Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.006 Web Services |
GroupAPT29 | APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations. |
| T1583.006 Web Services |
GroupMedusa Group | Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions. |
| T1583.006 Web Services |
GroupTA578 | TA578 has used Google Firebase to host malicious scripts. |
| T1583.006 Web Services |
GroupLazyScripter | LazyScripter has established GitHub accounts to host its toolsets. |
| T1583.006 Web Services |
GroupAPT28 | APT28 has used newly-created Blogspot pages for credential harvesting operations. |
| T1583.006 Web Services |
GroupAPT-C-36 | APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox. |
| T1583.006 Web Services |
GroupLazarus Group | Lazarus Group has hosted malicious downloads on Github. |
| T1583.006 Web Services |
GroupEarth Lusca | Earth Lusca has established GitHub accounts to host their malware. |
| T1583.006 Web Services |
GroupIndigoZebra | IndigoZebra created Dropbox accounts for their operations. |
| T1583.006 Web Services |
GroupVOID MANTICORE | VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure. |
| T1583.006 Web Services |
GroupMagic Hound | Magic Hound has acquired Amazon S3 buckets to use in C2. |
| T1583.006 Web Services |
GroupTeamPCP | TeamPCP has set up Clouflare Tunnels for malware C2. TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via *.getsession[.]org to recipient ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`. |
| T1583.007 Serverless |
CampaignAPT41 DUST | APT41 DUST used infrastructure hosted behind Cloudflare or utilized Cloudflare Workers for command and control. |
| T1583.008 Malvertising |
GroupMustard Tempest | Mustard Tempest has posted false advertisements including for software packages and browser updates in order to distribute malware. |
| T1583.008 Malvertising |
MalwareRaspberry Robin | Raspberry Robin variants have been delivered via malicious advertising items that, when interacted with, download a malicious archive file containing the initial payload, hosted on services such as Discord. |
| T1584 Compromise Infrastructure |
CampaignIndian Critical Infrastructure Intrusions | Indian Critical Infrastructure Intrusions included the use of compromised infrastructure, such as DVR and IP camera devices, for command and control purposes in ShadowPad activity. |
| T1584 Compromise Infrastructure |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 compromised third-party infrastructure in physical proximity to targets of interest for follow-on activities. |
| T1584.001 Domains |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure. |
| T1584.001 Domains |
CampaignC0021 | For C0021, the threat actors used legitimate but compromised domains to host malicious payloads. |
| T1584.001 Domains |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 compromised domains to use for C2. |
| T1584.001 Domains |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compromised infrastructure to use for C2. |
| T1584.001 Domains |
CampaignC0010 | During C0010, UNC3890 actors likely compromised the domain of a legitimate Israeli shipping company. |
| T1584.001 Domains |
GroupSideCopy | SideCopy has compromised domains for some of their infrastructure, including for C2 and staging malware. |
| T1584.001 Domains |
GroupMustard Tempest | Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page. |
| T1584.001 Domains |
GroupKimsuky | Kimsuky has compromised legitimate sites and used them to distribute malware. |
| T1584.001 Domains |
GroupAPT1 | APT1 hijacked FQDNs associated with legitimate websites hosted by hop points. |
| T1584.001 Domains |
GroupTransparent Tribe | Transparent Tribe has compromised domains for use in targeted malicious campaigns. |
| T1584.001 Domains |
GroupMagic Hound | Magic Hound has used compromised domains to host links targeted to specific phishing victims. |
| T1584.001 Domains |
MalwareGootloader | Gootloader has used compromised legitimate domains to as a delivery network for malicious payloads. |
| T1584.002 DNS Server |
GroupSea Turtle | Sea Turtle modified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers to provide responses for all DNS lookups. |
| T1584.002 DNS Server |
GroupLAPSUS$ | LAPSUS$ has reconfigured a victim's DNS records to actor-controlled domains and websites. |
| T1584.003 Virtual Private Server |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors abused Virtual Private Servers to store malicious files. |
| T1584.003 Virtual Private Server |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries used compromised VPS servers for C2. |
| T1584.003 Virtual Private Server |
GroupVolt Typhoon | Volt Typhoon has compromised Virtual Private Servers (VPS) to proxy C2 traffic. |
| T1584.003 Virtual Private Server |
GroupTurla | Turla has used the VPS infrastructure of compromised Iranian threat actors. |
| T1584.004 Server |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools. |
| T1584.004 Server |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors compromised a server they used as part of the campaign's infrastructure. |
| T1584.004 Server |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary operated dedicated penetration testing servers accessible via MCP to support remote command execution, simultaneous tool coordination, and persistent operational state maintenance across campaign sessions. |
| T1584.004 Server |
CampaignJuicy Mix | During Juicy Mix, OilRig compromised an Israeli job portal to use for a C2 server. |
| T1584.004 Server |
CampaignOuter Space | During Outer Space, OilRig compromised an Israeli human resources site to use as a C2 server. |
| T1584.004 Server |
CampaignNight Dragon | During Night Dragon, threat actors compromised web servers to use for C2. |
| T1584.004 Server |
GroupIndrik Spider | Indrik Spider has served fake updates via legitimate websites that have been compromised. |
| T1584.004 Server |
GroupVolt Typhoon | Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2. |
| T1584.004 Server |
GroupDragonfly | Dragonfly has compromised legitimate websites to host C2 and malware modules. |
| T1584.004 Server |
GroupSandworm Team | Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns. |
| T1584.004 Server |
GroupLeviathan | Leviathan has used compromised legitimate websites as command and control nodes for operations. |
| T1584.004 Server |
GroupTurla | Turla has used compromised servers as infrastructure. |
| T1584.004 Server |
GroupLazarus Group | Lazarus Group has compromised servers to stage malicious tools. |
| T1584.004 Server |
GroupEarth Lusca | Earth Lusca has used compromised web servers as part of their operational infrastructure. |
| T1584.004 Server |
GroupAPT16 | APT16 has compromised otherwise legitimate sites as staging servers for second-stage payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.