Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1599 Network Boundary Bridging |
GroupAPT41 | APT41 used `NATBypass` to bypass firewall restrictions and to access compromised systems via RDP. |
| T1601 Modify System Image |
MalwareDRYHOOK | DRYHOOK has modified the Ivanti Connect Secure VPN authentication Perl module `DSAuth.pm` by reading its contents in the buffer, then finding and replacing select lines of code. |
| T1601.001 Patch System Image |
MalwareSYNful Knock | SYNful Knock is malware that is inserted into a network device by patching the operating system image. |
| T1602.002 Network Device Configuration Dump |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries gathered and used the FortiGate bookmarks defined in the configuration file to include the statically defined credentials that facilitated RDP connections to jump hosts. |
| T1602.002 Network Device Configuration Dump |
GroupSalt Typhoon | Salt Typhoon has attempted to acquire credentials by dumping network device configurations. |
| T1602.002 Network Device Configuration Dump |
MalwareGlassWorm | GlassWorm has gathered data pertaining to VPN configurations. GlassWorm has also targeted locally stored data on macOS located in `/Library/Application Support/Fortinet/FortiClient/conf/vpn.plist`. |
| T1606.001 Web Cookies |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 bypassed MFA set on OWA accounts by generating a cookie value from a previously stolen secret key. |
| T1606.002 SAML Tokens |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 created tokens using compromised SAML signing certificates. |
| T1606.002 SAML Tokens |
ToolAADInternals | AADInternals can be used to create SAML tokens using the AD Federated Services token signing certificate. |
| T1608 Stage Capabilities |
GroupMustang Panda | Mustang Panda has used servers under their control to validate tracking pixels sent to phishing victims. |
| T1608.001 Upload Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used compromised servers to host malware. |
| T1608.001 Upload Malware |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda staged malware on adversary-controlled domains and cloud storage instances during RedDelta Modified PlugX Infection Chain Operations. |
| T1608.001 Upload Malware |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors staged malicious files on Dropbox and other websites. |
| T1608.001 Upload Malware |
CampaignOperation Spalax | For Operation Spalax, the threat actors staged malware and malicious files in legitimate hosting services such as OneDrive or MediaFire. |
| T1608.001 Upload Malware |
CampaignC0021 | For C0021, the threat actors uploaded malware to websites under their control. |
| T1608.001 Upload Malware |
CampaignC0010 | For C0010, UNC3890 actors staged malware on their infrastructure for direct download onto a compromised system. |
| T1608.001 Upload Malware |
CampaignNight Dragon | During Night Dragon, threat actors uploaded commonly available hacker tools to compromised web servers. |
| T1608.001 Upload Malware |
CampaignC0011 | For C0011, Transparent Tribe hosted malicious documents on domains registered by the group. |
| T1608.001 Upload Malware |
GroupBlackByte | BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites. |
| T1608.001 Upload Malware |
GroupSideCopy | SideCopy has used compromised domains to host its malicious payloads. |
| T1608.001 Upload Malware |
GroupMustard Tempest | Mustard Tempest has hosted payloads on acquired second-stage servers for periods of either days, weeks, or months. |
| T1608.001 Upload Malware |
GroupKimsuky | Kimsuky has used compromised and acquired infrastructure to host and deliver malware including Blogspot to host beacons, file exfiltrators, and implants. Kimsuky has also hosted malicious payloads on Dropbox. |
| T1608.001 Upload Malware |
GroupEXOTIC LILY | EXOTIC LILY has uploaded malicious payloads to file-sharing services including TransferNow, TransferXL, WeTransfer, and OneDrive. |
| T1608.001 Upload Malware |
GroupAPT32 | APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting. |
| T1608.001 Upload Malware |
GroupGamaredon Group | Gamaredon Group has registered domains to stage payloads. |
| T1608.001 Upload Malware |
GroupTeamTNT | TeamTNT has uploaded backdoored Docker images to Docker Hub. |
| T1608.001 Upload Malware |
GroupFIN7 | FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3. FIN7 has also used an open directory web server as a staging server for payloads and other tools, such as OpenSSH and 7zip. |
| T1608.001 Upload Malware |
GroupSandworm Team | Sandworm Team staged compromised versions of legitimate software installers in forums to enable initial access to executing user. |
| T1608.001 Upload Malware |
GroupMustang Panda | Mustang Panda has hosted malicious payloads on DropBox including PlugX. |
| T1608.001 Upload Malware |
GroupContagious Interview | Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview October 2024Securonix Contagious Interview DEVPOPPER April 2024Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1608.001 Upload Malware |
GroupTA2541 | TA2541 has uploaded malware to various platforms including Google Drive, Pastetext, Sharetext, and GitHub. |
| T1608.001 Upload Malware |
GroupOilRig | OilRig has hosted malware on fake websites designed to target specific audiences. |
| T1608.001 Upload Malware |
GroupSaint Bear | Saint Bear has used the Discord content delivery network for hosting malicious content referenced in links and emails. |
| T1608.001 Upload Malware |
GroupTA505 | TA505 has staged malware on actor-controlled domains. |
| T1608.001 Upload Malware |
GroupBITTER | BITTER has registered domains to stage payloads. |
| T1608.001 Upload Malware |
GroupStar Blizzard | Star Blizzard has uploaded malicious payloads to cloud storage sites. |
| T1608.001 Upload Malware |
GroupLazyScripter | LazyScripter has hosted open-source remote access Trojans used in its operations in GitHub. |
| T1608.001 Upload Malware |
GroupLuminousMoth | LuminousMoth has hosted malicious payloads on Dropbox. |
| T1608.001 Upload Malware |
GroupAPT42 | APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application. |
| T1608.001 Upload Malware |
GroupAPT-C-36 | APT-C-36 has staged malware implants on group-owned repositories and sites. |
| T1608.001 Upload Malware |
GroupEarth Lusca | Earth Lusca has staged malware and malicious files on compromised web servers, GitHub, and Google Drive. |
| T1608.001 Upload Malware |
GroupMoonstone Sleet | Moonstone Sleet staged malicious capabilities online for follow-on download by victims or malware. |
| T1608.001 Upload Malware |
GroupHEXANE | HEXANE has staged malware on fraudulent websites set up to impersonate targeted organizations. |
| T1608.001 Upload Malware |
GroupWIRTE | WIRTE has directed victims to malicious payloads staged on file sharing services. |
| T1608.001 Upload Malware |
GroupThreat Group-3390 | Threat Group-3390 has hosted malicious payloads on Dropbox. |
| T1608.001 Upload Malware |
MalwareShai-Hulud | Shai-Hulud has published malicious gzip-compressed tarball (.tgz) following modification of packages within compromised accounts. Shai-Hulud has also modified packages within compromised accounts. |
| T1608.001 Upload Malware |
GroupTeamPCP | TeamPCP has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains. |
| T1608.002 Upload Tool |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used multiple servers to host malicious tools. |
| T1608.002 Upload Tool |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had staged tools and files for use on Dropbox and Pastebin. |
| T1608.002 Upload Tool |
CampaignC0010 | For C0010, UNC3890 actors staged tools on their infrastructure to download directly onto a compromised system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.