ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1587.001
Malware
CampaignOperation Ghost

For Operation Ghost, APT29 used new strains of malware including FatDuke, MiniDuke, RegDuke, and PolyglotDuke.

T1587.001
Malware
CampaignJuicy Mix

For Juicy Mix, OilRig improved on Solar by developing the Mango backdoor.

T1587.001
Malware
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP.

T1587.001
Malware
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used custom malware, as well as customized variants of publicly available tools.

T1587.001
Malware
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors created malicious applications within Salesforce trial accounts, typically Python scripts with similar function to the Salesforce Data Loader.

T1587.001
Malware
CampaignOuter Space

For Outer Space, OilRig created new implants including the Solar backdoor.

T1587.001
Malware
CampaignArcaneDoor

ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner.

T1587.001
Malware
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries observed that their malware was initially detected by the victims EDR solutions, so they modified the payload and attempted to execute the new version within the same day.

T1587.001
Malware
CampaignC0010

For C0010, UNC3890 actors used unique malware, including SUGARUSH and SUGARDUMP.

T1587.001
Malware
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation involved the development of a new web shell variant, VersaMem.

T1587.001
Malware
CampaignOperation Wocao

During Operation Wocao, threat actors developed their own custom webshells to upload to compromised servers.

T1587.001
Malware
CampaignCostaRicto

For CostaRicto, the threat actors used custom malware, including PS1, CostaBricks, and SombRAT.

T1587.002
Code Signing Certificates
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group digitally signed their malware and the dbxcli utility.

T1587.003
Digital Certificates
CampaignJ-magic Campaign

During the J-magic Campaign, threat actors used self-signed certificates on VPS C2 infrastructure.

T1587.003
Digital Certificates
CampaignArcaneDoor

ArcaneDoor included acquiring digital certificates mimicking patterns associated with Cisco ASA appliances for command and control infrastructure.

T1587.003
Digital Certificates
CampaignC0011

For C0011, Transparent Tribe established SSL certificates on the typo-squatted domains the group registered.

T1587.004
Exploits
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to research exploitation techniques for an identified SSRF vulnerability, to generate a tailored custom attack payload, and to develop a full exploit chain prior to deployment.

T1588.001
Malware
CampaignOperation Spalax

For Operation Spalax, the threat actors obtained malware, including Remcos, njRAT, and AsyncRAT.

T1588.001
Malware
CampaignJ-magic Campaign

During the J-magic Campaign campaign, threat actors used open-source malware post-compromise including a custom variant of the cd00r backdoor.

T1588.001
Malware
CampaignC0015

For C0015, the threat actors used Cobalt Strike and Conti ransomware.

T1588.001
Malware
CampaignFunnyDream

For FunnyDream, the threat actors used a new backdoor named FunnyDream.

T1588.001
Malware
CampaignNight Dragon

During Night Dragon, threat actors used Trojans from underground hacker websites.

T1588.002
Tool
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli.

T1588.002
Tool
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors leveraged tools including Impacket, PsExec, and Mimikatz.

T1588.002
Tool
CampaignFrankenstein

For Frankenstein, the threat actors obtained and used Empire.

T1588.002
Tool
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel (GOST) reverse proxy tool.

T1588.002
Tool
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles used tools such as Mimikatz and other open-source software.

T1588.002
Tool
CampaignOperation Spalax

For Operation Spalax, the threat actors obtained packers such as CyaX.

T1588.002
Tool
CampaignCutting Edge

During Cutting Edge, threat actors leveraged tools including Interactsh to identify vulnerable targets, PySoxy to simultaneously dispatch traffic between multiple endpoints, BusyBox to enable post exploitation activities, and Kubo Injector to inject shared objects into process memory.

T1588.002
Tool
CampaignC0018

For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy.

T1588.002
Tool
CampaignShadowRay

During ShadowRay, threat actors used tools including the XMRig miner and Interactsh.

T1588.002
Tool
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary obtained open-source penetration testing tools including network scanners, database exploitation frameworks, password crackers, and binary analysis suites.

T1588.002
Tool
CampaignC0021

For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile.

T1588.002
Tool
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used third party tools including custom implementations of Mimikatz.

T1588.002
Tool
CampaignC0015

For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker.

T1588.002
Tool
CampaignHomeLand Justice

During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket.

T1588.002
Tool
CampaignC0032

During the C0032 campaign, TEMP.Veles obtained and used tools such as Mimikatz and PsExec.

T1588.002
Tool
CampaignSPACEHOP Activity

SPACEHOP Activity leverages a C2 framework sourced from a publicly-available Github repository for administration of relay nodes.

T1588.002
Tool
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace deployed multiple publicly available tools including PuTTY, FRP, and Rubeus.

T1588.002
Tool
CampaignFunnyDream

For FunnyDream, the threat actors used a modified version of the open source PcShare remote administration tool.

T1588.002
Tool
CampaignOperation CuckooBees

For Operation CuckooBees, the threat actors obtained publicly-available JSP code that was used to deploy a webshell onto a compromised server.

T1588.002
Tool
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors initially relied on the legitimate Salesforce Data Loader app for data exfiltration.

T1588.002
Tool
CampaignC0010

For C0010, UNC3890 actors obtained multiple publicly-available tools, including METASPLOIT, UNICORN, and NorthStar C2.

T1588.002
Tool
CampaignNight Dragon

During Night Dragon, threat actors obtained and used tools such as gsecdump.

T1588.002
Tool
CampaignOperation Wocao

For Operation Wocao, the threat actors obtained a variety of open source tools, including JexBoss, KeeThief, and BloodHound.

T1588.002
Tool
CampaignC0017

For C0017, APT41 obtained publicly available tools such as YSoSerial.NET, ConfuserEx, and BadPotato.

T1588.002
Tool
CampaignC0027

During C0027, Scattered Spider obtained and used multiple tools including the LINpeas privilege escalation utility, aws_consoler, rsocx reverse proxy, Level RMM tool, and RustScan port scanner.

T1588.002
Tool
CampaignCostaRicto

During CostaRicto, the threat actors obtained open source tools to use in their operations.

T1588.003
Code Signing Certificates
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used code signing certificates issued by Sectigo RSA for some of its malware and tools.

T1588.003
Code Signing Certificates
CampaignHomeLand Justice

During HomeLand Justice, threat actors used tools with legitimate code signing certificates.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.