Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1588.003 Code Signing Certificates |
GroupOilRig | OilRig has obtained stolen code signing certificates to digitally sign malware. |
| T1588.003 Code Signing Certificates |
GroupBlackTech | BlackTech has used stolen code-signing certificates for its malicious payloads. |
| T1588.003 Code Signing Certificates |
GroupWizard Spider | Wizard Spider has obtained code signing certificates signed by DigiCert, GlobalSign, and COMOOD for malware payloads. |
| T1588.003 Code Signing Certificates |
GroupThreat Group-3390 | Threat Group-3390 has obtained stolen valid certificates, including from VMProtect and the Chinese instant messaging application Youdu, for their operations. |
| T1588.003 Code Signing Certificates |
GroupFIN8 | FIN8 has used an expired open-source X.509 certificate for testing in the OpenSSL repository, to connect to actor-controlled C2 servers. |
| T1588.003 Code Signing Certificates |
MalwareMegaCortex | MegaCortex has used code signing certificates issued to fake companies to bypass security controls. |
| T1588.004 Digital Certificates |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda acquired Cloudflare Origin CA TLS certificates during RedDelta Modified PlugX Infection Chain Operations. |
| T1588.004 Digital Certificates |
CampaignOperation Honeybee | For Operation Honeybee, the threat actors stole a digital signature from Adobe Systems to use with their MaoCheng dropper. |
| T1588.004 Digital Certificates |
CampaignIndian Critical Infrastructure Intrusions | Indian Critical Infrastructure Intrusions included the use of digital certificates spoofing Microsoft. |
| T1588.004 Digital Certificates |
GroupMustang Panda | Mustang Panda has obtained SSL certificates for their C2 domains. |
| T1588.004 Digital Certificates |
GroupUNC3886 | UNC3886 has deployed malware using the victim's legitimate TLS certificate obtained from a compromised FortiGate device. |
| T1588.004 Digital Certificates |
GroupSea Turtle | Sea Turtle created new certificates using a technique called the actors performed "certificate impersonation," a technique in which Sea Turtle obtained a certificate authority-signed X.509 certificate from another provider for the same domain imitating the one already used by the targeted organization. |
| T1588.004 Digital Certificates |
GroupBlackTech | BlackTech has used valid, stolen digital certificates for some of their malware and tools. |
| T1588.004 Digital Certificates |
GroupSilent Librarian | Silent Librarian has obtained free Let's Encrypt SSL certificates for use on their phishing pages. |
| T1588.004 Digital Certificates |
GroupLuminousMoth | LuminousMoth has used a valid digital certificate for some of their malware. |
| T1588.004 Digital Certificates |
GroupLazarus Group | Lazarus Group has obtained SSL certificates for their C2 domains. |
| T1588.005 Exploits |
GroupKimsuky | Kimsuky has obtained exploit code for various CVEs. |
| T1588.005 Exploits |
GroupEmber Bear | Ember Bear has obtained exploitation scripts against publicly-disclosed vulnerabilities from public repositories. |
| T1588.006 Vulnerabilities |
CampaignLeviathan Australian Intrusions | Leviathan weaponized publicly-known vulnerabilities for initial access and other purposes during Leviathan Australian Intrusions. |
| T1588.006 Vulnerabilities |
GroupVolt Typhoon | Volt Typhoon has used publicly available exploit code for initial access. |
| T1588.006 Vulnerabilities |
GroupSandworm Team | In 2017, Sandworm Team conducted technical research related to vulnerabilities associated with websites used by the Korean Sport and Olympic Committee, a Korean power company, and a Korean airport. |
| T1588.006 Vulnerabilities |
GroupStorm-0501 | Storm-0501 has obtained capabilities to exploit N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203). |
| T1588.007 Artificial Intelligence |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary obtained access to Claude Code to support cyber intrusion operations. |
| T1588.007 Artificial Intelligence |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries generated custom script with an LLM. |
| T1588.007 Artificial Intelligence |
GroupContagious Interview | Contagious Interview has appeared to have used AI to generate images and content to facilitate their campaigns. |
| T1588.007 Artificial Intelligence |
GroupAPT28 | APT28 has deployed LAMEHUG which can can query an LLM to generate and return commands for post compromise activity on targeted systems. |
| T1588.007 Artificial Intelligence |
MalwareLazyWiper | LazyWiper is believed to have been generated by a large language model (LLM) due to the non-sensical comments in the code. |
| T1588.007 Artificial Intelligence |
GroupShinyHunters | ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks. |
| T1589 Gather Victim Identity Information |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group conducted extensive reconnaissance research on potential targets. |
| T1589 Gather Victim Identity Information |
CampaignOperation Wocao | During Operation Wocao, threat actors targeted people based on their organizational roles and privileges. |
| T1589 Gather Victim Identity Information |
GroupVolt Typhoon | Volt Typhoon has gathered victim identify information during pre-compromise reconnaissance. |
| T1589 Gather Victim Identity Information |
GroupAPT32 | APT32 has conducted targeted surveillance against activists and bloggers. |
| T1589 Gather Victim Identity Information |
GroupScattered Spider | Scattered Spider has used information from previous data breaches to identify employee names to be used in social engineering. |
| T1589 Gather Victim Identity Information |
GroupContagious Interview | Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Securonix Contagious Interview DEVPOPPER April 2024Sekoia ClickFake 2025Sentinel One Contagious Interview ClickFix September 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1589 Gather Victim Identity Information |
GroupStar Blizzard | Star Blizzard has identified ways to engage targets by researching potential victims' interests and social or professional contacts. |
| T1589 Gather Victim Identity Information |
GroupLAPSUS$ | LAPSUS$ has gathered detailed information of target employees to enhance their social engineering lures. |
| T1589 Gather Victim Identity Information |
GroupVOID MANTICORE | VOID MANTICORE has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks. |
| T1589 Gather Victim Identity Information |
GroupHEXANE | HEXANE has identified specific potential victims at targeted organizations. |
| T1589 Gather Victim Identity Information |
GroupMagic Hound | Magic Hound has acquired mobile phone numbers of potential targets, possibly for mobile malware or additional phishing operations. |
| T1589 Gather Victim Identity Information |
GroupFIN13 | FIN13 has researched employees to target for social engineering attacks. |
| T1589.001 Credentials |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 conducted credential theft operations to obtain credentials to be used for access to victim environments. |
| T1589.001 Credentials |
CampaignC0027 | During C0027, Scattered Spider sent phishing messages via SMS to steal credentials. |
| T1589.001 Credentials |
GroupLeviathan | Leviathan has collected compromised credentials to use for targeting efforts. |
| T1589.001 Credentials |
GroupChimera | Chimera has collected credentials for the target organization from previous breaches for use in brute force attacks. |
| T1589.001 Credentials |
GroupAPT28 | APT28 has harvested user's login credentials. |
| T1589.001 Credentials |
GroupLAPSUS$ | LAPSUS$ has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials. |
| T1589.001 Credentials |
GroupMagic Hound | Magic Hound gathered credentials from two victims that they then attempted to validate across 75 different websites. Magic Hound has also collected credentials from over 900 Fortinet VPN servers in the US, Europe, and Israel. |
| T1589.001 Credentials |
GroupShinyHunters | ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS. |
| T1589.002 Email Addresses |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution utilizes thread spoofing of existing email threads in order to execute spear phishing operations. |
| T1589.002 Email Addresses |
CampaignQuad7 Activity | Quad7 Activity has gathered targeted individual’s e-mail addresses for the password spraying attempts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.