ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1036
Masquerading
CampaignOperation Honeybee

During Operation Honeybee, the threat actors modified the MaoCheng dropper so its icon appeared as a Word document.

T1036
Masquerading
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors disguised some executables as JPG files.

T1036
Masquerading
CampaignC0018

During C0018, AvosLocker was disguised using the victim company name as the filename.

T1036
Masquerading
CampaignC0015

During C0015, the threat actors named a binary file `compareForfor.jpg` to disguise it as a JPG file.

T1036
Masquerading
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used voice calls to socially engineer victims into authorizing a modified version of the Salesforce Data Loader app.

T1036
Masquerading
CampaignArcaneDoor

ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances.

T1036.004
Masquerade Task or Service
CampaignKV Botnet Activity

KV Botnet Activity installation steps include first identifying, then stopping, any process containing [kworker\/0:1], then renaming its initial installation stage to this process name.

T1036.004
Masquerade Task or Service
CampaignFrankenstein

During Frankenstein, the threat actors named a malicious scheduled task "WinUpdate" for persistence.

T1036.004
Masquerade Task or Service
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda masqueraded Registry run keys as legitimate-looking service names such as `OneNote Update` during RedDelta Modified PlugX Infection Chain Operations.

T1036.004
Masquerade Task or Service
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate.

T1036.004
Masquerade Task or Service
CampaignAPT41 DUST

APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`.

T1036.004
Masquerade Task or Service
CampaignC0017

During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code.

T1036.004
Masquerade Task or Service
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Systemd service units to masquerade GOGETTER malware as legitimate or seemingly legitimate services.

T1036.005
Match Legitimate Resource Name or Location
CampaignRedPenguin

During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Sharpshooter

During Operation Sharpshooter, threat actors installed Rising Sun in the Startup folder and disguised it as `mssync.exe`.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used a legitimate Windows executable and secure directory for their payloads to bypass UAC.

T1036.005
Match Legitimate Resource Name or Location
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0018

For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`.

T1036.005
Match Legitimate Resource Name or Location
CampaignJ-magic Campaign

During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization.

T1036.005
Match Legitimate Resource Name or Location
CampaignHomeLand Justice

During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0032

During the C0032 campaign, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files.

T1036.005
Match Legitimate Resource Name or Location
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors renamed a malicious executable to `rundll32.exe` to allow it to blend in with other Windows system files.

T1036.005
Match Legitimate Resource Name or Location
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries created rules that mimicked the name of an institution already present in the network device configuration to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Wocao

During Operation Wocao, the threat actors renamed some tools and executables to appear as legitimate programs.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0017

During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections.

T1036.008
Masquerade File Type
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection.

T1036.008
Masquerade File Type
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace disguised LNK and SFX (self-extracting) files as Word documents to lure victims into opening malicious files.

T1036.008
Masquerade File Type
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team masqueraded executables as `.txt` files.

T1036.010
Masquerade Account Name
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System).

T1037
Boot or Logon Initialization Scripts
CampaignArcaneDoor

ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices.

T1039
Data from Network Shared Drive
CampaignC0015

During C0015, the threat actors collected files from network shared drives prior to network encryption.

T1040
Network Sniffing
CampaignRedPenguin

During RedPenguin, UNC3886 used a passive backdoor to act as a libpcap-based packet sniffer.

T1040
Network Sniffing
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network between the local LAN and the power grid’s industrial control systems.

T1040
Network Sniffing
CampaignArcaneDoor

ArcaneDoor included network packet capture and sniffing for data collection in victim environments.

T1041
Exfiltration Over C2 Channel
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers.

T1041
Exfiltration Over C2 Channel
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors exfiltrated stolen credentials and internal data over HTTPS to C2 infrastructure.

T1041
Exfiltration Over C2 Channel
CampaignFrankenstein

During Frankenstein, the threat actors collected information via Empire, which sent the data back to the adversary's C2.

T1041
Exfiltration Over C2 Channel
CampaignRedPenguin

During RedPenguin, UNC3886 uploaded specified files from compromised devices to a remote server.

T1041
Exfiltration Over C2 Channel
CampaignOperation Honeybee

During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers.

T1041
Exfiltration Over C2 Channel
CampaignHomeLand Justice

During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers.

T1041
Exfiltration Over C2 Channel
CampaignArcaneDoor

ArcaneDoor included use of existing command and control channels for data exfiltration.

T1041
Exfiltration Over C2 Channel
CampaignOperation Wocao

During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data.

T1041
Exfiltration Over C2 Channel
CampaignLeviathan Australian Intrusions

Leviathan exfiltrated collected data over existing command and control channels during Leviathan Australian Intrusions.

T1041
Exfiltration Over C2 Channel
CampaignC0017

During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration.

T1046
Network Service Discovery
CampaignC0018

During C0018, the threat actors used the SoftPerfect Network Scanner for network scanning.

T1046
Network Service Discovery
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to enumerate internal network services and endpoints across targeted environments using browser automation via MCP, including databases, container registries, admin interfaces, and workflow orchestration platforms.

T1046
Network Service Discovery
CampaignHomeLand Justice

During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.