Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1586.003 Cloud Accounts |
GroupAPT29 | APT29 has used residential proxies, including Azure Virtual Machines, to obfuscate their access to victim environments. |
| T1586.003 Cloud Accounts |
GroupAPT-C-36 | APT-C-36 has used compromised Google Drive accounts including one associated with a Colombian government organization. |
| T1587 Develop Capabilities |
GroupKimsuky | Kimsuky created and used a mailing toolkit to use in spearphishing attacks. |
| T1587 Develop Capabilities |
GroupContagious Interview | Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims. Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1587 Develop Capabilities |
GroupMoonstone Sleet | Moonstone Sleet developed malicious npm packages for delivery to or retrieval by victims. |
| T1587.001 Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations. |
| T1587.001 Malware |
CampaignRedPenguin | During RedPenguin, UNC3886 deployed custom malware based on the publicly-available TINYSHELL backdoor. |
| T1587.001 Malware |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors used the Rising Sun modular backdoor. |
| T1587.001 Malware |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles developed, prior to the attack, malware capabilities that would require access to specific and specialized hardware and software. |
| T1587.001 Malware |
CampaignOperation Ghost | For Operation Ghost, APT29 used new strains of malware including FatDuke, MiniDuke, RegDuke, and PolyglotDuke. |
| T1587.001 Malware |
CampaignJuicy Mix | For Juicy Mix, OilRig improved on Solar by developing the Mango backdoor. |
| T1587.001 Malware |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP. |
| T1587.001 Malware |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used custom malware, as well as customized variants of publicly available tools. |
| T1587.001 Malware |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors created malicious applications within Salesforce trial accounts, typically Python scripts with similar function to the Salesforce Data Loader. |
| T1587.001 Malware |
CampaignOuter Space | For Outer Space, OilRig created new implants including the Solar backdoor. |
| T1587.001 Malware |
CampaignArcaneDoor | ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner. |
| T1587.001 Malware |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries observed that their malware was initially detected by the victims EDR solutions, so they modified the payload and attempted to execute the new version within the same day. |
| T1587.001 Malware |
CampaignC0010 | For C0010, UNC3890 actors used unique malware, including SUGARUSH and SUGARDUMP. |
| T1587.001 Malware |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation involved the development of a new web shell variant, VersaMem. |
| T1587.001 Malware |
CampaignOperation Wocao | During Operation Wocao, threat actors developed their own custom webshells to upload to compromised servers. |
| T1587.001 Malware |
CampaignCostaRicto | For CostaRicto, the threat actors used custom malware, including PS1, CostaBricks, and SombRAT. |
| T1587.001 Malware |
GroupIndrik Spider | Indrik Spider has developed malware for their operations, including ransomware such as BitPaymer and WastedLocker. |
| T1587.001 Malware |
GroupKimsuky | Kimsuky has developed its own unique malware such as MailFetch.py for use in operations. |
| T1587.001 Malware |
GroupSalt Typhoon | Salt Typhoon has used custom tooling including JumbledPath. |
| T1587.001 Malware |
GroupTeamTNT | |
| T1587.001 Malware |
GroupFIN7 | FIN7 has developed malware for use in operations, including the creation of infected removable media. |
| T1587.001 Malware |
GroupSandworm Team | Sandworm Team has developed malware for its operations, including malicious mobile applications and destructive malware such as NotPetya and Olympic Destroyer. |
| T1587.001 Malware |
GroupMustang Panda | Mustang Panda has developed custom malware for use in their operations. |
| T1587.001 Malware |
GroupUNC3886 | UNC3886 has deployed custom malware families on Fortinet and VMware systems. |
| T1587.001 Malware |
GroupContagious Interview | Contagious Interview has developed malware that utilizes Qt cross-platform framework to include BeaverTail. |
| T1587.001 Malware |
GroupMoses Staff | Moses Staff has built malware, such as DCSrv and PyDCrypt, for targeting victims' machines. |
| T1587.001 Malware |
GroupOilRig | OilRig actively developed and used a series of downloaders during 2022. |
| T1587.001 Malware |
GroupAoqin Dragon | Aoqin Dragon has used custom malware, including Mongall and Heyoka Backdoor, in their operations. |
| T1587.001 Malware |
GroupKe3chang | Ke3chang has developed custom malware that allowed them to maintain persistence on victim networks. |
| T1587.001 Malware |
GroupTurla | Turla has developed its own unique malware for use in operations. |
| T1587.001 Malware |
GroupRedCurl | RedCurl has created its own tools to use during operations. |
| T1587.001 Malware |
GroupAPT29 | APT29 has used unique malware in many of their operations. |
| T1587.001 Malware |
GroupMirrorFace | MirrorFace has created and continued to develop custom strains of malware including LODEINFO. |
| T1587.001 Malware |
GroupCleaver | Cleaver has created customized tools and payloads for functions including ARP poisoning, encryption, credential dumping, ASP.NET shells, web backdoors, process enumeration, WMI querying, HTTP and SMB communications, network interface sniffing, and keystroke logging. |
| T1587.001 Malware |
GroupLuminousMoth | LuminousMoth has used unique malware for information theft and exfiltration. |
| T1587.001 Malware |
GroupAPT-C-36 | APT-C-36 has customized existing malware with new capabilities including njRAT, AsyncRAT, LimeRAT, and BitRAT. |
| T1587.001 Malware |
GroupLazarus Group | Lazarus Group has developed custom malware for use in their operations. |
| T1587.001 Malware |
GroupMoonstone Sleet | Moonstone Sleet has developed custom malware, including a malware delivery mechanism masquerading as a legitimate game. |
| T1587.001 Malware |
GroupVOID MANTICORE | VOID MANTICORE has utilized custom-malware and wipers to include BiBi Wiper. |
| T1587.001 Malware |
GroupPlay | |
| T1587.001 Malware |
GroupFIN13 | FIN13 has utilized custom malware to maintain persistence in a compromised environment. |
| T1587.001 Malware |
GroupTeamPCP | TeamPCP has developed and deployed custom malware including TeamPCP Cloud Stealer, CanisterWorm, and Mini Shai-Hulud. |
| T1587.002 Code Signing Certificates |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group digitally signed their malware and the dbxcli utility. |
| T1587.002 Code Signing Certificates |
GroupPatchwork | Patchwork has created self-signed certificates from fictitious and spoofed legitimate software companies that were later used to sign malware. |
| T1587.002 Code Signing Certificates |
GroupPROMETHIUM | PROMETHIUM has created self-signed certificates to sign malicious installers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.