Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1608.002 Upload Tool |
GroupMedusa Group | Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise. |
| T1608.002 Upload Tool |
GroupThreat Group-3390 | Threat Group-3390 has staged tools, including gsecdump and WCE, on previously compromised websites. |
| T1608.003 Install Digital Certificate |
GroupSea Turtle | Sea Turtle captured legitimate SSL certificates from victim organizations and installed these on Sea Turtle-controlled infrastructure to enable subsequent adversary-in-the-middle operations. |
| T1608.004 Drive-by Target |
CampaignC0010 | For C0010, the threat actors compromised the login page of a legitimate Israeli shipping company and likely established a watering hole that collected visitor information. |
| T1608.004 Drive-by Target |
GroupMustard Tempest | Mustard Tempest has injected malicious JavaScript into compromised websites to infect victims via drive-by download. |
| T1608.004 Drive-by Target |
GroupDragonfly | Dragonfly has compromised websites to redirect traffic and to host exploit kits. |
| T1608.004 Drive-by Target |
GroupAPT32 | APT32 has stood up websites containing numerous articles and content scraped from the Internet to make them appear legitimate, but some of these pages include malicious JavaScript to profile the potential victim or infect them via a fake software update. |
| T1608.004 Drive-by Target |
GroupFIN7 | FIN7 has compromised a digital product website and modified multiple download links to point to trojanized versions of offered digital products. |
| T1608.004 Drive-by Target |
GroupCURIUM | CURIUM used strategic website compromise to fingerprint then target victims. |
| T1608.004 Drive-by Target |
GroupLuminousMoth | LuminousMoth has redirected compromised machines to an actor-controlled webpage through HTML injection. |
| T1608.004 Drive-by Target |
GroupTransparent Tribe | Transparent Tribe has set up websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools. |
| T1608.004 Drive-by Target |
GroupThreat Group-3390 | Threat Group-3390 has embedded malicious code into websites to screen a potential victim's IP address and then exploit their browser if they are of interest. |
| T1608.005 Link Target |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used links to direct victims to malicious files hosted on OneDrive. |
| T1608.005 Link Target |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors established an Okta phishing panel which victims were tricked into accessing from mobile phones or work computers during social engineering calls. |
| T1608.005 Link Target |
GroupFIN7 | FIN7 has created a fake link that redirected to an adversary-controlled Dropbox that downloaded the malicious executable. |
| T1608.005 Link Target |
GroupSilent Librarian | Silent Librarian has cloned victim organization login pages and staged them for later use in credential harvesting campaigns. Silent Librarian has also made use of a variety of URL shorteners for these staged websites. |
| T1608.005 Link Target |
GroupLuminousMoth | LuminousMoth has created a link to a Dropbox file that has been used in their spear-phishing operations. |
| T1608.006 SEO Poisoning |
GroupMustard Tempest | Mustard Tempest has poisoned search engine results to return fake software updates in order to distribute malware. |
| T1609 Container Administration Command |
GroupTeamTNT | TeamTNT executed Hildegard through the kubelet API run command and by executing commands on running containers. |
| T1609 Container Administration Command |
MalwareHildegard | Hildegard was executed through the kubelet API run command and by executing commands on running containers. |
| T1609 Container Administration Command |
MalwareSiloscape | Siloscape can send kubectl commands to victim clusters through an IRC channel and can run kubectl locally to spread once within a victim cluster. |
| T1609 Container Administration Command |
MalwareKinsing | Kinsing was executed with an Ubuntu container entry point that runs shell scripts. |
| T1609 Container Administration Command |
ToolPeirates | Peirates can use `kubectl` or the Kubernetes API to run commands. |
| T1609 Container Administration Command |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `kubectl get secrets` to extract credentials from Kubernetes. |
| T1609 Container Administration Command |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized container administration commands to gather details of compromised hosts and gather credentials to include Kubernetes command-line utilities `kubectl get secrets`. |
| T1609 Container Administration Command |
MalwareCanisterWorm | CanisterWorm can deploy privileged DaemonSets in Kubernetes clusters for data wiping using kubectl. |
| T1610 Deploy Container |
MalwareKinsing | Kinsing was run through a deployed Ubuntu container. |
| T1610 Deploy Container |
GroupTeamTNT | TeamTNT has deployed different types of containers into victim environments to facilitate execution. TeamTNT has also transferred cryptocurrency mining software to Kubernetes clusters discovered within local IP address ranges. |
| T1610 Deploy Container |
ToolPeirates | Peirates can deploy a pod that mounts its node’s root file system, then execute a command to create a reverse shell on the node. |
| T1610 Deploy Container |
MalwareDoki | Doki was run through a deployed container. |
| T1611 Escape to Host |
GroupTeamTNT | TeamTNT has deployed privileged containers that mount the filesystem of victim machine. |
| T1611 Escape to Host |
MalwareHildegard | Hildegard has used the BOtB tool that can break out of containers. |
| T1611 Escape to Host |
MalwareDoki | Doki’s container was configured to bind the host root directory. |
| T1611 Escape to Host |
MalwareSiloscape | Siloscape maps the host’s C drive to the container by creating a global symbolic link to the host through the calling of |
| T1611 Escape to Host |
ToolPeirates | Peirates can gain a reverse shell on a host node by mounting the Kubernetes hostPath. |
| T1613 Container and Resource Discovery |
GroupTeamTNT | TeamTNT has checked for running containers with |
| T1613 Container and Resource Discovery |
MalwareHildegard | Hildegard has used masscan to search for kubelets and the kubelet API for additional running containers. |
| T1613 Container and Resource Discovery |
ToolPeirates | Peirates can enumerate Kubernetes pods in a given namespace. |
| T1613 Container and Resource Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify Docker and Kubernetes environments for credentials. |
| T1613 Container and Resource Discovery |
MalwareCanisterWorm | CanisterWorm has performed environment fingerprinting to identify Kubernetes clusters. CanisterWorm has also searched for Kubernetes pods using the command ` os.path.exists("/var/run/secrets/kubernetes.io/serviceaccount") or "KUBERNETES_SERVICE_HOST" in os.environ `. |
| T1614 System Location Discovery |
GroupSideCopy | SideCopy has identified the country location of a compromised host. |
| T1614 System Location Discovery |
GroupVolt Typhoon | Volt Typhoon has obtained the victim's system current location. |
| T1614 System Location Discovery |
MalwareAmadey | Amadey does not run any tasks or install additional malware if the victim machine is based in Russia. |
| T1614 System Location Discovery |
MalwareTsundere Botnet | Tsundere Botnet has checked the victim machine’s location by obtaining the culture name of the machine. |
| T1614 System Location Discovery |
MalwareInvisibleFerret | InvisibleFerret has collected the internal IP address, IP geolocation information of the infected host and sends the data to a C2 server. InvisibleFerret has also leveraged the “pay” module to obtain region name, country, city, zip code, ISP, latitude and longitude using “http://ip-api.com/json”. |
| T1614 System Location Discovery |
MalwareCrimson | Crimson can identify the geographical location of a victim host. |
| T1614 System Location Discovery |
MalwareGootloader | Gootloader can use IP geolocation to determine if the person browsing to a compromised site is within a targeted territory such as the US, Canada, Germany, and South Korea. |
| T1614 System Location Discovery |
MalwareHexEval Loader | HexEval Loader has a function where the C2 endpoint can identify the geographical location of a victim host based on request headers, execution environment and runtime conditions. |
| T1614 System Location Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can determine the geographical location of a victim host by checking the language. |
| T1614 System Location Discovery |
MalwareSameCoin | SameCoin can attempt to connect to the Israel Home Front Command site, oref.org[.]il, which is only reachable from within Israel to verify the target's location. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.