ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1529
System Shutdown/Reboot
MalwareBlack Basta

Black Basta has used `ShellExecuteA` to shut down and restart the victim system.

T1529
System Shutdown/Reboot
MalwareXLoader

XLoader can initiate a system reboot or shutdown.

T1529
System Shutdown/Reboot
MalwareHermeticWiper

HermeticWiper can initiate a system shutdown.

T1529
System Shutdown/Reboot
MalwareLookBack

LookBack can shutdown and reboot the victim machine.

T1529
System Shutdown/Reboot
MalwareBFG Agonizer

BFG Agonizer uses elevated privileges to call NtRaiseHardError to induce a "blue screen of death" on infected systems, causing a system crash. Once shut down, the system is no longer bootable.

T1529
System Shutdown/Reboot
MalwareMaze

Maze has issued a shutdown command on a victim machine that, upon reboot, will run the ransomware within a VM.

T1529
System Shutdown/Reboot
MalwareKillDisk

KillDisk attempts to reboot the machine by terminating specific processes.

T1529
System Shutdown/Reboot
MalwareQilin

Qilin can initiate a reboot of the backup server to hinder recovery.

T1529
System Shutdown/Reboot
ToolRemcos

Remcos can shutdown and restart remote devices.

T1529
System Shutdown/Reboot
MalwareCanisterWorm

CanisterWorm has forced the target system to reboot after file deletion.

T1530
Data from Cloud Storage
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to download targeted data from SharePoint, and Teams.

T1530
Data from Cloud Storage
CampaignC0027

During C0027, Scattered Spider accessed victim OneDrive environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides.

T1530
Data from Cloud Storage
GroupHAFNIUM

HAFNIUM has exfitrated data from OneDrive.

T1530
Data from Cloud Storage
GroupScattered Spider

Scattered Spider enumerates data stored in cloud resources for collection and exfiltration purposes.

T1530
Data from Cloud Storage
GroupStorm-0501

Storm-0501 had modified Azure Storage account resources through the `Microsoft.Storage/storageAccounts/write` operation to expose non-remotely accessible accounts for data exfiltration.

T1530
Data from Cloud Storage
GroupAPT42

APT42 has collected data from Microsoft 365 environments.

T1530
Data from Cloud Storage
GroupFox Kitten

Fox Kitten has obtained files from the victim's cloud storage instances.

T1530
Data from Cloud Storage
ToolPacu

Pacu can enumerate and download files stored in AWS storage services, such as S3 buckets.

T1530
Data from Cloud Storage
ToolAADInternals

AADInternals can collect files from a user’s OneDrive.

T1530
Data from Cloud Storage
ToolTruffleHog

TruffleHog has the ability to scan cloud storage services for credentials to include Amazon (AWS) S3 and Google Cloud Storage.

T1530
Data from Cloud Storage
ToolPeirates

Peirates can dump the contents of AWS S3 buckets. It can also retrieve service account tokens from kOps buckets in Google Cloud Storage or S3.

T1530
Data from Cloud Storage
GroupShinyHunters

ShinyHunters has collected data from insecure cloud buckets.

T1531
Account Access Removal
GroupAkira

Akira deletes administrator accounts in victim networks prior to encryption.

T1531
Account Access Removal
GroupLAPSUS$

LAPSUS$ has removed a targeted organization's global admin accounts to lock the organization out of all access.

T1531
Account Access Removal
MalwareLockerGoga

LockerGoga has been observed changing account passwords and logging off current users.

T1531
Account Access Removal
MalwareMegaCortex

MegaCortex has changed user account passwords and logged users off the system.

T1531
Account Access Removal
MalwareMeteor

Meteor has the ability to change the password of local users on compromised hosts and can log off users.

T1531
Account Access Removal
MalwareDEADWOOD

DEADWOOD changes the password for local and domain users via net.exe to a random 32 character string to prevent these accounts from logging on. Additionally, DEADWOOD will terminate the winlogon.exe process to prevent attempts to log on to the infected system.

T1534
Internal Spearphishing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group conducted internal spearphishing from within a compromised organization.

T1534
Internal Spearphishing
GroupKimsuky

Kimsuky has sent internal spearphishing emails for lateral movement after stealing victim information.

T1534
Internal Spearphishing
GroupMuddyWater

MuddyWater has used compromised mailboxes within target organizations to send spearphishing emails.

T1534
Internal Spearphishing
GroupGamaredon Group

Gamaredon Group has used an Outlook VBA module on infected systems to send phishing emails with malicious attachments to other employees within the organization.

T1534
Internal Spearphishing
GroupLeviathan

Leviathan has conducted internal spearphishing within the victim's environment for lateral movement.

T1534
Internal Spearphishing
GroupAPT-C-36

APT-C-36 has used a compromised account to send a phishing email to an address likely used and monitored by the IT team within the same targeted organization.

T1534
Internal Spearphishing
GroupHEXANE

HEXANE has conducted internal spearphishing attacks against executives, HR, and IT personnel to gain information and access.

T1534
Internal Spearphishing
MalwareSameCoin

SameCoin can send its Setup.exe file as an attachment to other addresses in the same compromised organization.

T1537
Transfer Data to Cloud Account
GroupStorm-0501

Storm-0501 has copied data from the victims environment to their own infrastructure leveraging AzCopy CLI.

T1537
Transfer Data to Cloud Account
GroupRedCurl

RedCurl has used cloud storage to exfiltrate data, in particular the megatools utilities were used to exfiltrate data to Mega, a file storage service.

T1537
Transfer Data to Cloud Account
GroupINC Ransom

INC Ransom has used Megasync to exfiltrate data to the cloud.

T1538
Cloud Service Dashboard
GroupScattered Spider

Scattered Spider abused AWS Systems Manager Inventory to identify targets on the compromised network prior to lateral movement.

T1539
Steal Web Session Cookie
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 stole Chrome browser cookies by copying the Chrome profile directories of targeted users.

T1539
Steal Web Session Cookie
GroupKimsuky

Kimsuky has used malware, such as TRANSLATEXT, to steal and exfiltrate browser cookies.

T1539
Steal Web Session Cookie
GroupEvilnum

Evilnum can steal cookies and session information from browsers.

T1539
Steal Web Session Cookie
GroupSandworm Team

Sandworm Team used information stealer malware to collect browser session cookies.

T1539
Steal Web Session Cookie
GroupScattered Spider

Scattered Spider retrieves browser cookies via Raccoon Stealer.

T1539
Steal Web Session Cookie
GroupLotus Blossom

Lotus Blossom has used publicly-available tools to steal cookies from browsers such as Chrome.

T1539
Steal Web Session Cookie
GroupStar Blizzard

Star Blizzard has used EvilGinx to steal the session cookies of victims directed to
phishing domains.

T1539
Steal Web Session Cookie
GroupLuminousMoth

LuminousMoth has used an unnamed post-exploitation tool to steal cookies from the Chrome browser.

T1539
Steal Web Session Cookie
GroupAPT42

APT42 has used custom malware to steal login and cookie data from common browsers.

T1539
Steal Web Session Cookie
MalwareTRANSLATEXT

TRANSLATEXT has exfiltrated updated cookies from Google, Naver, Kakao or Daum to the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.