Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1587.001 Malware |
CampaignOperation Ghost | For Operation Ghost, APT29 used new strains of malware including FatDuke, MiniDuke, RegDuke, and PolyglotDuke. |
| T1587.001 Malware |
CampaignJuicy Mix | For Juicy Mix, OilRig improved on Solar by developing the Mango backdoor. |
| T1587.001 Malware |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP. |
| T1587.001 Malware |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used custom malware, as well as customized variants of publicly available tools. |
| T1587.001 Malware |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors created malicious applications within Salesforce trial accounts, typically Python scripts with similar function to the Salesforce Data Loader. |
| T1587.001 Malware |
CampaignOuter Space | For Outer Space, OilRig created new implants including the Solar backdoor. |
| T1587.001 Malware |
CampaignArcaneDoor | ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner. |
| T1587.001 Malware |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries observed that their malware was initially detected by the victims EDR solutions, so they modified the payload and attempted to execute the new version within the same day. |
| T1587.001 Malware |
CampaignC0010 | For C0010, UNC3890 actors used unique malware, including SUGARUSH and SUGARDUMP. |
| T1587.001 Malware |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation involved the development of a new web shell variant, VersaMem. |
| T1587.001 Malware |
CampaignOperation Wocao | During Operation Wocao, threat actors developed their own custom webshells to upload to compromised servers. |
| T1587.001 Malware |
CampaignCostaRicto | For CostaRicto, the threat actors used custom malware, including PS1, CostaBricks, and SombRAT. |
| T1587.002 Code Signing Certificates |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group digitally signed their malware and the dbxcli utility. |
| T1587.003 Digital Certificates |
CampaignJ-magic Campaign | During the J-magic Campaign, threat actors used self-signed certificates on VPS C2 infrastructure. |
| T1587.003 Digital Certificates |
CampaignArcaneDoor | ArcaneDoor included acquiring digital certificates mimicking patterns associated with Cisco ASA appliances for command and control infrastructure. |
| T1587.003 Digital Certificates |
CampaignC0011 | For C0011, Transparent Tribe established SSL certificates on the typo-squatted domains the group registered. |
| T1587.004 Exploits |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to research exploitation techniques for an identified SSRF vulnerability, to generate a tailored custom attack payload, and to develop a full exploit chain prior to deployment. |
| T1588.001 Malware |
CampaignOperation Spalax | For Operation Spalax, the threat actors obtained malware, including Remcos, njRAT, and AsyncRAT. |
| T1588.001 Malware |
CampaignJ-magic Campaign | During the J-magic Campaign campaign, threat actors used open-source malware post-compromise including a custom variant of the cd00r backdoor. |
| T1588.001 Malware |
CampaignC0015 | For C0015, the threat actors used Cobalt Strike and Conti ransomware. |
| T1588.001 Malware |
CampaignFunnyDream | For FunnyDream, the threat actors used a new backdoor named FunnyDream. |
| T1588.001 Malware |
CampaignNight Dragon | During Night Dragon, threat actors used Trojans from underground hacker websites. |
| T1588.002 Tool |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli. |
| T1588.002 Tool |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged tools including Impacket, PsExec, and Mimikatz. |
| T1588.002 Tool |
CampaignFrankenstein | For Frankenstein, the threat actors obtained and used Empire. |
| T1588.002 Tool |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used the GO Simple Tunnel (GOST) reverse proxy tool. |
| T1588.002 Tool |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used tools such as Mimikatz and other open-source software. |
| T1588.002 Tool |
CampaignOperation Spalax | For Operation Spalax, the threat actors obtained packers such as CyaX. |
| T1588.002 Tool |
CampaignCutting Edge | During Cutting Edge, threat actors leveraged tools including Interactsh to identify vulnerable targets, PySoxy to simultaneously dispatch traffic between multiple endpoints, BusyBox to enable post exploitation activities, and Kubo Injector to inject shared objects into process memory. |
| T1588.002 Tool |
CampaignC0018 | For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy. |
| T1588.002 Tool |
CampaignShadowRay | During ShadowRay, threat actors used tools including the XMRig miner and Interactsh. |
| T1588.002 Tool |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary obtained open-source penetration testing tools including network scanners, database exploitation frameworks, password crackers, and binary analysis suites. |
| T1588.002 Tool |
CampaignC0021 | For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile. |
| T1588.002 Tool |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used third party tools including custom implementations of Mimikatz. |
| T1588.002 Tool |
CampaignC0015 | For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker. |
| T1588.002 Tool |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket. |
| T1588.002 Tool |
CampaignC0032 | During the C0032 campaign, TEMP.Veles obtained and used tools such as Mimikatz and PsExec. |
| T1588.002 Tool |
CampaignSPACEHOP Activity | SPACEHOP Activity leverages a C2 framework sourced from a publicly-available Github repository for administration of relay nodes. |
| T1588.002 Tool |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace deployed multiple publicly available tools including PuTTY, FRP, and Rubeus. |
| T1588.002 Tool |
CampaignFunnyDream | For FunnyDream, the threat actors used a modified version of the open source PcShare remote administration tool. |
| T1588.002 Tool |
CampaignOperation CuckooBees | For Operation CuckooBees, the threat actors obtained publicly-available JSP code that was used to deploy a webshell onto a compromised server. |
| T1588.002 Tool |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors initially relied on the legitimate Salesforce Data Loader app for data exfiltration. |
| T1588.002 Tool |
CampaignC0010 | For C0010, UNC3890 actors obtained multiple publicly-available tools, including METASPLOIT, UNICORN, and NorthStar C2. |
| T1588.002 Tool |
CampaignNight Dragon | During Night Dragon, threat actors obtained and used tools such as gsecdump. |
| T1588.002 Tool |
CampaignOperation Wocao | For Operation Wocao, the threat actors obtained a variety of open source tools, including JexBoss, KeeThief, and BloodHound. |
| T1588.002 Tool |
CampaignC0017 | For C0017, APT41 obtained publicly available tools such as YSoSerial.NET, ConfuserEx, and BadPotato. |
| T1588.002 Tool |
CampaignC0027 | During C0027, Scattered Spider obtained and used multiple tools including the LINpeas privilege escalation utility, aws_consoler, rsocx reverse proxy, Level RMM tool, and RustScan port scanner. |
| T1588.002 Tool |
CampaignCostaRicto | During CostaRicto, the threat actors obtained open source tools to use in their operations. |
| T1588.003 Code Signing Certificates |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used code signing certificates issued by Sectigo RSA for some of its malware and tools. |
| T1588.003 Code Signing Certificates |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used tools with legitimate code signing certificates. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.