ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1587.002
Code Signing Certificates
GroupDaggerfly

Daggerfly created code signing certificates to sign malicious macOS files.

T1587.003
Digital Certificates
CampaignJ-magic Campaign

During the J-magic Campaign, threat actors used self-signed certificates on VPS C2 infrastructure.

T1587.003
Digital Certificates
CampaignArcaneDoor

ArcaneDoor included acquiring digital certificates mimicking patterns associated with Cisco ASA appliances for command and control infrastructure.

T1587.003
Digital Certificates
CampaignC0011

For C0011, Transparent Tribe established SSL certificates on the typo-squatted domains the group registered.

T1587.003
Digital Certificates
GroupGamaredon Group

Gamaredon Group has used the same TLS certificate across its infrastructure.

T1587.003
Digital Certificates
GroupStorm-0501

Storm-0501 has utilized their own self-signed TLS certificate “Microsoft IT TLS CA 5” with their infrastructure.

T1587.003
Digital Certificates
GroupAPT29

APT29 has created self-signed digital certificates to enable mutual TLS authentication for malware.

T1587.003
Digital Certificates
GroupPROMETHIUM

PROMETHIUM has created self-signed digital certificates for use in HTTPS C2 traffic.

T1587.004
Exploits
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to research exploitation techniques for an identified SSRF vulnerability, to generate a tailored custom attack payload, and to develop a full exploit chain prior to deployment.

T1587.004
Exploits
GroupVolt Typhoon

Volt Typhoon has exploited zero-day vulnerabilities for initial access.

T1587.004
Exploits
GroupUNC3886

UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter.

T1587.004
Exploits
GroupLeviathan

Leviathan has rapidly transformed and adapted public exploit proof-of-concept code for new vulnerabilities and utilized them against target networks.

T1587.004
Exploits
GroupShinyHunters

ShinyHunters has exploited zero-day vulnerability CVE-2026-35273 against Oracle PeopleSoft application infrastructure.

T1588.001
Malware
CampaignOperation Spalax

For Operation Spalax, the threat actors obtained malware, including Remcos, njRAT, and AsyncRAT.

T1588.001
Malware
CampaignJ-magic Campaign

During the J-magic Campaign campaign, threat actors used open-source malware post-compromise including a custom variant of the cd00r backdoor.

T1588.001
Malware
CampaignC0015

For C0015, the threat actors used Cobalt Strike and Conti ransomware.

T1588.001
Malware
CampaignFunnyDream

For FunnyDream, the threat actors used a new backdoor named FunnyDream.

T1588.001
Malware
CampaignNight Dragon

During Night Dragon, threat actors used Trojans from underground hacker websites.

T1588.001
Malware
GroupMuddyWater

MuddyWater has used publicly available malware for operations, likely to blend in with other cybercriminals.

T1588.001
Malware
GroupAndariel

Andariel has used a variety of publicly-available remote access Trojans (RATs) for its operations.

T1588.001
Malware
GroupScattered Spider

Scattered Spider has obtained malware to use at multiple stages of operations including information stealers, remote access tools, and ransomware.

T1588.001
Malware
GroupUNC3886

UNC3886 has used the publicly available rootkits REPTILE and MEDUSA.

T1588.001
Malware
GroupTA2541

TA2541 has used multiple strains of malware available for purchase on criminal forums or in open-source repositories.

T1588.001
Malware
GroupAquatic Panda

Aquatic Panda has acquired and used njRAT in its operations.

T1588.001
Malware
GroupAPT1

APT1 used publicly available malware for privilege escalation.

T1588.001
Malware
GroupTurla

Turla has used malware obtained after compromising other threat actors, such as OilRig.

T1588.001
Malware
GroupTA505

TA505 has used malware such as Azorult and Cobalt Strike in their operations.

T1588.001
Malware
GroupBackdoorDiplomacy

BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.

T1588.001
Malware
GroupEmber Bear

Ember Bear has acquired malware and related tools from dark web forums.

T1588.001
Malware
GroupLazyScripter

LazyScripter has used a variety of open-source remote access Trojans for its operations.

T1588.001
Malware
GroupLuminousMoth

LuminousMoth has obtained and used malware such as Cobalt Strike.

T1588.001
Malware
GroupMetador

Metador has used unique malware in their operations, including metaMain and Mafalda.

T1588.001
Malware
GroupAPT-C-36

APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos.

T1588.001
Malware
GroupEarth Lusca

Earth Lusca has acquired and used a variety of malware, including Cobalt Strike.

T1588.001
Malware
GroupLAPSUS$

LAPSUS$ acquired and used the Redline password stealer in their operations.

T1588.001
Malware
GroupVOID MANTICORE

VOID MANTICORE has developed or obtained trojanized applications used for persistent surveillance of targeted individuals.

T1588.002
Tool
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli.

T1588.002
Tool
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors leveraged tools including Impacket, PsExec, and Mimikatz.

T1588.002
Tool
CampaignFrankenstein

For Frankenstein, the threat actors obtained and used Empire.

T1588.002
Tool
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel (GOST) reverse proxy tool.

T1588.002
Tool
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles used tools such as Mimikatz and other open-source software.

T1588.002
Tool
CampaignOperation Spalax

For Operation Spalax, the threat actors obtained packers such as CyaX.

T1588.002
Tool
CampaignCutting Edge

During Cutting Edge, threat actors leveraged tools including Interactsh to identify vulnerable targets, PySoxy to simultaneously dispatch traffic between multiple endpoints, BusyBox to enable post exploitation activities, and Kubo Injector to inject shared objects into process memory.

T1588.002
Tool
CampaignC0018

For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy.

T1588.002
Tool
CampaignShadowRay

During ShadowRay, threat actors used tools including the XMRig miner and Interactsh.

T1588.002
Tool
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary obtained open-source penetration testing tools including network scanners, database exploitation frameworks, password crackers, and binary analysis suites.

T1588.002
Tool
CampaignC0021

For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile.

T1588.002
Tool
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used third party tools including custom implementations of Mimikatz.

T1588.002
Tool
CampaignC0015

For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker.

T1588.002
Tool
CampaignHomeLand Justice

During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.