ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1566.002
Spearphishing Link
MalwareGuLoader

GuLoader has been spread in phishing campaigns using malicious web links.

T1566.002
Spearphishing Link
MalwareMispadu

Mispadu has been spread via malicious links embedded in emails.

T1566.002
Spearphishing Link
MalwareSocGholish

SocGholish has been spread via emails containing malicious links.

T1566.002
Spearphishing Link
MalwareSpicyOmelette

SpicyOmelette has been distributed via emails containing a malicious link that appears to be a PDF document.

T1566.002
Spearphishing Link
MalwareJavali

Javali has been delivered via malicious links embedded in e-mails.

T1566.002
Spearphishing Link
MalwareLumma Stealer

Lumma Stealer has been delivered through phishing emails containing malicious links.

T1566.002
Spearphishing Link
MalwareDarkGate

DarkGate is distributed in phishing emails containing links to distribute malicious VBS or MSI files. DarkGate uses applications such as Microsoft Teams for distributing links to payloads.

T1566.002
Spearphishing Link
MalwareLatrodectus

Latrodectus has been distributed to victims through emails containing malicious links.

T1566.002
Spearphishing Link
MalwareSaint Bot

Saint Bot has been distributed through malicious links contained within spearphishing emails.

T1566.002
Spearphishing Link
MalwareKerrdown

Kerrdown has been distributed via e-mails containing a malicious link.

T1566.002
Spearphishing Link
MalwareGrandoreiro

Grandoreiro has been spread via malicious links embedded in e-mails.

T1566.002
Spearphishing Link
MalwareBazar

Bazar has been spread via emails with embedded malicious links.

T1566.002
Spearphishing Link
MalwareValak

Valak has been delivered via malicious links in e-mail.

T1566.002
Spearphishing Link
MalwareOutSteel

OutSteel has been distributed through malicious links contained within spearphishing emails.

T1566.002
Spearphishing Link
MalwareMelcoz

Melcoz has been spread through malicious links embedded in e-mails.

T1566.002
Spearphishing Link
MalwareKOCTOPUS

KOCTOPUS has been distributed as a malicious link within an email.

T1566.002
Spearphishing Link
MalwareQilin

Qilin has been delivered via malicious links in spearphishing emails.

T1566.002
Spearphishing Link
MalwareAppleJeus

AppleJeus has been distributed via spearphishing link.

T1566.002
Spearphishing Link
MalwareQakBot

QakBot has spread through emails with malicious links.

T1566.002
Spearphishing Link
MalwareHancitor

Hancitor has been delivered via phishing emails which contained malicious links.

T1566.002
Spearphishing Link
ToolAADInternals

AADInternals can send "consent phishing" emails containing malicious links designed to steal users’ access tokens.

T1566.002
Spearphishing Link
MalwareKali365

Kali365 has sent bulk phishing emails containing malicious hyperlinks that direct victims to actor-controlled landing pages impersonating services including SharePoint, OneDrive, Teams, DocuSign, and Adobe Acrobat Sign.

T1566.003
Spearphishing via Service
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent victims spearphishing messages via LinkedIn concerning fictitious jobs.

T1566.003
Spearphishing via Service
GroupEXOTIC LILY

EXOTIC LILY has used the e-mail notification features of legitimate file sharing services for spearphishing.

T1566.003
Spearphishing via Service
GroupFIN6

FIN6 has used fake job advertisements sent via LinkedIn to spearphish targets.

T1566.003
Spearphishing via Service
GroupStorm-1811

Storm-1811 has used Microsoft Teams to send messages and initiate voice calls to victims posing as IT support personnel.

T1566.003
Spearphishing via Service
GroupCURIUM

CURIUM has used social media to deliver malicious files to victims.

T1566.003
Spearphishing via Service
GroupContagious Interview

Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims.

T1566.003
Spearphishing via Service
GroupOilRig

OilRig has used LinkedIn to send spearphishing links.

T1566.003
Spearphishing via Service
GroupAPT29

APT29 has used the legitimate mailing service Constant Contact to send phishing e-mails.

T1566.003
Spearphishing via Service
GroupDark Caracal

Dark Caracal spearphished victims via Facebook and Whatsapp.

T1566.003
Spearphishing via Service
GroupWindshift

Windshift has used fake personas on social media to engage and target victims.

T1566.003
Spearphishing via Service
GroupToddyCat

ToddyCat has sent loaders configured to run Ninja as zip archives via Telegram.

T1566.003
Spearphishing via Service
GroupLazarus Group

Lazarus Group has used social media platforms, including LinkedIn and Twitter, to send spearphishing messages.

T1566.003
Spearphishing via Service
GroupMoonstone Sleet

Moonstone Sleet has used social media services to spear phish victims to deliver trojainized software.

T1566.003
Spearphishing via Service
GroupMagic Hound

Magic Hound used various social media channels (such as LinkedIn) as well as messaging services (such as WhatsApp) to spearphish victims.

T1566.003
Spearphishing via Service
GroupAjax Security Team

Ajax Security Team has used various social media channels to spearphish victims.

T1566.003
Spearphishing via Service
MalwareNinja

Ninja has been distributed to victims via the messaging app Telegram.

T1566.004
Spearphishing Voice
CampaignC0027

During C0027, Scattered Spider impersonated legitimate IT personnel in phone calls to direct victims to download a remote monitoring and management (RMM) tool that would allow the adversary to remotely control their system.

T1566.004
Spearphishing Voice
GroupStorm-1811

Storm-1811 has initiated voice calls with victims posing as IT support to prompt users to download and execute scripts and other tools for initial access.

T1567
Exfiltration Over Web Service
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to generate a detailed summary report of collected data, which is then reviewed and approved by the adversary prior to exfiltration of data over Claude.

T1567
Exfiltration Over Web Service
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors exfiltrated data via legitimate Salesforce API communication channels including the Salesforce Data Loader application.

T1567
Exfiltration Over Web Service
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 exfiltrated data over public-facing webservers – such as Google Drive.

T1567
Exfiltration Over Web Service
CampaignC0017

During C0017, APT41 used Cloudflare services for data exfiltration.

T1567
Exfiltration Over Web Service
GroupBlackByte

BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data.

T1567
Exfiltration Over Web Service
GroupContagious Interview

Contagious Interview has leveraged Telegram API to exfiltrate stolen data.

T1567
Exfiltration Over Web Service
GroupAPT28

APT28 can exfiltrate data over Google Drive.

T1567
Exfiltration Over Web Service
GroupMagic Hound

Magic Hound has used the Telegram API `sendMessage` to relay data on compromised devices.

T1567
Exfiltration Over Web Service
MalwareInvisibleFerret

InvisibleFerret has leveraged Telegram chat to upload stolen data using the Telegram API with a bot token.

T1567
Exfiltration Over Web Service
MalwareAppleSeed

AppleSeed has exfiltrated files using web services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.