Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1588.003 Code Signing Certificates |
CampaignAPT41 DUST | APT41 DUST used stolen code signing certificates to sign DUSTTRAP malware and components. |
| T1588.004 Digital Certificates |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda acquired Cloudflare Origin CA TLS certificates during RedDelta Modified PlugX Infection Chain Operations. |
| T1588.004 Digital Certificates |
CampaignOperation Honeybee | For Operation Honeybee, the threat actors stole a digital signature from Adobe Systems to use with their MaoCheng dropper. |
| T1588.004 Digital Certificates |
CampaignIndian Critical Infrastructure Intrusions | Indian Critical Infrastructure Intrusions included the use of digital certificates spoofing Microsoft. |
| T1588.006 Vulnerabilities |
CampaignLeviathan Australian Intrusions | Leviathan weaponized publicly-known vulnerabilities for initial access and other purposes during Leviathan Australian Intrusions. |
| T1588.007 Artificial Intelligence |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary obtained access to Claude Code to support cyber intrusion operations. |
| T1588.007 Artificial Intelligence |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries generated custom script with an LLM. |
| T1589 Gather Victim Identity Information |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group conducted extensive reconnaissance research on potential targets. |
| T1589 Gather Victim Identity Information |
CampaignOperation Wocao | During Operation Wocao, threat actors targeted people based on their organizational roles and privileges. |
| T1589.001 Credentials |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 conducted credential theft operations to obtain credentials to be used for access to victim environments. |
| T1589.001 Credentials |
CampaignC0027 | During C0027, Scattered Spider sent phishing messages via SMS to steal credentials. |
| T1589.002 Email Addresses |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution utilizes thread spoofing of existing email threads in order to execute spear phishing operations. |
| T1589.002 Email Addresses |
CampaignQuad7 Activity | Quad7 Activity has gathered targeted individual’s e-mail addresses for the password spraying attempts. |
| T1590.004 Network Topology |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to map a complete network topology of the target infrastructure. |
| T1590.006 Network Security Appliances |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries obtained details on the configuration of the victim Fortinet perimeter device to include publicly disclosed details on an online forum used by criminal communities. |
| T1591 Gather Victim Org Information |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group gathered victim organization information to identify specific targets. |
| T1591 Gather Victim Org Information |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors concealed malicious activity by using terms that aligned with the technological context of the targeted organization. |
| T1591.004 Identify Roles |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group targeted specific individuals within an organization with tailored job vacancy announcements. |
| T1592.002 Software |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to catalog services and data on discovered endpoints. |
| T1592.004 Client Configurations |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to gather details of high-value systems to include databases and workflow orchestration platforms. |
| T1593.001 Social Media |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used LinkedIn to identify and target employees within a chosen organization. |
| T1593.002 Search Engines |
CampaignAPT41 DUST | APT41 DUST involved use of search engines to research victim servers. |
| T1594 Search Victim-Owned Websites |
CampaignCutting Edge | During Cutting Edge, threat actors peformed reconnaissance of victims' internal websites via proxied connections. |
| T1594 Search Victim-Owned Websites |
CampaignAPT41 DUST | APT41 DUST involved access of external victim websites for target development. |
| T1594 Search Victim-Owned Websites |
CampaignLeviathan Australian Intrusions | Leviathan enumerated compromised web application resources to identify additional endpoints and resources linkd to the website for follow-on access during Leviathan Australian Intrusions. |
| T1595 Active Scanning |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles engaged in network reconnaissance against targets of interest. |
| T1595.001 Scanning IP Blocks |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan infrastructure across IP ranges associated with the target organization. |
| T1595.002 Vulnerability Scanning |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors scanned for SharePoint servers vulnerable to CVE-2025-53770. |
| T1595.002 Vulnerability Scanning |
CampaignCutting Edge | During Cutting Edge, threat actors used the publicly available Interactsh tool to identify Ivanti Connect Secure VPNs vulnerable to CVE-2024-21893. |
| T1595.002 Vulnerability Scanning |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan target infrastructure to identify potential vulnerabilities and to enumerate services and endpoints. |
| T1596.005 Scan Databases |
CampaignAPT41 DUST | APT41 DUST used internet scan data for target development. |
| T1598.001 Spearphishing Service |
CampaignC0027 | During C0027, Scattered Spider sent Telegram messages impersonating IT personnel to harvest credentials. |
| T1598.004 Spearphishing Voice |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors initiated voice calls with victims to socially engineer them into authorizing malicious applications or divulging sensitive credentials. |
| T1598.004 Spearphishing Voice |
CampaignC0027 | During C0027, Scattered Spider used phone calls to instruct victims to navigate to credential-harvesting websites. |
| T1599 Network Boundary Bridging |
CampaignIndian Critical Infrastructure Intrusions | Indian Critical Infrastructure Intrusions involved the use of FRP to bridge network boundaries and overcome NAT. Indian Critical Infrastructure Intrusions also involved the use of VPN tunnels with a potentially compromised MSP entity allowing for direct access to critical infrastructure entity networks. |
| T1602.002 Network Device Configuration Dump |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries gathered and used the FortiGate bookmarks defined in the configuration file to include the statically defined credentials that facilitated RDP connections to jump hosts. |
| T1606.001 Web Cookies |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 bypassed MFA set on OWA accounts by generating a cookie value from a previously stolen secret key. |
| T1606.002 SAML Tokens |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 created tokens using compromised SAML signing certificates. |
| T1608.001 Upload Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used compromised servers to host malware. |
| T1608.001 Upload Malware |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda staged malware on adversary-controlled domains and cloud storage instances during RedDelta Modified PlugX Infection Chain Operations. |
| T1608.001 Upload Malware |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors staged malicious files on Dropbox and other websites. |
| T1608.001 Upload Malware |
CampaignOperation Spalax | For Operation Spalax, the threat actors staged malware and malicious files in legitimate hosting services such as OneDrive or MediaFire. |
| T1608.001 Upload Malware |
CampaignC0021 | For C0021, the threat actors uploaded malware to websites under their control. |
| T1608.001 Upload Malware |
CampaignC0010 | For C0010, UNC3890 actors staged malware on their infrastructure for direct download onto a compromised system. |
| T1608.001 Upload Malware |
CampaignNight Dragon | During Night Dragon, threat actors uploaded commonly available hacker tools to compromised web servers. |
| T1608.001 Upload Malware |
CampaignC0011 | For C0011, Transparent Tribe hosted malicious documents on domains registered by the group. |
| T1608.002 Upload Tool |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used multiple servers to host malicious tools. |
| T1608.002 Upload Tool |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had staged tools and files for use on Dropbox and Pastebin. |
| T1608.002 Upload Tool |
CampaignC0010 | For C0010, UNC3890 actors staged tools on their infrastructure to download directly onto a compromised system. |
| T1608.004 Drive-by Target |
CampaignC0010 | For C0010, the threat actors compromised the login page of a legitimate Israeli shipping company and likely established a watering hole that collected visitor information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.