Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1190 Exploit Public-Facing Application |
ToolHavij | Havij is used to automate SQL injection. |
| T1190 Exploit Public-Facing Application |
GroupTeamPCP | TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints. |
| T1190 Exploit Public-Facing Application |
GroupShinyHunters | ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure. ShinyHunters has exploited known vulnerabilities in internet-facing servers. |
| T1195 Supply Chain Compromise |
GroupSandworm Team | Sandworm Team staged compromised versions of legitimate software installers on forums to achieve initial, untargetetd access in victim environments. |
| T1195 Supply Chain Compromise |
GroupOilRig | OilRig has leveraged compromised organizations to conduct supply chain attacks on government entities. |
| T1195 Supply Chain Compromise |
GroupEmber Bear | Ember Bear has compromised information technology providers and software developers providing services to targets of interest, building initial access to ultimate victims at least in part through compromise of service providers that work with the victim organizations. |
| T1195 Supply Chain Compromise |
MalwareLumma Stealer | Lumma Stealer has been delivered through cracked software downloads. |
| T1195 Supply Chain Compromise |
MalwareRaccoon Stealer | Raccoon Stealer has been distributed through cracked software downloads. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareTsundere Botnet | Tsundere Botnet has used the Node Package Manager (npm) to download malicious packages and to deliver the payload. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareBeaverTail | BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages. Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareGlassWorm | GlassWorm has spread through Visual Studio extensions. GlassWorm has also spread through JavaScript projects hosted on Github. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareShai-Hulud | Shai-Hulud has published itself on compromised code repository maintainers within infected packages in attempts to propagate to other victims. Shai-Hulud has also modified versions of code packages. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareXCSSET | XCSSET adds malicious code to a host's Xcode projects by enumerating CocoaPods |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareMini Shai-Hulud | Mini Shai-Hulud has published itself on compromised victim code repositories to propagate malicious versions of packages to other victims. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareCanisterWorm | CanisterWorm has spread through an automated process that infects and publishes npm packages. |
| T1195.001 Compromise Software Dependencies and Development Tools |
GroupTeamPCP | TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages. Aikido TeamPCP Telnyx MAR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1195.001 Compromise Software Dependencies and Development Tools |
GroupShinyHunters | ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms. |
| T1195.002 Compromise Software Supply Chain |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus first compromised an “end-of-life" trading software application which was downloaded and executed inside the 3CX enterprise environment. The second compromise modified the Windows and macOS build environments used to distribute the 3CX software to their customer base. |
| T1195.002 Compromise Software Supply Chain |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software. |
| T1195.002 Compromise Software Supply Chain |
GroupAPT41 | APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users. |
| T1195.002 Compromise Software Supply Chain |
GroupDragonfly | Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores. |
| T1195.002 Compromise Software Supply Chain |
GroupFIN7 | FIN7 has gained initial access by compromising a victim's software supply chain. |
| T1195.002 Compromise Software Supply Chain |
GroupSandworm Team | Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one. |
| T1195.002 Compromise Software Supply Chain |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has distributed ransomware by backdooring software installers via a strategic web compromise of the site hosting Italian WinRAR. |
| T1195.002 Compromise Software Supply Chain |
GroupCobalt Group | Cobalt Group has compromised legitimate web browser updates to deliver a backdoor. |
| T1195.002 Compromise Software Supply Chain |
GroupMoonstone Sleet | Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims. |
| T1195.002 Compromise Software Supply Chain |
GroupDaggerfly | Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims. |
| T1195.002 Compromise Software Supply Chain |
GroupThreat Group-3390 | Threat Group-3390 has compromised the Able Desktop installer to gain access to victim's environments. |
| T1195.002 Compromise Software Supply Chain |
MalwareCCBkdr | CCBkdr was added to a legitimate, signed version 5.33 of the CCleaner software and distributed on CCleaner's distribution site. |
| T1195.002 Compromise Software Supply Chain |
MalwareGoldenSpy | GoldenSpy has been packaged with a legitimate tax preparation software. |
| T1195.002 Compromise Software Supply Chain |
MalwareSUNSPOT | SUNSPOT malware was designed and used to insert SUNBURST into software builds of the SolarWinds Orion IT management product. |
| T1197 BITS Jobs |
GroupPatchwork | Patchwork has used BITS jobs to download malicious payloads. |
| T1197 BITS Jobs |
GroupAPT41 | |
| T1197 BITS Jobs |
GroupAPT39 | APT39 has used the BITS protocol to exfiltrate stolen data from a compromised host. |
| T1197 BITS Jobs |
GroupLeviathan | |
| T1197 BITS Jobs |
GroupWizard Spider | Wizard Spider has used batch scripts that utilizes WMIC to execute a BITSAdmin transfer of a ransomware payload to each compromised machine. |
| T1197 BITS Jobs |
MalwareProLock | ProLock can use BITS jobs to download its malicious payload. |
| T1197 BITS Jobs |
MalwareUBoatRAT | UBoatRAT takes advantage of the /SetNotifyCmdLine option in BITSAdmin to ensure it stays running on a system to maintain persistence. |
| T1197 BITS Jobs |
MalwareMarkiRAT | MarkiRAT can use BITS Utility to connect with the C2 server. |
| T1197 BITS Jobs |
MalwareBazar | Bazar has been downloaded via Windows BITS functionality. |
| T1197 BITS Jobs |
MalwareCobalt Strike | Cobalt Strike can download a hosted "beacon" payload using BITSAdmin. |
| T1197 BITS Jobs |
MalwareEgregor | Egregor has used BITSadmin to download and execute malicious DLLs. |
| T1197 BITS Jobs |
MalwareJPIN | A JPIN variant downloads the backdoor payload via the BITS service. |
| T1197 BITS Jobs |
ToolBITSAdmin | BITSAdmin can be used to create BITS Jobs to launch a malicious process. |
| T1199 Trusted Relationship |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained access through compromised accounts at cloud solution partners, and used compromised certificates issued by Mimecast to authenticate to Mimecast customer systems. |
| T1199 Trusted Relationship |
GroupmenuPass | menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest. |
| T1199 Trusted Relationship |
GroupHAFNIUM | HAFNIUM has used stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to access downstream customer environments. |
| T1199 Trusted Relationship |
GroupSandworm Team | Sandworm Team has used dedicated network connections from one victim organization to gain unauthorized access to a separate organization. Additionally, Sandworm Team has accessed Internet service providers and telecommunication entities that provide mobile connectivity. |
| T1199 Trusted Relationship |
GroupSea Turtle | Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers. |
| T1199 Trusted Relationship |
GroupPOLONIUM | POLONIUM has used compromised credentials from an IT company to target downstream customers including a law firm and aviation company. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.