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors created Salesforce trial accounts to register their malicious applications. |
| T1585.001 Social Media Accounts |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group created fake LinkedIn accounts for their targeting efforts. |
| T1585.001 Social Media Accounts |
CampaignOperation Ghost | For Operation Ghost, APT29 registered Twitter accounts to host C2 nodes. |
| T1585.002 Email Accounts |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group created fake email accounts to correspond with fake LinkedIn personas; Lazarus Group also established email accounts to match those of the victim as part of their BEC attempt. |
| T1585.002 Email Accounts |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors created Proton mail accounts for communication with organizations infected with ransomware. |
| T1585.002 Email Accounts |
CampaignOperation Honeybee | During Operation Honeybee, attackers created email addresses to register for a free account for a control server used for the implants. |
| T1585.002 Email Accounts |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors established email addresses to register domains for their operations. |
| T1585.002 Email Accounts |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used free email providers such as Gmail for spearphishing. |
| T1585.002 Email Accounts |
CampaignFunnyDream | For FunnyDream, the threat actors likely established an identified email account to register a variety of domains that were used during the campaign. |
| T1585.002 Email Accounts |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors registered emails shinycorp@tuta[.]com and shinygroup@tuta[.]com to send victims extortion demands. |
| T1585.002 Email Accounts |
CampaignOperation Wocao | For Operation Wocao, the threat actors registered email accounts to use during the campaign. |
| T1585.003 Cloud Accounts |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace established OneDrive accounts to host malicious payloads. |
| T1585.003 Cloud Accounts |
CampaignOuter Space | During Outer Space, OilRig created M365 email accounts to be used as part of C2. |
| T1586.002 Email Accounts |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used compromised accounts to send spearphishing emails. |
| T1586.002 Email Accounts |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used compromised emails to create Salesforce trial accounts. |
| T1586.003 Cloud Accounts |
CampaignAPT41 DUST | APT41 DUST used compromised Google Workspace accounts for command and control. |
| T1587.001 Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations. |
| T1587.001 Malware |
CampaignRedPenguin | During RedPenguin, UNC3886 deployed custom malware based on the publicly-available TINYSHELL backdoor. |
| T1587.001 Malware |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors used the Rising Sun modular backdoor. |
| T1587.001 Malware |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles developed, prior to the attack, malware capabilities that would require access to specific and specialized hardware and software. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.