ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1190
Exploit Public-Facing Application
ToolHavij

Havij is used to automate SQL injection.

T1190
Exploit Public-Facing Application
GroupTeamPCP

TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints.

T1190
Exploit Public-Facing Application
GroupShinyHunters

ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure. ShinyHunters has exploited known vulnerabilities in internet-facing servers.

T1195
Supply Chain Compromise
GroupSandworm Team

Sandworm Team staged compromised versions of legitimate software installers on forums to achieve initial, untargetetd access in victim environments.

T1195
Supply Chain Compromise
GroupOilRig

OilRig has leveraged compromised organizations to conduct supply chain attacks on government entities.

T1195
Supply Chain Compromise
GroupEmber Bear

Ember Bear has compromised information technology providers and software developers providing services to targets of interest, building initial access to ultimate victims at least in part through compromise of service providers that work with the victim organizations.

T1195
Supply Chain Compromise
MalwareLumma Stealer

Lumma Stealer has been delivered through cracked software downloads.

T1195
Supply Chain Compromise
MalwareRaccoon Stealer

Raccoon Stealer has been distributed through cracked software downloads.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareTsundere Botnet

Tsundere Botnet has used the Node Package Manager (npm) to download malicious packages and to deliver the payload.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareBeaverTail

BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareGlassWorm

GlassWorm has spread through Visual Studio extensions. GlassWorm has also spread through JavaScript projects hosted on Github.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareShai-Hulud

Shai-Hulud has published itself on compromised code repository maintainers within infected packages in attempts to propagate to other victims. Shai-Hulud has also modified versions of code packages.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareXCSSET

XCSSET adds malicious code to a host's Xcode projects by enumerating CocoaPods target_integrator.rb files under the /Library/Ruby/Gems folder or enumerates all .xcodeproj folders under a given directory. XCSSET then downloads a script and Mach-O file into the Xcode project folder.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareMini Shai-Hulud

Mini Shai-Hulud has published itself on compromised victim code repositories to propagate malicious versions of packages to other victims.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareCanisterWorm

CanisterWorm has spread through an automated process that infects and publishes npm packages.

T1195.001
Compromise Software Dependencies and Development Tools
GroupTeamPCP

TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.

T1195.001
Compromise Software Dependencies and Development Tools
GroupShinyHunters

ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms.

T1195.002
Compromise Software Supply Chain
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus first compromised an “end-of-life" trading software application which was downloaded and executed inside the 3CX enterprise environment. The second compromise modified the Windows and macOS build environments used to distribute the 3CX software to their customer base.

T1195.002
Compromise Software Supply Chain
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software.

T1195.002
Compromise Software Supply Chain
GroupAPT41

APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users.

T1195.002
Compromise Software Supply Chain
GroupDragonfly

Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores.

T1195.002
Compromise Software Supply Chain
GroupFIN7

FIN7 has gained initial access by compromising a victim's software supply chain.

T1195.002
Compromise Software Supply Chain
GroupSandworm Team

Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one.

T1195.002
Compromise Software Supply Chain
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has distributed ransomware by backdooring software installers via a strategic web compromise of the site hosting Italian WinRAR.

T1195.002
Compromise Software Supply Chain
GroupCobalt Group

Cobalt Group has compromised legitimate web browser updates to deliver a backdoor.

T1195.002
Compromise Software Supply Chain
GroupMoonstone Sleet

Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims.

T1195.002
Compromise Software Supply Chain
GroupDaggerfly

Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims.

T1195.002
Compromise Software Supply Chain
GroupThreat Group-3390

Threat Group-3390 has compromised the Able Desktop installer to gain access to victim's environments.

T1195.002
Compromise Software Supply Chain
MalwareCCBkdr

CCBkdr was added to a legitimate, signed version 5.33 of the CCleaner software and distributed on CCleaner's distribution site.

T1195.002
Compromise Software Supply Chain
MalwareGoldenSpy

GoldenSpy has been packaged with a legitimate tax preparation software.

T1195.002
Compromise Software Supply Chain
MalwareSUNSPOT

SUNSPOT malware was designed and used to insert SUNBURST into software builds of the SolarWinds Orion IT management product.

T1197
BITS Jobs
GroupPatchwork

Patchwork has used BITS jobs to download malicious payloads.

T1197
BITS Jobs
GroupAPT41

APT41 used BITSAdmin to download and install payloads.

T1197
BITS Jobs
GroupAPT39

APT39 has used the BITS protocol to exfiltrate stolen data from a compromised host.

T1197
BITS Jobs
GroupLeviathan

Leviathan has used BITSAdmin to download additional tools.

T1197
BITS Jobs
GroupWizard Spider

Wizard Spider has used batch scripts that utilizes WMIC to execute a BITSAdmin transfer of a ransomware payload to each compromised machine.

T1197
BITS Jobs
MalwareProLock

ProLock can use BITS jobs to download its malicious payload.

T1197
BITS Jobs
MalwareUBoatRAT

UBoatRAT takes advantage of the /SetNotifyCmdLine option in BITSAdmin to ensure it stays running on a system to maintain persistence.

T1197
BITS Jobs
MalwareMarkiRAT

MarkiRAT can use BITS Utility to connect with the C2 server.

T1197
BITS Jobs
MalwareBazar

Bazar has been downloaded via Windows BITS functionality.

T1197
BITS Jobs
MalwareCobalt Strike

Cobalt Strike can download a hosted "beacon" payload using BITSAdmin.

T1197
BITS Jobs
MalwareEgregor

Egregor has used BITSadmin to download and execute malicious DLLs.

T1197
BITS Jobs
MalwareJPIN

A JPIN variant downloads the backdoor payload via the BITS service.

T1197
BITS Jobs
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to launch a malicious process.

T1199
Trusted Relationship
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained access through compromised accounts at cloud solution partners, and used compromised certificates issued by Mimecast to authenticate to Mimecast customer systems.

T1199
Trusted Relationship
GroupmenuPass

menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest.

T1199
Trusted Relationship
GroupHAFNIUM

HAFNIUM has used stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to access downstream customer environments.

T1199
Trusted Relationship
GroupSandworm Team

Sandworm Team has used dedicated network connections from one victim organization to gain unauthorized access to a separate organization. Additionally, Sandworm Team has accessed Internet service providers and telecommunication entities that provide mobile connectivity.

T1199
Trusted Relationship
GroupSea Turtle

Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers.

T1199
Trusted Relationship
GroupPOLONIUM

POLONIUM has used compromised credentials from an IT company to target downstream customers including a law firm and aviation company.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.