Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1189 Drive-by Compromise |
GroupWinter Vivern | Winter Vivern created dedicated web pages mimicking legitimate government websites to deliver malicious fake anti-virus software. |
| T1189 Drive-by Compromise |
GroupTurla | Turla has infected victims using watering holes. |
| T1189 Drive-by Compromise |
GroupDark Caracal | Dark Caracal leveraged a watering hole to serve up malicious code. |
| T1189 Drive-by Compromise |
GroupBRONZE BUTLER | BRONZE BUTLER compromised three Japanese websites using a Flash exploit to perform watering hole attacks. |
| T1189 Drive-by Compromise |
GroupDarkhotel | Darkhotel used embedded iframes on hotel login portals to redirect selected victims to download malware. |
| T1189 Drive-by Compromise |
GroupAxiom | Axiom has used watering hole attacks to gain access. |
| T1189 Drive-by Compromise |
GroupWindshift | Windshift has used compromised websites to register custom URL schemes on a remote system. |
| T1189 Drive-by Compromise |
GroupAPT28 | APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages. |
| T1189 Drive-by Compromise |
GroupRTM | RTM has distributed its malware via the RIG and SUNDOWN exploit kits, as well as online advertising network |
| T1189 Drive-by Compromise |
GroupLazarus Group | Lazarus Group delivered RATANKBA and other malicious code to victims via a compromised legitimate website. |
| T1189 Drive-by Compromise |
GroupEarth Lusca | Earth Lusca has performed watering hole attacks. |
| T1189 Drive-by Compromise |
GroupTransparent Tribe | Transparent Tribe has used websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools. |
| T1189 Drive-by Compromise |
GroupPROMETHIUM | PROMETHIUM has used watering hole attacks to deliver malicious versions of legitimate installers. |
| T1189 Drive-by Compromise |
GroupDaggerfly | Daggerfly has used strategic website compromise for initial access against victims. |
| T1189 Drive-by Compromise |
GroupPLATINUM | PLATINUM has sometimes used drive-by attacks against vulnerable browser plugins. |
| T1189 Drive-by Compromise |
GroupMagic Hound | Magic Hound has conducted watering-hole attacks through media and magazine websites. |
| T1189 Drive-by Compromise |
GroupThreat Group-3390 | Threat Group-3390 has extensively used strategic web compromises to target victims. |
| T1189 Drive-by Compromise |
GroupAPT19 | APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets. |
| T1189 Drive-by Compromise |
MalwareBad Rabbit | Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a |
| T1189 Drive-by Compromise |
MalwareKARAE | KARAE was distributed through torrent file-sharing websites to South Korean victims, using a YouTube video downloader application as a lure. |
| T1189 Drive-by Compromise |
MalwareSnip3 | Snip3 has been delivered to targets via downloads from malicious domains. |
| T1189 Drive-by Compromise |
MalwareIcedID | IcedID has cloned legitimate websites/applications to distribute the malware. |
| T1189 Drive-by Compromise |
MalwarePOORAIM | POORAIM has been delivered through compromised sites acting as watering holes. |
| T1189 Drive-by Compromise |
MalwareSocGholish | SocGholish has been distributed through compromised websites with malicious content often masquerading as browser updates. |
| T1189 Drive-by Compromise |
MalwareBundlore | Bundlore has been spread through malicious advertisements on websites. |
| T1189 Drive-by Compromise |
MalwareGrandoreiro | Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer. |
| T1189 Drive-by Compromise |
MalwareREvil | REvil has infected victim machines through compromised websites and exploit kits. |
| T1189 Drive-by Compromise |
MalwareLoudMiner | LoudMiner is typically bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS. |
| T1190 Exploit Public-Facing Application |
CampaignFrostyGoop Incident | FrostyGoop Incident was likely enabled by the adversary exploiting an unknown vulnerability in an external-facing router. |
| T1190 Exploit Public-Facing Application |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors exploited authentication bypass and remote code execution vulnerabilities (CVE-2025-49706 and CVE-2025-49704) against on-premises SharePoint servers. This activity was characterized by crafted `POST` requests to the ToolPane endpoint `/_layouts/15/ToolPane.aspx`. |
| T1190 Exploit Public-Facing Application |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect. |
| T1190 Exploit Public-Facing Application |
CampaignCutting Edge | During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887. |
| T1190 Exploit Public-Facing Application |
CampaignC0018 | During C0018, the threat actors exploited VMWare Horizon Unified Access Gateways that were vulnerable to several Log4Shell vulnerabilities, including CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832. |
| T1190 Exploit Public-Facing Application |
CampaignShadowRay | During ShadowRay, threat actors exploited CVE-2023-48022 on publicly exposed Ray servers to steal computing power and to expose sensitive data. |
| T1190 Exploit Public-Facing Application |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to deploy a custom exploit payload targeting an identified SSRF vulnerability to gain initial access to a targeted environment. |
| T1190 Exploit Public-Facing Application |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used SQL injection to compromise publicly exposed web and database servers. |
| T1190 Exploit Public-Facing Application |
CampaignHomeLand Justice | For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access. |
| T1190 Exploit Public-Facing Application |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel to regain access to a network. |
| T1190 Exploit Public-Facing Application |
CampaignSPACEHOP Activity | SPACEHOP Activity has enabled the exploitation of CVE-2022-27518 and CVE-2022-27518 for illegitimate access. |
| T1190 Exploit Public-Facing Application |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors exploited multiple vulnerabilities in externally facing servers. |
| T1190 Exploit Public-Facing Application |
CampaignArcaneDoor | ArcaneDoor abused WebVPN traffic to targeted devices to achieve unauthorized remote code execution. |
| T1190 Exploit Public-Facing Application |
CampaignNight Dragon | During Night Dragon, threat actors used SQL injection exploits against extranet web servers to gain access. |
| T1190 Exploit Public-Facing Application |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation involved exploitation of a vulnerability in Versa Director servers, since identified as CVE-2024-39717, for initial access and code execution. |
| T1190 Exploit Public-Facing Application |
CampaignOperation Wocao | During Operation Wocao, threat actors gained initial access by exploiting vulnerabilities in JBoss webservers. |
| T1190 Exploit Public-Facing Application |
CampaignLeviathan Australian Intrusions | Leviathan exploited public-facing web applications and appliances for initial access during Leviathan Australian Intrusions. |
| T1190 Exploit Public-Facing Application |
CampaignC0017 | During C0017, APT41 exploited CVE-2021-44207 in the USAHerds application and CVE-2021-44228 in Log4j, as well as other .NET deserialization, SQL injection, and directory traversal vulnerabilities to gain initial access. |
| T1190 Exploit Public-Facing Application |
CampaignC0027 | During C0027, Scattered Spider exploited CVE-2021-35464 in the ForgeRock Open Access Management (OpenAM) application server to gain initial access. |
| T1190 Exploit Public-Facing Application |
CampaignQuad7 Activity | Quad7 Activity has enabled the exploitation of vulnerabilities for remote code execution capabilities in SOHO routers including CVE-2023-50224 and CVE-2025-9377 in TP-Link devices. |
| T1190 Exploit Public-Facing Application |
CampaignFLORAHOX Activity | FLORAHOX Activity has exploited and infected vulnerable routers to recruit additional network devices into the ORB. |
| T1190 Exploit Public-Facing Application |
GroupBlackByte | BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.