ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1574.012
COR_PROFILER
GroupBlue Mockingbird

Blue Mockingbird has used wmic.exe and Windows Registry modifications to set the COR_PROFILER environment variable to execute a malicious DLL whenever a process loads the .NET CLR.

T1574.012
COR_PROFILER
MalwareDarkTortilla

DarkTortilla can detect profilers by verifying the `COR_ENABLE_PROFILING` environment variable is present and active.

T1574.013
KernelCallbackTable
GroupLazarus Group

Lazarus Group has abused the KernelCallbackTable to hijack process control flow and execute shellcode.

T1574.013
KernelCallbackTable
MalwareFinFisher

FinFisher has used the KernelCallbackTable to hijack the execution flow of a process by replacing the __fnDWORD function with the address of a created Asynchronous Procedure Call stub routine.

T1574.014
AppDomainManager
MalwareIMAPLoader

IMAPLoader is executed via the AppDomainManager injection technique.

T1578.001
Create Snapshot
ToolPacu

Pacu can create snapshots of EBS volumes and RDS instances.

T1578.002
Create Cloud Instance
CampaignC0027

During C0027, Scattered Spider used access to the victim's Azure tenant to create Azure VMs.

T1578.002
Create Cloud Instance
GroupScattered Spider

Scattered Spider has created Amazon EC2 instances within the victim's environment.

T1578.002
Create Cloud Instance
GroupLAPSUS$

LAPSUS$ has created new virtual machines within the target's cloud environment after leveraging credential access to cloud assets.

T1578.003
Delete Cloud Instance
GroupStorm-0501

Storm-0501 has conducted mass deletion of cloud data stores and resources from Azure subscriptions.

T1578.003
Delete Cloud Instance
GroupLAPSUS$

LAPSUS$ has deleted the target's systems and resources in the cloud to trigger the organization's incident and crisis response process.

T1580
Cloud Infrastructure Discovery
GroupScattered Spider

Scattered Spider enumerates cloud environments including Amazon Web Services (AWS) S3 buckets to identify server and backup management infrastructure, resource access, databases and storage containers .

T1580
Cloud Infrastructure Discovery
GroupStorm-0501

Storm-0501 has enumerated compromised cloud environments to identify critical assets, data stores, and back resources.

T1580
Cloud Infrastructure Discovery
ToolPacu

Pacu can enumerate AWS infrastructure, such as EC2 instances.

T1580
Cloud Infrastructure Discovery
ToolTruffleHog

TruffleHog can enumerate AWS Infrastructure to include EC2 instances.

T1580
Cloud Infrastructure Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to search for generic GitHub runners.

T1580
Cloud Infrastructure Discovery
GroupShinyHunters

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations.

T1583
Acquire Infrastructure
GroupIndrik Spider

Indrik Spider has purchased access to victim VPNs to facilitate access to victim environments.

T1583
Acquire Infrastructure
GroupKimsuky

Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure.

T1583
Acquire Infrastructure
GroupSandworm Team

Sandworm Team used various third-party email campaign management services to deliver phishing emails.

T1583
Acquire Infrastructure
GroupContagious Interview

Contagious Interview has used services such as Astrill VPN.

T1583
Acquire Infrastructure
GroupSea Turtle

Sea Turtle accessed victim networks from VPN service provider networks.

T1583
Acquire Infrastructure
GroupStar Blizzard

Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails.

T1583
Acquire Infrastructure
GroupEmber Bear

Ember Bear uses services such as IVPN, SurfShark, and Tor to add anonymization to operations.

T1583
Acquire Infrastructure
GroupAgrius

Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN.

T1583
Acquire Infrastructure
GroupTeamPCP

In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests.

T1583.001
Domains
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort.

T1583.001
Domains
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors registered C2 domains to spoof legitimate Microsoft domains.

T1583.001
Domains
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda registered adversary-controlled domains during RedDelta Modified PlugX Infection Chain Operations that were re-registrations of expired domains.

T1583.001
Domains
CampaignOperation Honeybee

During Operation Honeybee, threat actors registered domains for C2.

T1583.001
Domains
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors established domains as part of their operational infrastructure.

T1583.001
Domains
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities.

T1583.001
Domains
CampaignOperation Spalax

For Operation Spalax, the threat actors registered hundreds of domains using Duck DNS and DNS Exit.

T1583.001
Domains
CampaignC0021

For C0021, the threat actors registered domains for use in C2.

T1583.001
Domains
CampaignOperation Ghost

For Operation Ghost, APT29 registered domains for use in C2 including some crafted to appear as existing legitimate domains.

T1583.001
Domains
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers.

T1583.001
Domains
CampaignFunnyDream

For FunnyDream, the threat actors registered a variety of domains.

T1583.001
Domains
CampaignC0010

For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer.

T1583.001
Domains
CampaignC0011

For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India.

T1583.001
Domains
CampaignC0026

For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware.

T1583.001
Domains
CampaignCostaRicto

For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains.

T1583.001
Domains
GroupAPT38

APT38 has created fake domains to imitate legitimate venture capital or bank domains.

T1583.001
Domains
GroupKimsuky

Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges.

T1583.001
Domains
GroupEXOTIC LILY

EXOTIC LILY has registered domains to spoof targeted organizations by changing the top-level domain (TLD) to “.us”, “.co” or “.biz”.

T1583.001
Domains
GroupDragonfly

Dragonfly has registered domains for targeting intended victims.

T1583.001
Domains
GroupmenuPass

menuPass has registered malicious domains for use in intrusion campaigns.

T1583.001
Domains
GroupAPT32

APT32 has set up and operated websites to gather information and deliver malware.

T1583.001
Domains
GroupMuddyWater

MuddyWater has established domains, some of which appeared to spoof legitimate domains for use in operations.

T1583.001
Domains
GroupRedEcho

RedEcho has registered domains spoofing Indian critical infrastructure entities.

T1583.001
Domains
GroupGamaredon Group

Gamaredon Group has registered multiple domains to facilitate payload staging and C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.