Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1653 Power Settings |
MalwareLine Runner | Line Runner used CVE-2024-20353 to trigger victim devices to reboot, in the process unzipping and installing the Line Dancer payload. |
| T1654 Log Enumeration |
GroupVolt Typhoon | Volt Typhoon has used `wevtutil.exe` and the PowerShell command `Get-EventLog security` to enumerate Windows logs to search for successful logons. |
| T1654 Log Enumeration |
GroupMustang Panda | Mustang Panda has used Wevtutil to gather Windows Security Event Logs. |
| T1654 Log Enumeration |
GroupAquatic Panda | Aquatic Panda enumerated logs related to authentication in Linux environments prior to deleting selective entries for defense evasion purposes. |
| T1654 Log Enumeration |
GroupEmber Bear | Ember Bear has enumerated SECURITY and SYSTEM log files during intrusions. |
| T1654 Log Enumeration |
GroupAPT5 | APT5 has used the BLOODMINE utility to parse and extract information from Pulse Secure Connect logs. |
| T1654 Log Enumeration |
MalwareDUSTTRAP | DUSTTRAP can identify infected system log information. |
| T1654 Log Enumeration |
MalwareMegazord | Megazord has the ability to print the trace, debug, error, info, and warning logs. |
| T1654 Log Enumeration |
MalwareBeaverTail | BeaverTail has identified .ldb and .log files stored in browser extension directories for collection and exfiltration. |
| T1654 Log Enumeration |
MalwareAkira _v2 | Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems. |
| T1654 Log Enumeration |
ToolPacu | Pacu can collect CloudTrail event histories and CloudWatch logs. |
| T1657 Financial Theft |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors demanded ransom payments to unencrypt filesystems and to refrain from publishing sensitive data exfiltrated from victim networks. |
| T1657 Financial Theft |
GroupKimsuky | Kimsuky has stolen and laundered cryptocurrency to self-fund operations including the acquisition of infrastructure. |
| T1657 Financial Theft |
GroupAppleJeus | AppleJeus has targeted the cryptocurrency industry with the goal of stealing digital assets. |
| T1657 Financial Theft |
GroupScattered Spider | Scattered Spider has deployed ransomware on compromised hosts and threatened to leak stolen data for financial gain. |
| T1657 Financial Theft |
GroupContagious Interview | Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1657 Financial Theft |
GroupAkira | Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom. |
| T1657 Financial Theft |
GroupSilverTerrier | SilverTerrier targets organizations in high technology, higher education, and manufacturing for business email compromise (BEC) campaigns with the goal of financial theft. |
| T1657 Financial Theft |
GroupStorm-0501 | Storm-0501 has engaged in double-extortion ransomware, exfiltrating data and directly contacting victims when the primary organization refuses to pay along with posting data on their data leak sites. |
| T1657 Financial Theft |
GroupCinnamon Tempest | Cinnamon Tempest has maintained leak sites for exfiltrated data in attempt to extort victims into paying a ransom. |
| T1657 Financial Theft |
GroupMedusa Group | Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom. |
| T1657 Financial Theft |
GroupWater Galura | Water Galura has extorted victims for ransomware decryption keys and to prevent publication of data exfiltrated to their Tor data leak site. |
| T1657 Financial Theft |
GroupMalteiro | Malteiro targets organizations in a wide variety of sectors via the use of Mispadu banking trojan with the goal of financial theft. |
| T1657 Financial Theft |
GroupINC Ransom | INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it. |
| T1657 Financial Theft |
GroupVOID MANTICORE | VOID MANTICORE has conducted data exfiltration and posted stolen information on data leak sites for the purposes of financial and political extortion. VOID MANTICORE has also sold stolen data to prospective buyers for cryptocurrency. |
| T1657 Financial Theft |
GroupPlay | Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks. |
| T1657 Financial Theft |
GroupFIN13 | FIN13 has observed the victim's software and infrastructure over several months to understand the technical process of legitimate financial transactions, prior to attempting to conduct fraudulent transactions. |
| T1657 Financial Theft |
MalwareInvisibleFerret | InvisibleFerret has searched the victim device credentials and files commonly associated with cryptocurrency wallets. |
| T1657 Financial Theft |
MalwareBeaverTail | BeaverTail has searched the victim device for browser extensions commonly associated with cryptocurrency wallets. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025 |
| T1657 Financial Theft |
MalwareDarkGate | DarkGate can deploy payloads capable of capturing credentials related to cryptocurrency wallets. |
| T1657 Financial Theft |
MalwareGlassWorm | GlassWorm has the ability to steal credentials for cryptocurrency wallets. |
| T1657 Financial Theft |
MalwareEmbargo | Embargo has been leveraged in double-extortion ransomware, exfiltrating files then encrypting them, to prompt victims to pay a ransom. |
| T1657 Financial Theft |
MalwareRedLine Stealer | RedLine Stealer has collected data from cryptocurrency wallets and harvested credit cards details from browsers. |
| T1657 Financial Theft |
MalwareCrocodilus | Crocodilus has stolen cryptocurrency wallet details from victim devices. |
| T1657 Financial Theft |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search filesystems for cryptocurrency wallets such as Bitcoin, Litecoin, Dogecoin, Zcash, Dash, Ripple, and Monero. |
| T1657 Financial Theft |
GroupTeamPCP | TeamPCP has engaged in cryptocurrency mining and theft. TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware. |
| T1657 Financial Theft |
GroupShinyHunters | ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com. |
| T1659 Content Injection |
GroupMoustachedBouncer | MoustachedBouncer has injected content into DNS, HTTP, and SMB replies to redirect specifically-targeted victims to a fake Windows Update page to download malware. |
| T1659 Content Injection |
MalwareDisco | Disco has achieved initial access and execution through content injection into DNS, HTTP, and SMB replies to targeted hosts that redirect them to download malicious files. |
| T1665 Hide Infrastructure |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used public Cloud infrastructure to mask malicious activity. |
| T1665 Hide Infrastructure |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 set the hostnames of their C2 infrastructure to match legitimate hostnames in the victim environment. They also used IP addresses originating from the same country as the victim for their VPN infrastructure. |
| T1665 Hide Infrastructure |
CampaignQuad7 Activity | Quad7 Activity has rotated the compromised SOHO IPs used in password spraying activity to hamper detection and network blocking activities by defenders. |
| T1665 Hide Infrastructure |
GroupZIRCONIUM | ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to obfuscate the origin of C2 traffic. |
| T1665 Hide Infrastructure |
GroupAPT29 | APT29 uses compromised residential endpoints, typically within the same ISP IP address range, as proxies to hide the true source of C2 traffic. |
| T1665 Hide Infrastructure |
MalwareJumbledPath | JumbledPath can use a chain of jump hosts to communicate with compromised devices to obscure actor infrastructure. |
| T1665 Hide Infrastructure |
MalwareUPSTYLE | UPSTYLE attempts to retrieve a non-existent webpage from the command and control server resulting in hidden commands sent via resulting error messages. |
| T1665 Hide Infrastructure |
MalwareDarkGate | DarkGate command and control includes hard-coded domains in the malware masquerading as legitimate services such as Akamai CDN or Amazon Web Services. |
| T1667 Email Bombing |
GroupStorm-1811 | Storm-1811 has deployed large volumes of non-malicious email spam to victims in order to prompt follow-on interactions with the threat actor posing as IT support or helpdesk to resolve the problem. |
| T1669 Wi-Fi Networks |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 established wireless connections to secure, enterprise Wi-Fi networks belonging to a target organization for initial access into the environment. |
| T1669 Wi-Fi Networks |
GroupAPT28 | APT28 has exploited open Wi-Fi access points for initial access to target devices using the network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.