ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1588.003
Code Signing Certificates
CampaignAPT41 DUST

APT41 DUST used stolen code signing certificates to sign DUSTTRAP malware and components.

T1588.004
Digital Certificates
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda acquired Cloudflare Origin CA TLS certificates during RedDelta Modified PlugX Infection Chain Operations.

T1588.004
Digital Certificates
CampaignOperation Honeybee

For Operation Honeybee, the threat actors stole a digital signature from Adobe Systems to use with their MaoCheng dropper.

T1588.004
Digital Certificates
CampaignIndian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions included the use of digital certificates spoofing Microsoft.

T1588.006
Vulnerabilities
CampaignLeviathan Australian Intrusions

Leviathan weaponized publicly-known vulnerabilities for initial access and other purposes during Leviathan Australian Intrusions.

T1588.007
Artificial Intelligence
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary obtained access to Claude Code to support cyber intrusion operations.

T1588.007
Artificial Intelligence
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries generated custom script with an LLM.

T1589
Gather Victim Identity Information
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group conducted extensive reconnaissance research on potential targets.

T1589
Gather Victim Identity Information
CampaignOperation Wocao

During Operation Wocao, threat actors targeted people based on their organizational roles and privileges.

T1589.001
Credentials
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 conducted credential theft operations to obtain credentials to be used for access to victim environments.

T1589.001
Credentials
CampaignC0027

During C0027, Scattered Spider sent phishing messages via SMS to steal credentials.

T1589.002
Email Addresses
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution utilizes thread spoofing of existing email threads in order to execute spear phishing operations.

T1589.002
Email Addresses
CampaignQuad7 Activity

Quad7 Activity has gathered targeted individual’s e-mail addresses for the password spraying attempts.

T1590.004
Network Topology
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to map a complete network topology of the target infrastructure.

T1590.006
Network Security Appliances
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries obtained details on the configuration of the victim Fortinet perimeter device to include publicly disclosed details on an online forum used by criminal communities.

T1591
Gather Victim Org Information
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group gathered victim organization information to identify specific targets.

T1591
Gather Victim Org Information
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors concealed malicious activity by using terms that aligned with the technological context of the targeted organization.

T1591.004
Identify Roles
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group targeted specific individuals within an organization with tailored job vacancy announcements.

T1592.002
Software
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to catalog services and data on discovered endpoints.

T1592.004
Client Configurations
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to gather details of high-value systems to include databases and workflow orchestration platforms.

T1593.001
Social Media
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used LinkedIn to identify and target employees within a chosen organization.

T1593.002
Search Engines
CampaignAPT41 DUST

APT41 DUST involved use of search engines to research victim servers.

T1594
Search Victim-Owned Websites
CampaignCutting Edge

During Cutting Edge, threat actors peformed reconnaissance of victims' internal websites via proxied connections.

T1594
Search Victim-Owned Websites
CampaignAPT41 DUST

APT41 DUST involved access of external victim websites for target development.

T1594
Search Victim-Owned Websites
CampaignLeviathan Australian Intrusions

Leviathan enumerated compromised web application resources to identify additional endpoints and resources linkd to the website for follow-on access during Leviathan Australian Intrusions.

T1595
Active Scanning
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles engaged in network reconnaissance against targets of interest.

T1595.001
Scanning IP Blocks
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan infrastructure across IP ranges associated with the target organization.

T1595.002
Vulnerability Scanning
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors scanned for SharePoint servers vulnerable to CVE-2025-53770.

T1595.002
Vulnerability Scanning
CampaignCutting Edge

During Cutting Edge, threat actors used the publicly available Interactsh tool to identify Ivanti Connect Secure VPNs vulnerable to CVE-2024-21893.

T1595.002
Vulnerability Scanning
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan target infrastructure to identify potential vulnerabilities and to enumerate services and endpoints.

T1596.005
Scan Databases
CampaignAPT41 DUST

APT41 DUST used internet scan data for target development.

T1598.001
Spearphishing Service
CampaignC0027

During C0027, Scattered Spider sent Telegram messages impersonating IT personnel to harvest credentials.

T1598.004
Spearphishing Voice
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors initiated voice calls with victims to socially engineer them into authorizing malicious applications or divulging sensitive credentials.

T1598.004
Spearphishing Voice
CampaignC0027

During C0027, Scattered Spider used phone calls to instruct victims to navigate to credential-harvesting websites.

T1599
Network Boundary Bridging
CampaignIndian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions involved the use of FRP to bridge network boundaries and overcome NAT. Indian Critical Infrastructure Intrusions also involved the use of VPN tunnels with a potentially compromised MSP entity allowing for direct access to critical infrastructure entity networks.

T1602.002
Network Device Configuration Dump
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries gathered and used the FortiGate bookmarks defined in the configuration file to include the statically defined credentials that facilitated RDP connections to jump hosts.

T1606.001
Web Cookies
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 bypassed MFA set on OWA accounts by generating a cookie value from a previously stolen secret key.

T1606.002
SAML Tokens
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 created tokens using compromised SAML signing certificates.

T1608.001
Upload Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used compromised servers to host malware.

T1608.001
Upload Malware
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda staged malware on adversary-controlled domains and cloud storage instances during RedDelta Modified PlugX Infection Chain Operations.

T1608.001
Upload Malware
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors staged malicious files on Dropbox and other websites.

T1608.001
Upload Malware
CampaignOperation Spalax

For Operation Spalax, the threat actors staged malware and malicious files in legitimate hosting services such as OneDrive or MediaFire.

T1608.001
Upload Malware
CampaignC0021

For C0021, the threat actors uploaded malware to websites under their control.

T1608.001
Upload Malware
CampaignC0010

For C0010, UNC3890 actors staged malware on their infrastructure for direct download onto a compromised system.

T1608.001
Upload Malware
CampaignNight Dragon

During Night Dragon, threat actors uploaded commonly available hacker tools to compromised web servers.

T1608.001
Upload Malware
CampaignC0011

For C0011, Transparent Tribe hosted malicious documents on domains registered by the group.

T1608.002
Upload Tool
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used multiple servers to host malicious tools.

T1608.002
Upload Tool
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had staged tools and files for use on Dropbox and Pastebin.

T1608.002
Upload Tool
CampaignC0010

For C0010, UNC3890 actors staged tools on their infrastructure to download directly onto a compromised system.

T1608.004
Drive-by Target
CampaignC0010

For C0010, the threat actors compromised the login page of a legitimate Israeli shipping company and likely established a watering hole that collected visitor information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.