ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1588.003
Code Signing Certificates
GroupOilRig

OilRig has obtained stolen code signing certificates to digitally sign malware.

T1588.003
Code Signing Certificates
GroupBlackTech

BlackTech has used stolen code-signing certificates for its malicious payloads.

T1588.003
Code Signing Certificates
GroupWizard Spider

Wizard Spider has obtained code signing certificates signed by DigiCert, GlobalSign, and COMOOD for malware payloads.

T1588.003
Code Signing Certificates
GroupThreat Group-3390

Threat Group-3390 has obtained stolen valid certificates, including from VMProtect and the Chinese instant messaging application Youdu, for their operations.

T1588.003
Code Signing Certificates
GroupFIN8

FIN8 has used an expired open-source X.509 certificate for testing in the OpenSSL repository, to connect to actor-controlled C2 servers.

T1588.003
Code Signing Certificates
MalwareMegaCortex

MegaCortex has used code signing certificates issued to fake companies to bypass security controls.

T1588.004
Digital Certificates
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda acquired Cloudflare Origin CA TLS certificates during RedDelta Modified PlugX Infection Chain Operations.

T1588.004
Digital Certificates
CampaignOperation Honeybee

For Operation Honeybee, the threat actors stole a digital signature from Adobe Systems to use with their MaoCheng dropper.

T1588.004
Digital Certificates
CampaignIndian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions included the use of digital certificates spoofing Microsoft.

T1588.004
Digital Certificates
GroupMustang Panda

Mustang Panda has obtained SSL certificates for their C2 domains.

T1588.004
Digital Certificates
GroupUNC3886

UNC3886 has deployed malware using the victim's legitimate TLS certificate obtained from a compromised FortiGate device.

T1588.004
Digital Certificates
GroupSea Turtle

Sea Turtle created new certificates using a technique called the actors performed "certificate impersonation," a technique in which Sea Turtle obtained a certificate authority-signed X.509 certificate from another provider for the same domain imitating the one already used by the targeted organization.

T1588.004
Digital Certificates
GroupBlackTech

BlackTech has used valid, stolen digital certificates for some of their malware and tools.

T1588.004
Digital Certificates
GroupSilent Librarian

Silent Librarian has obtained free Let's Encrypt SSL certificates for use on their phishing pages.

T1588.004
Digital Certificates
GroupLuminousMoth

LuminousMoth has used a valid digital certificate for some of their malware.

T1588.004
Digital Certificates
GroupLazarus Group

Lazarus Group has obtained SSL certificates for their C2 domains.

T1588.005
Exploits
GroupKimsuky

Kimsuky has obtained exploit code for various CVEs.

T1588.005
Exploits
GroupEmber Bear

Ember Bear has obtained exploitation scripts against publicly-disclosed vulnerabilities from public repositories.

T1588.006
Vulnerabilities
CampaignLeviathan Australian Intrusions

Leviathan weaponized publicly-known vulnerabilities for initial access and other purposes during Leviathan Australian Intrusions.

T1588.006
Vulnerabilities
GroupVolt Typhoon

Volt Typhoon has used publicly available exploit code for initial access.

T1588.006
Vulnerabilities
GroupSandworm Team

In 2017, Sandworm Team conducted technical research related to vulnerabilities associated with websites used by the Korean Sport and Olympic Committee, a Korean power company, and a Korean airport.

T1588.006
Vulnerabilities
GroupStorm-0501

Storm-0501 has obtained capabilities to exploit N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203).

T1588.007
Artificial Intelligence
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary obtained access to Claude Code to support cyber intrusion operations.

T1588.007
Artificial Intelligence
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries generated custom script with an LLM.

T1588.007
Artificial Intelligence
GroupContagious Interview

Contagious Interview has appeared to have used AI to generate images and content to facilitate their campaigns.

T1588.007
Artificial Intelligence
GroupAPT28

APT28 has deployed LAMEHUG which can can query an LLM to generate and return commands for post compromise activity on targeted systems.

T1588.007
Artificial Intelligence
MalwareLazyWiper

LazyWiper is believed to have been generated by a large language model (LLM) due to the non-sensical comments in the code.

T1588.007
Artificial Intelligence
GroupShinyHunters

ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks.

T1589
Gather Victim Identity Information
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group conducted extensive reconnaissance research on potential targets.

T1589
Gather Victim Identity Information
CampaignOperation Wocao

During Operation Wocao, threat actors targeted people based on their organizational roles and privileges.

T1589
Gather Victim Identity Information
GroupVolt Typhoon

Volt Typhoon has gathered victim identify information during pre-compromise reconnaissance.

T1589
Gather Victim Identity Information
GroupAPT32

APT32 has conducted targeted surveillance against activists and bloggers.

T1589
Gather Victim Identity Information
GroupScattered Spider

Scattered Spider has used information from previous data breaches to identify employee names to be used in social engineering.

T1589
Gather Victim Identity Information
GroupContagious Interview

Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies.

T1589
Gather Victim Identity Information
GroupStar Blizzard

Star Blizzard has identified ways to engage targets by researching potential victims' interests and social or professional contacts.

T1589
Gather Victim Identity Information
GroupLAPSUS$

LAPSUS$ has gathered detailed information of target employees to enhance their social engineering lures.

T1589
Gather Victim Identity Information
GroupVOID MANTICORE

VOID MANTICORE has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks.

T1589
Gather Victim Identity Information
GroupHEXANE

HEXANE has identified specific potential victims at targeted organizations.

T1589
Gather Victim Identity Information
GroupMagic Hound

Magic Hound has acquired mobile phone numbers of potential targets, possibly for mobile malware or additional phishing operations.

T1589
Gather Victim Identity Information
GroupFIN13

FIN13 has researched employees to target for social engineering attacks.

T1589.001
Credentials
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 conducted credential theft operations to obtain credentials to be used for access to victim environments.

T1589.001
Credentials
CampaignC0027

During C0027, Scattered Spider sent phishing messages via SMS to steal credentials.

T1589.001
Credentials
GroupLeviathan

Leviathan has collected compromised credentials to use for targeting efforts.

T1589.001
Credentials
GroupChimera

Chimera has collected credentials for the target organization from previous breaches for use in brute force attacks.

T1589.001
Credentials
GroupAPT28

APT28 has harvested user's login credentials.

T1589.001
Credentials
GroupLAPSUS$

LAPSUS$ has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials.

T1589.001
Credentials
GroupMagic Hound

Magic Hound gathered credentials from two victims that they then attempted to validate across 75 different websites. Magic Hound has also collected credentials from over 900 Fortinet VPN servers in the US, Europe, and Israel.

T1589.001
Credentials
GroupShinyHunters

ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS.

T1589.002
Email Addresses
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution utilizes thread spoofing of existing email threads in order to execute spear phishing operations.

T1589.002
Email Addresses
CampaignQuad7 Activity

Quad7 Activity has gathered targeted individual’s e-mail addresses for the password spraying attempts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.