Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1574.012 COR_PROFILER |
GroupBlue Mockingbird | Blue Mockingbird has used wmic.exe and Windows Registry modifications to set the COR_PROFILER environment variable to execute a malicious DLL whenever a process loads the .NET CLR. |
| T1574.012 COR_PROFILER |
MalwareDarkTortilla | DarkTortilla can detect profilers by verifying the `COR_ENABLE_PROFILING` environment variable is present and active. |
| T1574.013 KernelCallbackTable |
GroupLazarus Group | Lazarus Group has abused the |
| T1574.013 KernelCallbackTable |
MalwareFinFisher | FinFisher has used the |
| T1574.014 AppDomainManager |
MalwareIMAPLoader | IMAPLoader is executed via the AppDomainManager injection technique. |
| T1578.001 Create Snapshot |
ToolPacu | Pacu can create snapshots of EBS volumes and RDS instances. |
| T1578.002 Create Cloud Instance |
CampaignC0027 | During C0027, Scattered Spider used access to the victim's Azure tenant to create Azure VMs. |
| T1578.002 Create Cloud Instance |
GroupScattered Spider | Scattered Spider has created Amazon EC2 instances within the victim's environment. |
| T1578.002 Create Cloud Instance |
GroupLAPSUS$ | LAPSUS$ has created new virtual machines within the target's cloud environment after leveraging credential access to cloud assets. |
| T1578.003 Delete Cloud Instance |
GroupStorm-0501 | Storm-0501 has conducted mass deletion of cloud data stores and resources from Azure subscriptions. |
| T1578.003 Delete Cloud Instance |
GroupLAPSUS$ | LAPSUS$ has deleted the target's systems and resources in the cloud to trigger the organization's incident and crisis response process. |
| T1580 Cloud Infrastructure Discovery |
GroupScattered Spider | Scattered Spider enumerates cloud environments including Amazon Web Services (AWS) S3 buckets to identify server and backup management infrastructure, resource access, databases and storage containers . |
| T1580 Cloud Infrastructure Discovery |
GroupStorm-0501 | Storm-0501 has enumerated compromised cloud environments to identify critical assets, data stores, and back resources. |
| T1580 Cloud Infrastructure Discovery |
ToolPacu | Pacu can enumerate AWS infrastructure, such as EC2 instances. |
| T1580 Cloud Infrastructure Discovery |
ToolTruffleHog | TruffleHog can enumerate AWS Infrastructure to include EC2 instances. |
| T1580 Cloud Infrastructure Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to search for generic GitHub runners. |
| T1580 Cloud Infrastructure Discovery |
GroupShinyHunters | ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to collect information on S3 bucket configurations. |
| T1583 Acquire Infrastructure |
GroupIndrik Spider | Indrik Spider has purchased access to victim VPNs to facilitate access to victim environments. |
| T1583 Acquire Infrastructure |
GroupKimsuky | Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure. |
| T1583 Acquire Infrastructure |
GroupSandworm Team | Sandworm Team used various third-party email campaign management services to deliver phishing emails. |
| T1583 Acquire Infrastructure |
GroupContagious Interview | Contagious Interview has used services such as Astrill VPN. |
| T1583 Acquire Infrastructure |
GroupSea Turtle | Sea Turtle accessed victim networks from VPN service provider networks. |
| T1583 Acquire Infrastructure |
GroupStar Blizzard | Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails. |
| T1583 Acquire Infrastructure |
GroupEmber Bear | Ember Bear uses services such as IVPN, SurfShark, and Tor to add anonymization to operations. |
| T1583 Acquire Infrastructure |
GroupAgrius | Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN. |
| T1583 Acquire Infrastructure |
GroupTeamPCP | In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests. |
| T1583.001 Domains |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort. |
| T1583.001 Domains |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors registered C2 domains to spoof legitimate Microsoft domains. |
| T1583.001 Domains |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda registered adversary-controlled domains during RedDelta Modified PlugX Infection Chain Operations that were re-registrations of expired domains. |
| T1583.001 Domains |
CampaignOperation Honeybee | During Operation Honeybee, threat actors registered domains for C2. |
| T1583.001 Domains |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors established domains as part of their operational infrastructure. |
| T1583.001 Domains |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities. |
| T1583.001 Domains |
CampaignOperation Spalax | For Operation Spalax, the threat actors registered hundreds of domains using Duck DNS and DNS Exit. |
| T1583.001 Domains |
CampaignC0021 | For C0021, the threat actors registered domains for use in C2. |
| T1583.001 Domains |
CampaignOperation Ghost | For Operation Ghost, APT29 registered domains for use in C2 including some crafted to appear as existing legitimate domains. |
| T1583.001 Domains |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers. |
| T1583.001 Domains |
CampaignFunnyDream | For FunnyDream, the threat actors registered a variety of domains. |
| T1583.001 Domains |
CampaignC0010 | For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer. |
| T1583.001 Domains |
CampaignC0011 | For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India. |
| T1583.001 Domains |
CampaignC0026 | For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware. |
| T1583.001 Domains |
CampaignCostaRicto | For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains. |
| T1583.001 Domains |
GroupAPT38 | APT38 has created fake domains to imitate legitimate venture capital or bank domains. |
| T1583.001 Domains |
GroupKimsuky | Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges. |
| T1583.001 Domains |
GroupEXOTIC LILY | EXOTIC LILY has registered domains to spoof targeted organizations by changing the top-level domain (TLD) to “.us”, “.co” or “.biz”. |
| T1583.001 Domains |
GroupDragonfly | Dragonfly has registered domains for targeting intended victims. |
| T1583.001 Domains |
GroupmenuPass | menuPass has registered malicious domains for use in intrusion campaigns. |
| T1583.001 Domains |
GroupAPT32 | APT32 has set up and operated websites to gather information and deliver malware. |
| T1583.001 Domains |
GroupMuddyWater | MuddyWater has established domains, some of which appeared to spoof legitimate domains for use in operations. |
| T1583.001 Domains |
GroupRedEcho | RedEcho has registered domains spoofing Indian critical infrastructure entities. |
| T1583.001 Domains |
GroupGamaredon Group | Gamaredon Group has registered multiple domains to facilitate payload staging and C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.