Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1589.002 Email Addresses |
GroupKimsuky | Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering. |
| T1589.002 Email Addresses |
GroupEXOTIC LILY | EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms. |
| T1589.002 Email Addresses |
GroupVolt Typhoon | Volt Typhoon has targeted the personal emails of key network and IT staff at victim organizations. |
| T1589.002 Email Addresses |
GroupAPT32 | APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware. |
| T1589.002 Email Addresses |
GroupHAFNIUM | HAFNIUM has collected e-mail addresses for users they intended to target. |
| T1589.002 Email Addresses |
GroupSandworm Team | Sandworm Team has obtained valid emails addresses while conducting research against target organizations that were subsequently used in spearphishing campaigns. |
| T1589.002 Email Addresses |
GroupSaint Bear | Saint Bear gathered victim email information in advance of phishing operations for targeted attacks. |
| T1589.002 Email Addresses |
GroupSilent Librarian | Silent Librarian has collected e-mail addresses from targeted organizations from open Internet searches. |
| T1589.002 Email Addresses |
GroupTA551 | TA551 has used spoofed company emails that were acquired from email clients on previously infected hosts to target other individuals. |
| T1589.002 Email Addresses |
GroupLazarus Group | Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns. |
| T1589.002 Email Addresses |
GroupLAPSUS$ | LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts. |
| T1589.002 Email Addresses |
GroupMoonstone Sleet | Moonstone Sleet gathered victim email address information for follow-on phishing activity. |
| T1589.002 Email Addresses |
GroupHEXANE | HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing. |
| T1589.002 Email Addresses |
GroupMagic Hound | Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting. |
| T1589.002 Email Addresses |
ToolAADInternals | AADInternals can check for the existence of user email addresses using public Microsoft APIs. |
| T1589.003 Employee Names |
GroupKimsuky | Kimsuky has collected victim employee name information. |
| T1589.003 Employee Names |
GroupSandworm Team | Sandworm Team's research of potential victim organizations included the identification and collection of employee information. |
| T1589.003 Employee Names |
GroupSilent Librarian | Silent Librarian has collected lists of names for individuals from targeted organizations. |
| T1590 Gather Victim Network Information |
GroupIndrik Spider | Indrik Spider has downloaded tools, such as the Advanced Port Scanner utility and Lansweeper, to conduct internal reconnaissance of the victim network. Indrik Spider has also accessed the victim’s VMware VCenter, which had information about host configuration, clusters, etc. |
| T1590 Gather Victim Network Information |
GroupVolt Typhoon | Volt Typhoon has conducted extensive pre-compromise reconnaissance to learn about the target organization’s network. |
| T1590 Gather Victim Network Information |
GroupHAFNIUM | HAFNIUM gathered the fully qualified domain names (FQDNs) for targeted Exchange servers in the victim's environment. |
| T1590.001 Domain Properties |
GroupSandworm Team | Sandworm Team conducted technical reconnaissance of the Parliament of Georgia's official internet domain prior to its 2019 attack. |
| T1590.001 Domain Properties |
ToolAADInternals | AADInternals can gather information about a tenant’s domains using public Microsoft APIs. |
| T1590.004 Network Topology |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to map a complete network topology of the target infrastructure. |
| T1590.004 Network Topology |
GroupVolt Typhoon | Volt Typhoon has conducted extensive reconnaissance of victim networks including identifying network topologies. |
| T1590.004 Network Topology |
GroupSalt Typhoon | Salt Typhoon has used configuration files from exploited network devices to help discover upstream and downstream network segments. |
| T1590.004 Network Topology |
GroupMuddyWater | MuddyWater has mapped target networks; access to this information and more is then shared/sold to other Iran threat actors. |
| T1590.004 Network Topology |
GroupFIN13 | FIN13 has searched for infrastructure that can provide remote access to an environment for targeting efforts. |
| T1590.005 IP Addresses |
GroupHAFNIUM | HAFNIUM has obtained IP addresses for publicly-accessible Exchange servers. |
| T1590.005 IP Addresses |
GroupAndariel | Andariel has limited its watering hole attacks to specific IP address ranges. |
| T1590.005 IP Addresses |
GroupMagic Hound | Magic Hound has captured the IP addresses of visitors to their phishing sites. |
| T1590.006 Network Security Appliances |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries obtained details on the configuration of the victim Fortinet perimeter device to include publicly disclosed details on an online forum used by criminal communities. |
| T1590.006 Network Security Appliances |
GroupVolt Typhoon | Volt Typhoon has identified target network security measures as part of pre-compromise reconnaissance. |
| T1591 Gather Victim Org Information |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group gathered victim organization information to identify specific targets. |
| T1591 Gather Victim Org Information |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors concealed malicious activity by using terms that aligned with the technological context of the targeted organization. |
| T1591 Gather Victim Org Information |
GroupKimsuky | Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others. Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest. |
| T1591 Gather Victim Org Information |
GroupVolt Typhoon | Volt Typhoon has conducted extensive reconnaissance pre-compromise to gain information about the targeted organization. |
| T1591 Gather Victim Org Information |
GroupFIN7 | FIN7 has compiled a list of victims by filtering companies by revenue using Zoominfo, which is a service that provides business information. |
| T1591 Gather Victim Org Information |
GroupMirrorFace | MirrorFace has placed specific content in phishing emails to target members of particular political parties. |
| T1591 Gather Victim Org Information |
GroupAPT28 | APT28 has used large language models (LLMs) to gather information about satellite capabilities. |
| T1591 Gather Victim Org Information |
GroupLazarus Group | Lazarus Group has studied publicly available information about a targeted organization to tailor spearphishing efforts against specific departments and/or individuals. |
| T1591 Gather Victim Org Information |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim organizations through email and social media interaction. |
| T1591.001 Determine Physical Locations |
GroupMagic Hound | Magic Hound has collected location information from visitors to their phishing sites. |
| T1591.002 Business Relationships |
GroupDragonfly | Dragonfly has collected open source information to identify relationships between organizations for targeting purposes. |
| T1591.002 Business Relationships |
GroupSandworm Team | In preparation for its attack against the 2018 Winter Olympics, Sandworm Team conducted online research of partner organizations listed on an official PyeongChang Olympics partnership site. |
| T1591.002 Business Relationships |
GroupLAPSUS$ | LAPSUS$ has gathered detailed knowledge of an organization's supply chain relationships. |
| T1591.004 Identify Roles |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group targeted specific individuals within an organization with tailored job vacancy announcements. |
| T1591.004 Identify Roles |
GroupVolt Typhoon | Volt Typhoon has identified key network and IT staff members pre-compromise at targeted organizations. |
| T1591.004 Identify Roles |
GroupFIN7 | FIN7 has identified IT staff and employees who had higher levels of administrative rights. |
| T1591.004 Identify Roles |
GroupLAPSUS$ | LAPSUS$ has gathered detailed knowledge of team structures within a target organization. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.