Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1683.002 Audio-Visual Content |
GroupContagious Interview | Contagious Interview has used AI to clone video-conferencing applications to distribute their BeaverTail malware. They have also used AI to create deepfake videos. |
| T1683.002 Audio-Visual Content |
GroupAPT-C-36 | APT-C-36 has used phishing pages appearing like legitimate banking login portals to compromise credentials. |
| T1684 Social Engineering |
GroupShinyHunters | ShinyHunters has used social engineering to demand payment from victims. |
| T1684.001 Impersonation |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group impersonated HR hiring personnel through LinkedIn messages and conducted interviews with victims in order to deceive them into downloading malware. |
| T1684.001 Impersonation |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors impersonated IT support personnel in voice calls with victims at times claiming to be addressing enterprise-wide connectivity issues. |
| T1684.001 Impersonation |
CampaignC0027 | During C0027, Scattered Spider impersonated legitimate IT personnel in phone calls and text messages either to direct victims to a credential harvesting site or getting victims to run commercial remote monitoring and management (RMM) tools. |
| T1684.001 Impersonation |
GroupKimsuky | Kimsuky has also impersonated legitimate people, such as a foreign advisor, an embassy employee, and a think tank employee. Kimsuky has also purported to be a Japanese diplomat to communicate with the victims. |
| T1684.001 Impersonation |
GroupAPT41 | APT41 impersonated an employee at a video game developer company to send phishing emails. |
| T1684.001 Impersonation |
GroupMuddyWater | MuddyWater has used support@microsoftonlines[.]com to send phishing emails that masqueraded as security updates from Microsoft. MuddyWater has also impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain info@tmcell. |
| T1684.001 Impersonation |
GroupStorm-1811 | Storm-1811 impersonates help desk and IT support personnel for phishing and social engineering purposes during initial access to victim environments. |
| T1684.001 Impersonation |
GroupScattered Spider | Scattered Spider utilized social engineering to compel IT help desk personnel to reset passwords and MFA tokens. Scattered Spider has also used Microsoft Teams to pose as internal IT support or help desk personnel. |
| T1684.001 Impersonation |
GroupContagious Interview | Contagious Interview had impersonated HR hiring personnel through social media, job board notifications, and conducted interviews with victims in order to entice them to download malware disguised as legitimate applications or malicious scripts from code repositories. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Securonix Contagious Interview DEVPOPPER April 2024Sentinel One Contagious Interview ClickFix September 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1684.001 Impersonation |
GroupSaint Bear | Saint Bear has impersonated government and related entities in both phishing activity and developing web sites with malicious links that mimic legitimate resources. |
| T1684.001 Impersonation |
GroupMirrorFace | MirrorFace has sent targeted emails purporting to be from a Japanese political party’s PR department. |
| T1684.001 Impersonation |
GroupStar Blizzard | Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target. |
| T1684.001 Impersonation |
GroupAPT28 | LAMEHUG has sent spearphishing emails impersonating Ukrainian government officials. |
| T1684.001 Impersonation |
GroupAPT42 | APT42 has impersonated legitimate people in phishing emails to gain credentials. |
| T1684.001 Impersonation |
GroupAPT-C-36 | APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General. |
| T1684.001 Impersonation |
GroupLAPSUS$ | LAPSUS$ has called victims' help desk and impersonated legitimate users with previously gathered information in order to gain access to privileged accounts. |
| T1684.001 Impersonation |
GroupVOID MANTICORE | VOID MANTICORE has impersonated individuals familiar to the victim and technical support associated with social messaging services. |
| T1684.001 Impersonation |
GroupWIRTE | WIRTE has used utilized look-alike domains and graphics of trusted security solution providers to entice victims to click on phishing links. |
| T1684.001 Impersonation |
MalwareRustyWater | RustyWater has impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain `info@tmcell`. |
| T1684.001 Impersonation |
ToolNPPSPY | NPPSPY creates a network listener using the misspelled label |
| T1684.001 Impersonation |
GroupTeamPCP | TeamPCP impersonated legitimate maintainers to push imposter commits to the Aquasecurity Trivy scanner GitHub repository. |
| T1685 Disable or Modify Tools |
CampaignKV Botnet Activity | KV Botnet Activity used various scripts to remove or disable security tools, such as |
| T1685 Disable or Modify Tools |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors disabled Microsoft Defender through Registry settings and real-time monitoring via PowerShell. |
| T1685 Disable or Modify Tools |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry internet settings to lower internet security. |
| T1685 Disable or Modify Tools |
CampaignCutting Edge | During Cutting Edge, threat actors disabled logging and modified the `compcheckresult.cgi` component to edit the Ivanti Connect Secure built-in Integrity Checker exclusion list to evade detection. |
| T1685 Disable or Modify Tools |
CampaignHomeLand Justice | During HomeLand Justice, threat actors modified and disabled components of endpoint detection and response (EDR) solutions including Microsoft Defender Antivirus. |
| T1685 Disable or Modify Tools |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the service control manager on a remote system to disable services associated with security monitoring products. |
| T1685 Disable or Modify Tools |
CampaignArcaneDoor | ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations. |
| T1685 Disable or Modify Tools |
CampaignNight Dragon | During Night Dragon, threat actors disabled anti-virus and anti-spyware tools in some instances on the victim’s machines. The actors also disabled proxy settings to allow direct communication from victims to the Internet. |
| T1685 Disable or Modify Tools |
CampaignQuad7 Activity | Quad7 Activity has disabled the TP-Link management interface for TP-Link by killing the |
| T1685 Disable or Modify Tools |
GroupAPT38 | APT38 has unhooked DLLs to disable endpoint detection and response (EDR) or anti-virus (AV) tools. |
| T1685 Disable or Modify Tools |
GroupIndrik Spider | Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring. Indrik Spider has used `MpCmdRun` to revert the definitions in Microsoft Defender. Additionally, Indrik Spider has used WMI to stop or uninstall and reset anti-virus products and other defensive services. |
| T1685 Disable or Modify Tools |
GroupBlackByte | BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations. |
| T1685 Disable or Modify Tools |
GroupKimsuky | Kimsuky has been observed turning off Windows Security Center and can hide the AV software window from the view of the infected user. |
| T1685 Disable or Modify Tools |
GroupAPT41 | APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging. |
| T1685 Disable or Modify Tools |
GroupGorgon Group | Gorgon Group malware can attempt to disable security features in Microsoft Office and Windows Defender using the |
| T1685 Disable or Modify Tools |
GroupMuddyWater | MuddyWater can disable the system's local proxy settings. |
| T1685 Disable or Modify Tools |
GroupFIN6 | FIN6 has deployed a utility script named |
| T1685 Disable or Modify Tools |
GroupGamaredon Group | Gamaredon Group has delivered macros which can tamper with Microsoft Office security settings. |
| T1685 Disable or Modify Tools |
GroupTeamTNT | TeamTNT has disabled and uninstalled security tools such as Alibaba, Tencent, and BMC cloud monitoring agents on cloud-based infrastructure. |
| T1685 Disable or Modify Tools |
GroupRocke | Rocke used scripts which detected and uninstalled antivirus software. |
| T1685 Disable or Modify Tools |
GroupScattered Spider | Scattered Spider has uninstalled and disabled security tools. |
| T1685 Disable or Modify Tools |
GroupUNC3886 | UNC3886 has disabled OpenSSL digital signature verification of system files through corruption of boot files. |
| T1685 Disable or Modify Tools |
GroupContagious Interview | Contagious Interview has convinced victims to disable Docker and other container environments and run code on their machine natively in attempts to bypass container isolation and ensure device infection. |
| T1685 Disable or Modify Tools |
GroupTA2541 | TA2541 has attempted to disable built-in security protections such as Windows AMSI. |
| T1685 Disable or Modify Tools |
GroupAkira | Akira has disabled or modified security tools for defense evasion. |
| T1685 Disable or Modify Tools |
GroupPutter Panda | Malware used by Putter Panda attempts to terminate processes corresponding to two components of Sophos Anti-Virus (SAVAdminService.exe and SavService.exe). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.