Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.002 Spearphishing Link |
MalwareGuLoader | GuLoader has been spread in phishing campaigns using malicious web links. |
| T1566.002 Spearphishing Link |
MalwareMispadu | Mispadu has been spread via malicious links embedded in emails. |
| T1566.002 Spearphishing Link |
MalwareSocGholish | SocGholish has been spread via emails containing malicious links. |
| T1566.002 Spearphishing Link |
MalwareSpicyOmelette | SpicyOmelette has been distributed via emails containing a malicious link that appears to be a PDF document. |
| T1566.002 Spearphishing Link |
MalwareJavali | Javali has been delivered via malicious links embedded in e-mails. |
| T1566.002 Spearphishing Link |
MalwareLumma Stealer | Lumma Stealer has been delivered through phishing emails containing malicious links. |
| T1566.002 Spearphishing Link |
MalwareDarkGate | DarkGate is distributed in phishing emails containing links to distribute malicious VBS or MSI files. DarkGate uses applications such as Microsoft Teams for distributing links to payloads. |
| T1566.002 Spearphishing Link |
MalwareLatrodectus | Latrodectus has been distributed to victims through emails containing malicious links. |
| T1566.002 Spearphishing Link |
MalwareSaint Bot | Saint Bot has been distributed through malicious links contained within spearphishing emails. |
| T1566.002 Spearphishing Link |
MalwareKerrdown | Kerrdown has been distributed via e-mails containing a malicious link. |
| T1566.002 Spearphishing Link |
MalwareGrandoreiro | Grandoreiro has been spread via malicious links embedded in e-mails. |
| T1566.002 Spearphishing Link |
MalwareBazar | Bazar has been spread via emails with embedded malicious links. |
| T1566.002 Spearphishing Link |
MalwareValak | Valak has been delivered via malicious links in e-mail. |
| T1566.002 Spearphishing Link |
MalwareOutSteel | OutSteel has been distributed through malicious links contained within spearphishing emails. |
| T1566.002 Spearphishing Link |
MalwareMelcoz | Melcoz has been spread through malicious links embedded in e-mails. |
| T1566.002 Spearphishing Link |
MalwareKOCTOPUS | KOCTOPUS has been distributed as a malicious link within an email. |
| T1566.002 Spearphishing Link |
MalwareQilin | Qilin has been delivered via malicious links in spearphishing emails. |
| T1566.002 Spearphishing Link |
MalwareAppleJeus | AppleJeus has been distributed via spearphishing link. |
| T1566.002 Spearphishing Link |
MalwareQakBot | QakBot has spread through emails with malicious links. |
| T1566.002 Spearphishing Link |
MalwareHancitor | Hancitor has been delivered via phishing emails which contained malicious links. |
| T1566.002 Spearphishing Link |
ToolAADInternals | AADInternals can send "consent phishing" emails containing malicious links designed to steal users’ access tokens. |
| T1566.002 Spearphishing Link |
MalwareKali365 | Kali365 has sent bulk phishing emails containing malicious hyperlinks that direct victims to actor-controlled landing pages impersonating services including SharePoint, OneDrive, Teams, DocuSign, and Adobe Acrobat Sign. |
| T1566.003 Spearphishing via Service |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent victims spearphishing messages via LinkedIn concerning fictitious jobs. |
| T1566.003 Spearphishing via Service |
GroupEXOTIC LILY | EXOTIC LILY has used the e-mail notification features of legitimate file sharing services for spearphishing. |
| T1566.003 Spearphishing via Service |
GroupFIN6 | FIN6 has used fake job advertisements sent via LinkedIn to spearphish targets. |
| T1566.003 Spearphishing via Service |
GroupStorm-1811 | Storm-1811 has used Microsoft Teams to send messages and initiate voice calls to victims posing as IT support personnel. |
| T1566.003 Spearphishing via Service |
GroupCURIUM | CURIUM has used social media to deliver malicious files to victims. |
| T1566.003 Spearphishing via Service |
GroupContagious Interview | Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Sekoia ClickFake 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1566.003 Spearphishing via Service |
GroupOilRig | OilRig has used LinkedIn to send spearphishing links. |
| T1566.003 Spearphishing via Service |
GroupAPT29 | APT29 has used the legitimate mailing service Constant Contact to send phishing e-mails. |
| T1566.003 Spearphishing via Service |
GroupDark Caracal | Dark Caracal spearphished victims via Facebook and Whatsapp. |
| T1566.003 Spearphishing via Service |
GroupWindshift | Windshift has used fake personas on social media to engage and target victims. |
| T1566.003 Spearphishing via Service |
GroupToddyCat | ToddyCat has sent loaders configured to run Ninja as zip archives via Telegram. |
| T1566.003 Spearphishing via Service |
GroupLazarus Group | Lazarus Group has used social media platforms, including LinkedIn and Twitter, to send spearphishing messages. |
| T1566.003 Spearphishing via Service |
GroupMoonstone Sleet | Moonstone Sleet has used social media services to spear phish victims to deliver trojainized software. |
| T1566.003 Spearphishing via Service |
GroupMagic Hound | Magic Hound used various social media channels (such as LinkedIn) as well as messaging services (such as WhatsApp) to spearphish victims. |
| T1566.003 Spearphishing via Service |
GroupAjax Security Team | Ajax Security Team has used various social media channels to spearphish victims. |
| T1566.003 Spearphishing via Service |
MalwareNinja | Ninja has been distributed to victims via the messaging app Telegram. |
| T1566.004 Spearphishing Voice |
CampaignC0027 | During C0027, Scattered Spider impersonated legitimate IT personnel in phone calls to direct victims to download a remote monitoring and management (RMM) tool that would allow the adversary to remotely control their system. |
| T1566.004 Spearphishing Voice |
GroupStorm-1811 | Storm-1811 has initiated voice calls with victims posing as IT support to prompt users to download and execute scripts and other tools for initial access. |
| T1567 Exfiltration Over Web Service |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to generate a detailed summary report of collected data, which is then reviewed and approved by the adversary prior to exfiltration of data over Claude. |
| T1567 Exfiltration Over Web Service |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors exfiltrated data via legitimate Salesforce API communication channels including the Salesforce Data Loader application. |
| T1567 Exfiltration Over Web Service |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 exfiltrated data over public-facing webservers – such as Google Drive. |
| T1567 Exfiltration Over Web Service |
CampaignC0017 | During C0017, APT41 used Cloudflare services for data exfiltration. |
| T1567 Exfiltration Over Web Service |
GroupBlackByte | BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data. |
| T1567 Exfiltration Over Web Service |
GroupContagious Interview | Contagious Interview has leveraged Telegram API to exfiltrate stolen data. |
| T1567 Exfiltration Over Web Service |
GroupAPT28 | APT28 can exfiltrate data over Google Drive. |
| T1567 Exfiltration Over Web Service |
GroupMagic Hound | Magic Hound has used the Telegram API `sendMessage` to relay data on compromised devices. |
| T1567 Exfiltration Over Web Service |
MalwareInvisibleFerret | InvisibleFerret has leveraged Telegram chat to upload stolen data using the Telegram API with a bot token. |
| T1567 Exfiltration Over Web Service |
MalwareAppleSeed | AppleSeed has exfiltrated files using web services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.