Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1587.002 Code Signing Certificates |
GroupDaggerfly | Daggerfly created code signing certificates to sign malicious macOS files. |
| T1587.003 Digital Certificates |
CampaignJ-magic Campaign | During the J-magic Campaign, threat actors used self-signed certificates on VPS C2 infrastructure. |
| T1587.003 Digital Certificates |
CampaignArcaneDoor | ArcaneDoor included acquiring digital certificates mimicking patterns associated with Cisco ASA appliances for command and control infrastructure. |
| T1587.003 Digital Certificates |
CampaignC0011 | For C0011, Transparent Tribe established SSL certificates on the typo-squatted domains the group registered. |
| T1587.003 Digital Certificates |
GroupGamaredon Group | Gamaredon Group has used the same TLS certificate across its infrastructure. |
| T1587.003 Digital Certificates |
GroupStorm-0501 | Storm-0501 has utilized their own self-signed TLS certificate “Microsoft IT TLS CA 5” with their infrastructure. |
| T1587.003 Digital Certificates |
GroupAPT29 | APT29 has created self-signed digital certificates to enable mutual TLS authentication for malware. |
| T1587.003 Digital Certificates |
GroupPROMETHIUM | PROMETHIUM has created self-signed digital certificates for use in HTTPS C2 traffic. |
| T1587.004 Exploits |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to research exploitation techniques for an identified SSRF vulnerability, to generate a tailored custom attack payload, and to develop a full exploit chain prior to deployment. |
| T1587.004 Exploits |
GroupVolt Typhoon | Volt Typhoon has exploited zero-day vulnerabilities for initial access. |
| T1587.004 Exploits |
GroupUNC3886 | UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter. |
| T1587.004 Exploits |
GroupLeviathan | Leviathan has rapidly transformed and adapted public exploit proof-of-concept code for new vulnerabilities and utilized them against target networks. |
| T1587.004 Exploits |
GroupShinyHunters | ShinyHunters has exploited zero-day vulnerability CVE-2026-35273 against Oracle PeopleSoft application infrastructure. |
| T1588.001 Malware |
CampaignOperation Spalax | For Operation Spalax, the threat actors obtained malware, including Remcos, njRAT, and AsyncRAT. |
| T1588.001 Malware |
CampaignJ-magic Campaign | During the J-magic Campaign campaign, threat actors used open-source malware post-compromise including a custom variant of the cd00r backdoor. |
| T1588.001 Malware |
CampaignC0015 | For C0015, the threat actors used Cobalt Strike and Conti ransomware. |
| T1588.001 Malware |
CampaignFunnyDream | For FunnyDream, the threat actors used a new backdoor named FunnyDream. |
| T1588.001 Malware |
CampaignNight Dragon | During Night Dragon, threat actors used Trojans from underground hacker websites. |
| T1588.001 Malware |
GroupMuddyWater | MuddyWater has used publicly available malware for operations, likely to blend in with other cybercriminals. |
| T1588.001 Malware |
GroupAndariel | Andariel has used a variety of publicly-available remote access Trojans (RATs) for its operations. |
| T1588.001 Malware |
GroupScattered Spider | Scattered Spider has obtained malware to use at multiple stages of operations including information stealers, remote access tools, and ransomware. |
| T1588.001 Malware |
GroupUNC3886 | UNC3886 has used the publicly available rootkits REPTILE and MEDUSA. |
| T1588.001 Malware |
GroupTA2541 | TA2541 has used multiple strains of malware available for purchase on criminal forums or in open-source repositories. |
| T1588.001 Malware |
GroupAquatic Panda | Aquatic Panda has acquired and used njRAT in its operations. |
| T1588.001 Malware |
GroupAPT1 | APT1 used publicly available malware for privilege escalation. |
| T1588.001 Malware |
GroupTurla | Turla has used malware obtained after compromising other threat actors, such as OilRig. |
| T1588.001 Malware |
GroupTA505 | TA505 has used malware such as Azorult and Cobalt Strike in their operations. |
| T1588.001 Malware |
GroupBackdoorDiplomacy | BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations. |
| T1588.001 Malware |
GroupEmber Bear | Ember Bear has acquired malware and related tools from dark web forums. |
| T1588.001 Malware |
GroupLazyScripter | LazyScripter has used a variety of open-source remote access Trojans for its operations. |
| T1588.001 Malware |
GroupLuminousMoth | LuminousMoth has obtained and used malware such as Cobalt Strike. |
| T1588.001 Malware |
GroupMetador | Metador has used unique malware in their operations, including metaMain and Mafalda. |
| T1588.001 Malware |
GroupAPT-C-36 | APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos. |
| T1588.001 Malware |
GroupEarth Lusca | Earth Lusca has acquired and used a variety of malware, including Cobalt Strike. |
| T1588.001 Malware |
GroupLAPSUS$ | LAPSUS$ acquired and used the Redline password stealer in their operations. |
| T1588.001 Malware |
GroupVOID MANTICORE | VOID MANTICORE has developed or obtained trojanized applications used for persistent surveillance of targeted individuals. |
| T1588.002 Tool |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli. |
| T1588.002 Tool |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged tools including Impacket, PsExec, and Mimikatz. |
| T1588.002 Tool |
CampaignFrankenstein | For Frankenstein, the threat actors obtained and used Empire. |
| T1588.002 Tool |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used the GO Simple Tunnel (GOST) reverse proxy tool. |
| T1588.002 Tool |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used tools such as Mimikatz and other open-source software. |
| T1588.002 Tool |
CampaignOperation Spalax | For Operation Spalax, the threat actors obtained packers such as CyaX. |
| T1588.002 Tool |
CampaignCutting Edge | During Cutting Edge, threat actors leveraged tools including Interactsh to identify vulnerable targets, PySoxy to simultaneously dispatch traffic between multiple endpoints, BusyBox to enable post exploitation activities, and Kubo Injector to inject shared objects into process memory. |
| T1588.002 Tool |
CampaignC0018 | For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy. |
| T1588.002 Tool |
CampaignShadowRay | During ShadowRay, threat actors used tools including the XMRig miner and Interactsh. |
| T1588.002 Tool |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary obtained open-source penetration testing tools including network scanners, database exploitation frameworks, password crackers, and binary analysis suites. |
| T1588.002 Tool |
CampaignC0021 | For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile. |
| T1588.002 Tool |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used third party tools including custom implementations of Mimikatz. |
| T1588.002 Tool |
CampaignC0015 | For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker. |
| T1588.002 Tool |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.