ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1585.002
Email Accounts
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group created fake email accounts to correspond with fake LinkedIn personas; Lazarus Group also established email accounts to match those of the victim as part of their BEC attempt.

T1585.002
Email Accounts
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors created Proton mail accounts for communication with organizations infected with ransomware.

T1585.002
Email Accounts
CampaignOperation Honeybee

During Operation Honeybee, attackers created email addresses to register for a free account for a control server used for the implants.

T1585.002
Email Accounts
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors established email addresses to register domains for their operations.

T1585.002
Email Accounts
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used free email providers such as Gmail for spearphishing.

T1585.002
Email Accounts
CampaignFunnyDream

For FunnyDream, the threat actors likely established an identified email account to register a variety of domains that were used during the campaign.

T1585.002
Email Accounts
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors registered emails shinycorp@tuta[.]com and shinygroup@tuta[.]com to send victims extortion demands.

T1585.002
Email Accounts
CampaignOperation Wocao

For Operation Wocao, the threat actors registered email accounts to use during the campaign.

T1585.002
Email Accounts
GroupIndrik Spider

Indrik Spider has created email accounts to communicate with their ransomware victims, to include providing payment and decryption details.

T1585.002
Email Accounts
GroupKimsuky

Kimsuky has created email accounts for phishing operations.

T1585.002
Email Accounts
GroupEXOTIC LILY

EXOTIC LILY has created e-mail accounts to spoof targeted organizations.

T1585.002
Email Accounts
GroupSandworm Team

Sandworm Team has created email accounts that mimic legitimate organizations for its spearphishing operations.

T1585.002
Email Accounts
GroupCURIUM

CURIUM has created dedicated email accounts for use with tools such as IMAPLoader.

T1585.002
Email Accounts
GroupMustang Panda

Mustang Panda has leveraged the legitimate email marketing service SMTP2Go for phishing campaigns. Mustang Panda has also created fake Google accounts to distribute malware via spear-phishing emails. Mustang Panda has also created accounts for spearphishing operations including the use of services such as Proton Mail.

T1585.002
Email Accounts
GroupContagious Interview

Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services. Contagious Interview has also utilized fake email accounts with Threat Intelligence vendor services.

T1585.002
Email Accounts
GroupAPT1

APT1 has created email accounts for later use in social engineering, phishing, and when registering domains.

T1585.002
Email Accounts
GroupLeviathan

Leviathan has created new email accounts for targeting efforts.

T1585.002
Email Accounts
GroupSilent Librarian

Silent Librarian has established e-mail accounts to receive e-mails forwarded from compromised accounts.

T1585.002
Email Accounts
GroupMedusa Group

Medusa Group has created email accounts used in ransomware negotiations.

T1585.002
Email Accounts
GroupStar Blizzard

Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.

T1585.002
Email Accounts
GroupAPT42

APT42 has created email accounts to use in spearphishing operations.

T1585.002
Email Accounts
GroupLazarus Group

Lazarus Group has created new email accounts for spearphishing operations.

T1585.002
Email Accounts
GroupWizard Spider

Wizard Spider has leveraged ProtonMail email addresses in ransom notes when delivering Ryuk ransomware.

T1585.002
Email Accounts
GroupMoonstone Sleet

Moonstone Sleet has created email accounts to interact with victims, including for phishing purposes.

T1585.002
Email Accounts
GroupVOID MANTICORE

VOID MANTICORE has created email accounts to send threatening messages to victims to include ‘Handala_Team[@]outlook[.]com’.

T1585.002
Email Accounts
GroupHEXANE

HEXANE has established email accounts for use in domain registration including for ProtonMail addresses.

T1585.002
Email Accounts
GroupMagic Hound

Magic Hound has established email accounts using fake personas for spearphishing operations.

T1585.002
Email Accounts
GroupShinyHunters

ShinyHunters has established multiple email accounts, such as shinycorp@tutonota[.]com, for use in extortion activities.

T1585.003
Cloud Accounts
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace established OneDrive accounts to host malicious payloads.

T1585.003
Cloud Accounts
CampaignOuter Space

During Outer Space, OilRig created M365 email accounts to be used as part of C2.

T1585.003
Cloud Accounts
GroupStorm-1811

Storm-1811 has created malicious accounts to enable activity via Microsoft Teams, typically spoofing various IT support and helpdesk themes.

T1586.001
Social Media Accounts
GroupSandworm Team

Sandworm Team creates credential capture webpages to compromise existing, legitimate social media accounts.

T1586.001
Social Media Accounts
GroupLeviathan

Leviathan has compromised social media accounts to conduct social engineering attacks.

T1586.002
Email Accounts
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used compromised accounts to send spearphishing emails.

T1586.002
Email Accounts
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used compromised emails to create Salesforce trial accounts.

T1586.002
Email Accounts
GroupKimsuky

Kimsuky has compromised email accounts to send spearphishing e-mails.

T1586.002
Email Accounts
GroupTA577

TA577 has sent thread hijacked messages from compromised emails.

T1586.002
Email Accounts
GroupMustang Panda

Mustang Panda has compromised legitimate email accounts to use in their spear-phishing operations.

T1586.002
Email Accounts
GroupOilRig

OilRig has compromised email accounts to send phishing emails.

T1586.002
Email Accounts
GroupLeviathan

Leviathan has compromised email accounts to conduct social engineering attacks.

T1586.002
Email Accounts
GroupAPT29

APT29 has compromised email accounts to further enable phishing campaigns and taken control of dormant accounts.

T1586.002
Email Accounts
GroupStar Blizzard

Star Blizzard has used compromised email accounts to conduct spearphishing against
contacts of the original victim.

T1586.002
Email Accounts
GroupAPT28

APT28 has used compromised email accounts to send credential phishing emails.

T1586.002
Email Accounts
GroupAPT-C-36

APT-C-36 has regularly used compromised email accounts in spearphishing campaigns.

T1586.002
Email Accounts
GroupLAPSUS$

LAPSUS$ has payed employees, suppliers, and business partners of target organizations for credentials.

T1586.002
Email Accounts
GroupIndigoZebra

IndigoZebra has compromised legitimate email accounts to use in their spearphishing operations.

T1586.002
Email Accounts
GroupHEXANE

HEXANE has used compromised accounts to send spearphishing emails.

T1586.002
Email Accounts
GroupWIRTE

WIRTE has used compromised emails, including one belonging to an Israel-based technology reseller, to deliver targeted spearphishing messages.

T1586.002
Email Accounts
GroupMagic Hound

Magic Hound has compromised personal email accounts through the use of legitimate credentials and gathered additional victim information.

T1586.003
Cloud Accounts
CampaignAPT41 DUST

APT41 DUST used compromised Google Workspace accounts for command and control.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.