Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1595.002 Vulnerability Scanning |
GroupVolatile Cedar | Volatile Cedar has performed vulnerability scans of the target server. |
| T1595.002 Vulnerability Scanning |
GroupAPT28 | APT28 has performed large-scale scans in an attempt to find vulnerable servers. |
| T1595.002 Vulnerability Scanning |
GroupEarth Lusca | Earth Lusca has scanned for vulnerabilities in the public-facing servers of their targets. |
| T1595.002 Vulnerability Scanning |
GroupVOID MANTICORE | VOID MANTICORE has scanned victim environments for susceptibility to vulnerability exploitation. |
| T1595.002 Vulnerability Scanning |
GroupMagic Hound | Magic Hound has conducted widespread scanning to identify public-facing systems vulnerable to CVE-2021-44228 in Log4j and ProxyShell vulnerabilities; CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in on-premises MS Exchange Servers; and CVE-2018-13379 in Fortinet FortiOS SSL VPNs. |
| T1595.002 Vulnerability Scanning |
GroupShinyHunters | ShinyHunters has searched through victim companies’ GitHub repositories for vulnerabilities. |
| T1595.003 Wordlist Scanning |
GroupAPT41 | APT41 leverages various tools and frameworks to brute-force directories on web servers. |
| T1595.003 Wordlist Scanning |
GroupVolatile Cedar | Volatile Cedar has used DirBuster and GoBuster to brute force web directories and DNS subdomains. |
| T1596 Search Open Technical Databases |
GroupKimsuky | Kimsuky has used LLMs to better understand publicly reported vulnerabilities. |
| T1596 Search Open Technical Databases |
GroupAPT28 | APT28 has used large language models (LLMs) to assist in script development and deployment. |
| T1596.005 Scan Databases |
CampaignAPT41 DUST | APT41 DUST used internet scan data for target development. |
| T1596.005 Scan Databases |
GroupVolt Typhoon | Volt Typhoon has used FOFA, Shodan, and Censys to search for exposed victim infrastructure. |
| T1596.005 Scan Databases |
GroupAPT41 | APT41 uses the Chinese website fofa.su, similar to the Shodan scanning service, for passive scanning of victims. |
| T1597 Search Closed Sources |
GroupEXOTIC LILY | EXOTIC LILY has searched for information on targeted individuals on business databases including RocketReach and CrunchBase. |
| T1597.002 Purchase Technical Data |
GroupLAPSUS$ | LAPSUS$ has purchased credentials and session tokens from criminal underground forums. |
| T1598 Phishing for Information |
GroupKimsuky | Kimsuky has used tailored spearphishing emails to gather victim information including contat lists to identify additional targets. |
| T1598 Phishing for Information |
GroupZIRCONIUM | ZIRCONIUM targeted presidential campaign staffers with credential phishing e-mails. |
| T1598 Phishing for Information |
GroupScattered Spider | Scattered Spider has used a combination of credential phishing and social engineering to capture one-time-password (OTP) codes. |
| T1598 Phishing for Information |
GroupAPT28 | APT28 has used spearphishing to compromise credentials. |
| T1598 Phishing for Information |
GroupMoonstone Sleet | Moonstone Sleet has interacted with victims to gather information via email. |
| T1598 Phishing for Information |
GroupShinyHunters | ShinyHunters has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials. |
| T1598.001 Spearphishing Service |
CampaignC0027 | During C0027, Scattered Spider sent Telegram messages impersonating IT personnel to harvest credentials. |
| T1598.002 Spearphishing Attachment |
GroupSideCopy | SideCopy has crafted generic lures for spam campaigns to collect emails and credentials for targeting efforts. |
| T1598.002 Spearphishing Attachment |
GroupDragonfly | Dragonfly has used spearphishing with Microsoft Office attachments to enable harvesting of user credentials. |
| T1598.002 Spearphishing Attachment |
GroupSidewinder | Sidewinder has sent e-mails with malicious attachments that lead victims to credential harvesting websites. |
| T1598.002 Spearphishing Attachment |
GroupStar Blizzard | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential-stealing sites. |
| T1598.003 Spearphishing Link |
GroupKimsuky | Kimsuky has used links in e-mail to steal account information including web beacons for target profiling. Kimsuky has also utilized QR codes (also known as Quishing) to direct victims to malicious links through the reliance of a mobile device to scan a code with an embedded malicious URL. |
| T1598.003 Spearphishing Link |
GroupPatchwork | Patchwork has used embedded image tags (known as web bugs) with unique, per-recipient tracking links in their emails for the purpose of identifying which recipients opened messages. |
| T1598.003 Spearphishing Link |
GroupDragonfly | Dragonfly has used spearphishing with PDF attachments containing malicious links that redirected to credential harvesting websites. |
| T1598.003 Spearphishing Link |
GroupAPT32 | APT32 has used malicious links to direct users to web pages designed to harvest credentials. |
| T1598.003 Spearphishing Link |
GroupSandworm Team | Sandworm Team has crafted spearphishing emails with hyperlinks designed to trick unwitting recipients into revealing their account credentials. |
| T1598.003 Spearphishing Link |
GroupCURIUM | CURIUM used malicious links to adversary-controlled resources for credential harvesting. |
| T1598.003 Spearphishing Link |
GroupSidewinder | Sidewinder has sent e-mails with malicious links to credential harvesting websites. |
| T1598.003 Spearphishing Link |
GroupMustang Panda | Mustang Panda has delivered web bugs to profile their intended targets. |
| T1598.003 Spearphishing Link |
GroupZIRCONIUM | ZIRCONIUM has used web beacons in e-mails to track hits to attacker-controlled URL's. |
| T1598.003 Spearphishing Link |
GroupScattered Spider | Scattered Spider has used domains mirroring corporate login portals to socially engineer victims into providing credentials. |
| T1598.003 Spearphishing Link |
GroupSilent Librarian | Silent Librarian has used links in e-mails to direct victims to credential harvesting websites designed to appear like the targeted organization's login page. |
| T1598.003 Spearphishing Link |
GroupStar Blizzard | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites. |
| T1598.003 Spearphishing Link |
GroupAPT28 | APT28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites. |
| T1598.003 Spearphishing Link |
GroupMoonstone Sleet | Moonstone Sleet used spearphishing messages containing items such as tracking pixels to determine if users interacted with malicious messages. |
| T1598.003 Spearphishing Link |
GroupMagic Hound | Magic Hound has used SMS and email messages with links designed to steal credentials or track victims. |
| T1598.003 Spearphishing Link |
MalwareSMOKEDHAM | SMOKEDHAM has been delivered via malicious links in phishing emails. |
| T1598.003 Spearphishing Link |
Toolevilginx2 | evilginx2 can generate and display phishing URLs including hidden tracking pixels and can also embed URLs within iframes for browser-in-the-browser phishing. |
| T1598.003 Spearphishing Link |
ToolAADInternals | AADInternals can send phishing emails containing malicious links designed to collect users’ credentials. |
| T1598.003 Spearphishing Link |
GroupShinyHunters | ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials. |
| T1598.004 Spearphishing Voice |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors initiated voice calls with victims to socially engineer them into authorizing malicious applications or divulging sensitive credentials. |
| T1598.004 Spearphishing Voice |
CampaignC0027 | During C0027, Scattered Spider used phone calls to instruct victims to navigate to credential-harvesting websites. |
| T1598.004 Spearphishing Voice |
GroupScattered Spider | Scattered Spider has used help desk voice-based phishing and also called employees at target organizations and compelled them to navigate to fake login portals using adversary-in-the-middle toolkits. |
| T1598.004 Spearphishing Voice |
GroupLAPSUS$ | LAPSUS$ has called victims' help desk to convince the support personnel to reset a privileged account’s credentials. |
| T1599 Network Boundary Bridging |
CampaignIndian Critical Infrastructure Intrusions | Indian Critical Infrastructure Intrusions involved the use of FRP to bridge network boundaries and overcome NAT. Indian Critical Infrastructure Intrusions also involved the use of VPN tunnels with a potentially compromised MSP entity allowing for direct access to critical infrastructure entity networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.