Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1203 Exploitation for Client Execution |
GroupLeviathan | Leviathan has exploited multiple Microsoft Office and .NET vulnerabilities for execution, including CVE-2017-0199, CVE-2017-8759, and CVE-2017-11882. |
| T1203 Exploitation for Client Execution |
GroupBITTER | BITTER has exploited Microsoft Office vulnerabilities CVE-2012-0158, CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802. |
| T1203 Exploitation for Client Execution |
GroupAPT29 | APT29 has used multiple software exploits for common client software, like Microsoft Word, Exchange, and Adobe Reader, to gain code execution. |
| T1203 Exploitation for Client Execution |
GroupBRONZE BUTLER | BRONZE BUTLER has exploited Microsoft Office vulnerabilities CVE-2014-4114, CVE-2018-0802, and CVE-2018-0798 for execution. |
| T1203 Exploitation for Client Execution |
GroupDarkhotel | Darkhotel has exploited Adobe Flash vulnerability CVE-2015-8651 for execution. |
| T1203 Exploitation for Client Execution |
GroupAxiom | Axiom has used exploits for multiple vulnerabilities including CVE-2014-0322, CVE-2012-4792, CVE-2012-1889, and CVE-2013-3893. |
| T1203 Exploitation for Client Execution |
GroupEmber Bear | Ember Bear has used exploits to enable follow-on execution of frameworks such as Meterpreter. |
| T1203 Exploitation for Client Execution |
GroupAPT28 | APT28 has exploited Microsoft Office vulnerability CVE-2017-0262 for execution. |
| T1203 Exploitation for Client Execution |
GroupAPT12 | APT12 has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities (CVE-2009-3129, CVE-2012-0158) and vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611). |
| T1203 Exploitation for Client Execution |
GroupTonto Team | Tonto Team has exploited Microsoft vulnerabilities, including CVE-2018-0798, CVE-2018-8174, CVE-2018-0802, CVE-2017-11882, CVE-2019-9489 CVE-2020-8468, and CVE-2018-0798 to enable execution of their delivered malicious payloads. |
| T1203 Exploitation for Client Execution |
GroupLazarus Group | Lazarus Group has exploited Adobe Flash vulnerability CVE-2018-4878 for execution. |
| T1203 Exploitation for Client Execution |
GroupCobalt Group | Cobalt Group had exploited multiple vulnerabilities for execution, including Microsoft’s Equation Editor (CVE-2017-11882), an Internet Explorer vulnerability (CVE-2018-8174), CVE-2017-8570, CVE-2017-0199, and CVE-2017-8759. |
| T1203 Exploitation for Client Execution |
GroupTransparent Tribe | Transparent Tribe has crafted malicious files to exploit CVE-2012-0158 and CVE-2010-3333 for execution. |
| T1203 Exploitation for Client Execution |
GroupInception | Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution. |
| T1203 Exploitation for Client Execution |
GroupThreat Group-3390 | Threat Group-3390 has exploited CVE-2018-0798 in Equation Editor. |
| T1203 Exploitation for Client Execution |
GroupAPT33 | APT33 has attempted to exploit a known vulnerability in WinRAR (CVE-2018-20250), and attempted to gain remote code execution via a security bypass vulnerability (CVE-2017-11774). |
| T1203 Exploitation for Client Execution |
MalwareVersaMem | VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers. |
| T1203 Exploitation for Client Execution |
MalwareHAWKBALL | HAWKBALL has exploited Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2018-0802 to deliver the payload. |
| T1203 Exploitation for Client Execution |
MalwareBankshot | Bankshot leverages a known zero-day vulnerability in Adobe Flash to execute the implant into the victims’ machines. |
| T1203 Exploitation for Client Execution |
MalwareWoody RAT | Woody RAT has relied on CVE-2022-30190 (Follina) for execution during delivery. |
| T1203 Exploitation for Client Execution |
MalwareInvisiMole | InvisiMole has installed legitimate but vulnerable Total Video Player software and wdigest.dll library drivers on compromised hosts to exploit stack overflow and input validation vulnerabilities for code execution. |
| T1203 Exploitation for Client Execution |
MalwareXbash | Xbash can attempt to exploit known vulnerabilities in Hadoop, Redis, or ActiveMQ when it finds those services running in order to conduct further execution. |
| T1203 Exploitation for Client Execution |
MalwareDealersChoice | DealersChoice leverages vulnerable versions of Flash to perform execution. |
| T1203 Exploitation for Client Execution |
MalwareXLoader | XLoader has exploited Office vulnerabilities during local execution such as CVE-2017-11882 and CVE-2018-0798. |
| T1203 Exploitation for Client Execution |
MalwareSpeakUp | SpeakUp attempts to exploit the following vulnerabilities in order to execute its malicious script: CVE-2012-0874, CVE-2010-1871, CVE-2017-10271, CVE-2018-2894, CVE-2016-3088, JBoss AS 3/4/5/6, and the Hadoop YARN ResourceManager. |
| T1203 Exploitation for Client Execution |
MalwareCobalt Strike | Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460. |
| T1203 Exploitation for Client Execution |
MalwareEvilBunny | EvilBunny has exploited CVE-2011-4369, a vulnerability in the PRC component in Adobe Reader. |
| T1203 Exploitation for Client Execution |
MalwareSUPERNOVA | SUPERNOVA was installed via exploitation of a SolarWinds Orion API authentication bypass vulnerability (CVE-2020-10148). |
| T1203 Exploitation for Client Execution |
MalwareRamsay | Ramsay has been embedded in documents exploiting CVE-2017-0199, CVE-2017-11882, and CVE-2017-8570. |
| T1203 Exploitation for Client Execution |
MalwareAgent Tesla | Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery. |
| T1203 Exploitation for Client Execution |
GroupShinyHunters | ShinyHunters has exploited vulnerabilities in the target company’s GitHub repository source code to enable more complex follow-on third-party or supply chain attacks. |
| T1204 User Execution |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution requires users to interact with malicious attachments in order to start Pikabot installation. |
| T1204 User Execution |
GroupScattered Spider | Scattered Spider has impersonated organization IT and helpdesk staff to instruct victims to execute commercial remote access tools to gain initial access. |
| T1204 User Execution |
GroupLAPSUS$ | LAPSUS$ has recruited target organization employees or contractors who provide credentials and approve an associated MFA prompt, or install remote management software onto a corporate workstation, allowing LAPSUS$ to take control of an authenticated system. |
| T1204 User Execution |
MalwareRaspberry Robin | Raspberry Robin execution can rely on users directly interacting with malicious LNK files. |
| T1204 User Execution |
MalwareLumma Stealer | Lumma Stealer has been distributed through a fake CAPTCHA that presents instructions to the victim to open Windows Run window (“Windows Button + R”) and paste clipboard contents (“CTRL + V”) and press “Enter” to execute a Base64-encoded PowerShell. |
| T1204.001 Malicious Link |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access. |
| T1204.001 Malicious Link |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda distributed hyperlinks that would result in an MSC file running a PowerShell command to download and install a remotely-hosted MSI file during RedDelta Modified PlugX Infection Chain Operations. |
| T1204.001 Malicious Link |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors relied on a victim clicking on a malicious link sent via email. |
| T1204.001 Malicious Link |
CampaignOperation Spalax | During Operation Spalax, the threat actors relied on a victim to click on a malicious link distributed via phishing emails. |
| T1204.001 Malicious Link |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution distributed a PDF attachment containing a malicious link to a Pikabot installer. |
| T1204.001 Malicious Link |
CampaignC0021 | During C0021, the threat actors lured users into clicking a malicious link which led to the download of a ZIP archive containing a malicious .LNK file. |
| T1204.001 Malicious Link |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace lured users into executing malicious payloads with links to resources hosted on OneDrive. |
| T1204.001 Malicious Link |
CampaignNight Dragon | During Night Dragon, threat actors enticed users to click on links in spearphishing emails to download malware. |
| T1204.001 Malicious Link |
CampaignC0011 | During C0011, Transparent Tribe relied on student targets to click on a malicious link sent via email. |
| T1204.001 Malicious Link |
GroupAPT38 | APT38 has used links to execute a malicious Visual Basic script. |
| T1204.001 Malicious Link |
GroupElderwood | Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open links. |
| T1204.001 Malicious Link |
GroupAPT3 | APT3 has lured victims into clicking malicious links delivered through spearphishing. |
| T1204.001 Malicious Link |
GroupMustard Tempest | Mustard Tempest has lured users into downloading malware through malicious links in fake advertisements and spearphishing emails. |
| T1204.001 Malicious Link |
GroupKimsuky | Kimsuky has lured victims into clicking malicious links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.