ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1599
Network Boundary Bridging
GroupAPT41

APT41 used `NATBypass` to bypass firewall restrictions and to access compromised systems via RDP.

T1601
Modify System Image
MalwareDRYHOOK

DRYHOOK has modified the Ivanti Connect Secure VPN authentication Perl module `DSAuth.pm` by reading its contents in the buffer, then finding and replacing select lines of code.

T1601.001
Patch System Image
MalwareSYNful Knock

SYNful Knock is malware that is inserted into a network device by patching the operating system image.

T1602.002
Network Device Configuration Dump
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries gathered and used the FortiGate bookmarks defined in the configuration file to include the statically defined credentials that facilitated RDP connections to jump hosts.

T1602.002
Network Device Configuration Dump
GroupSalt Typhoon

Salt Typhoon has attempted to acquire credentials by dumping network device configurations.

T1602.002
Network Device Configuration Dump
MalwareGlassWorm

GlassWorm has gathered data pertaining to VPN configurations. GlassWorm has also targeted locally stored data on macOS located in `/Library/Application Support/Fortinet/FortiClient/conf/vpn.plist`.

T1606.001
Web Cookies
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 bypassed MFA set on OWA accounts by generating a cookie value from a previously stolen secret key.

T1606.002
SAML Tokens
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 created tokens using compromised SAML signing certificates.

T1606.002
SAML Tokens
ToolAADInternals

AADInternals can be used to create SAML tokens using the AD Federated Services token signing certificate.

T1608
Stage Capabilities
GroupMustang Panda

Mustang Panda has used servers under their control to validate tracking pixels sent to phishing victims.

T1608.001
Upload Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used compromised servers to host malware.

T1608.001
Upload Malware
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda staged malware on adversary-controlled domains and cloud storage instances during RedDelta Modified PlugX Infection Chain Operations.

T1608.001
Upload Malware
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors staged malicious files on Dropbox and other websites.

T1608.001
Upload Malware
CampaignOperation Spalax

For Operation Spalax, the threat actors staged malware and malicious files in legitimate hosting services such as OneDrive or MediaFire.

T1608.001
Upload Malware
CampaignC0021

For C0021, the threat actors uploaded malware to websites under their control.

T1608.001
Upload Malware
CampaignC0010

For C0010, UNC3890 actors staged malware on their infrastructure for direct download onto a compromised system.

T1608.001
Upload Malware
CampaignNight Dragon

During Night Dragon, threat actors uploaded commonly available hacker tools to compromised web servers.

T1608.001
Upload Malware
CampaignC0011

For C0011, Transparent Tribe hosted malicious documents on domains registered by the group.

T1608.001
Upload Malware
GroupBlackByte

BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites.

T1608.001
Upload Malware
GroupSideCopy

SideCopy has used compromised domains to host its malicious payloads.

T1608.001
Upload Malware
GroupMustard Tempest

Mustard Tempest has hosted payloads on acquired second-stage servers for periods of either days, weeks, or months.

T1608.001
Upload Malware
GroupKimsuky

Kimsuky has used compromised and acquired infrastructure to host and deliver malware including Blogspot to host beacons, file exfiltrators, and implants. Kimsuky has also hosted malicious payloads on Dropbox.

T1608.001
Upload Malware
GroupEXOTIC LILY

EXOTIC LILY has uploaded malicious payloads to file-sharing services including TransferNow, TransferXL, WeTransfer, and OneDrive.

T1608.001
Upload Malware
GroupAPT32

APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting.

T1608.001
Upload Malware
GroupGamaredon Group

Gamaredon Group has registered domains to stage payloads.

T1608.001
Upload Malware
GroupTeamTNT

TeamTNT has uploaded backdoored Docker images to Docker Hub.

T1608.001
Upload Malware
GroupFIN7

FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3. FIN7 has also used an open directory web server as a staging server for payloads and other tools, such as OpenSSH and 7zip.

T1608.001
Upload Malware
GroupSandworm Team

Sandworm Team staged compromised versions of legitimate software installers in forums to enable initial access to executing user.

T1608.001
Upload Malware
GroupMustang Panda

Mustang Panda has hosted malicious payloads on DropBox including PlugX.

T1608.001
Upload Malware
GroupContagious Interview

Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download.

T1608.001
Upload Malware
GroupTA2541

TA2541 has uploaded malware to various platforms including Google Drive, Pastetext, Sharetext, and GitHub.

T1608.001
Upload Malware
GroupOilRig

OilRig has hosted malware on fake websites designed to target specific audiences.

T1608.001
Upload Malware
GroupSaint Bear

Saint Bear has used the Discord content delivery network for hosting malicious content referenced in links and emails.

T1608.001
Upload Malware
GroupTA505

TA505 has staged malware on actor-controlled domains.

T1608.001
Upload Malware
GroupBITTER

BITTER has registered domains to stage payloads.

T1608.001
Upload Malware
GroupStar Blizzard

Star Blizzard has uploaded malicious payloads to cloud storage sites.

T1608.001
Upload Malware
GroupLazyScripter

LazyScripter has hosted open-source remote access Trojans used in its operations in GitHub.

T1608.001
Upload Malware
GroupLuminousMoth

LuminousMoth has hosted malicious payloads on Dropbox.

T1608.001
Upload Malware
GroupAPT42

APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application.

T1608.001
Upload Malware
GroupAPT-C-36

APT-C-36 has staged malware implants on group-owned repositories and sites.

T1608.001
Upload Malware
GroupEarth Lusca

Earth Lusca has staged malware and malicious files on compromised web servers, GitHub, and Google Drive.

T1608.001
Upload Malware
GroupMoonstone Sleet

Moonstone Sleet staged malicious capabilities online for follow-on download by victims or malware.

T1608.001
Upload Malware
GroupHEXANE

HEXANE has staged malware on fraudulent websites set up to impersonate targeted organizations.

T1608.001
Upload Malware
GroupWIRTE

WIRTE has directed victims to malicious payloads staged on file sharing services.

T1608.001
Upload Malware
GroupThreat Group-3390

Threat Group-3390 has hosted malicious payloads on Dropbox.

T1608.001
Upload Malware
MalwareShai-Hulud

Shai-Hulud has published malicious gzip-compressed tarball (.tgz) following modification of packages within compromised accounts. Shai-Hulud has also modified packages within compromised accounts.

T1608.001
Upload Malware
GroupTeamPCP

TeamPCP has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains.

T1608.002
Upload Tool
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used multiple servers to host malicious tools.

T1608.002
Upload Tool
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had staged tools and files for use on Dropbox and Pastebin.

T1608.002
Upload Tool
CampaignC0010

For C0010, UNC3890 actors staged tools on their infrastructure to download directly onto a compromised system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.