Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1098.002 Additional Email Delegate Permissions |
GroupMagic Hound | Magic Hound granted compromised email accounts read access to the email boxes of additional targeted accounts. The group then was able to authenticate to the intended victim's OWA (Outlook Web Access) portal and read hundreds of email communications for information on Middle East organizations. |
| T1098.003 Additional Cloud Roles |
GroupScattered Spider | Scattered Spider has assigned user access admin roles in order to gain Tenant Root Group management permissions in Azure. |
| T1098.003 Additional Cloud Roles |
GroupStorm-0501 | Storm-0501 has elevated their access to Azure resources using `Microsoft.Authorization/elevateAccess/action` and `Microsoft.Authorization/roleAssignments/write` operations to gain User Access Administrator and Owner Azure roles over the victims’ Azure subscriptions. |
| T1098.003 Additional Cloud Roles |
GroupLAPSUS$ | LAPSUS$ has added the global admin role to accounts they have created in the targeted organization's cloud instances. |
| T1098.004 SSH Authorized Keys |
GroupSalt Typhoon | Salt Typhoon has added SSH authorized_keys under root or other users at the Linux level on compromised network devices. |
| T1098.004 SSH Authorized Keys |
GroupTeamTNT | TeamTNT has added RSA keys in |
| T1098.004 SSH Authorized Keys |
GroupEarth Lusca | Earth Lusca has dropped an SSH-authorized key in the `/root/.ssh` folder in order to access a compromised server with SSH. |
| T1098.005 Device Registration |
GroupAPT29 | APT29 has enrolled their own devices into compromised cloud tenants, including enrolling a device in MFA to an Azure AD environment following a successful password guessing attack against a dormant account. |
| T1098.007 Additional Local or Domain Groups |
GroupAPT3 | APT3 has been known to add created accounts to local admin groups to maintain elevated access. |
| T1098.007 Additional Local or Domain Groups |
GroupKimsuky | Kimsuky has added accounts to specific groups with |
| T1098.007 Additional Local or Domain Groups |
GroupAPT41 | APT41 has added user accounts to the User and Admin groups. |
| T1098.007 Additional Local or Domain Groups |
GroupDragonfly | Dragonfly has added newly created accounts to the administrators group to maintain elevated access. |
| T1098.007 Additional Local or Domain Groups |
GroupAPT5 | APT5 has created their own accounts with Local Administrator privileges to maintain access to systems with short-cycle credential rotation. |
| T1098.007 Additional Local or Domain Groups |
GroupMagic Hound | Magic Hound has added a user named DefaultAccount to the Administrators and Remote Desktop Users groups. |
| T1098.007 Additional Local or Domain Groups |
GroupFIN13 | FIN13 has assigned newly created accounts the sysadmin role to maintain persistence. |
| T1102 Web Service |
GroupEXOTIC LILY | EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads. |
| T1102 Web Service |
GroupAPT32 | APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads. |
| T1102 Web Service |
GroupFIN6 | FIN6 has used Pastebin and Google Storage to host content for their operations. |
| T1102 Web Service |
GroupGamaredon Group | Gamaredon Group has used GitHub repositories for downloaders which will be obtained by the group's .NET executable on the compromised system. |
| T1102 Web Service |
GroupTeamTNT | TeamTNT has leveraged iplogger.org to send collected data back to C2. |
| T1102 Web Service |
GroupMustang Panda | Mustang Panda has used DropBox URLs to deliver variants of PlugX. Mustang Panda has also used Google Drive to host malicious downloads. |
| T1102 Web Service |
GroupRocke | Rocke has used Pastebin, Gitee, and GitLab for Command and Control. |
| T1102 Web Service |
GroupTurla | Turla has used legitimate web services including Pastebin, Dropbox, and GitHub for C2 communications. |
| T1102 Web Service |
GroupRedCurl | RedCurl has used web services to download malicious files. |
| T1102 Web Service |
GroupLazyScripter | LazyScripter has used GitHub to host its payloads to operate spam campaigns. |
| T1102 Web Service |
GroupAPT42 | APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations. |
| T1102 Web Service |
GroupFox Kitten | Fox Kitten has used Amazon Web Services to host C2. |
| T1102 Web Service |
GroupInception | Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe. |
| T1102 Web Service |
GroupVOID MANTICORE | VOID MANTICORE has utilized Telegram API for C2. |
| T1102 Web Service |
GroupFIN8 | FIN8 has used |
| T1102.001 Dead Drop Resolver |
GroupKimsuky | Kimsuky has used TRANSLATEXT and a dead drop resolver to retrieve configurations and commands from a public blog site. |
| T1102.001 Dead Drop Resolver |
GroupPatchwork | Patchwork hides base64-encoded and encrypted C2 server locations in comments on legitimate websites. |
| T1102.001 Dead Drop Resolver |
GroupAPT41 | APT41 used legitimate websites for C2 through dead drop resolvers (DDR), including GitHub, Pastebin, and Microsoft TechNet. |
| T1102.001 Dead Drop Resolver |
GroupRocke | Rocke has used Pastebin to check the version of beaconing malware and redirect to another Pastebin hosting updated malware. |
| T1102.001 Dead Drop Resolver |
GroupBRONZE BUTLER | BRONZE BUTLER's MSGET downloader uses a dead drop resolver to access malicious payloads. |
| T1102.001 Dead Drop Resolver |
GroupRTM | RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. |
| T1102.002 Bidirectional Communication |
GroupKimsuky | Kimsuky has used Blogspot pages and a Github repository for C2. Kimsuky has also leveraged Dropbox for downloading payloads and uploading victim system information. |
| T1102.002 Bidirectional Communication |
GroupMuddyWater | MuddyWater has used web services including OneHub to distribute remote access tools. |
| T1102.002 Bidirectional Communication |
GroupGamaredon Group | Gamaredon Group has used several ways to try to resolve the C2 server, including: public third-party websites, an adversary-operated Telegraph channel, the ngrok utility and the TXT record of a hardcoded C2 domain. |
| T1102.002 Bidirectional Communication |
GroupFIN7 | FIN7 used legitimate services like Google Docs, Google Scripts, and Pastebin for C2. |
| T1102.002 Bidirectional Communication |
GroupSandworm Team | Sandworm Team has used the Telegram Bot API from Telegram Messenger to send and receive commands to its Python backdoor. Sandworm Team also used legitimate M.E.Doc software update check requests for sending and receiving commands and hosted malicious payloads on putdrive.com. |
| T1102.002 Bidirectional Communication |
GroupZIRCONIUM | ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands. |
| T1102.002 Bidirectional Communication |
GroupAPT39 | APT39 has communicated with C2 through files uploaded to and downloaded from DropBox. |
| T1102.002 Bidirectional Communication |
GroupAPT37 | APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2. |
| T1102.002 Bidirectional Communication |
GroupCarbanak | Carbanak has used a VBScript named "ggldr" that uses Google Apps Script, Sheets, and Forms services for C2. |
| T1102.002 Bidirectional Communication |
GroupPOLONIUM | POLONIUM has used OneDrive and DropBox for C2. |
| T1102.002 Bidirectional Communication |
GroupTurla | A Turla JavaScript backdoor has used Google Apps Script as its C2 server. |
| T1102.002 Bidirectional Communication |
GroupAPT28 | APT28 has used Google Drive for C2. |
| T1102.002 Bidirectional Communication |
GroupAPT12 | APT12 has used blogs and WordPress for C2 infrastructure. |
| T1102.002 Bidirectional Communication |
GroupLazarus Group | Lazarus Group has used GitHub as C2, pulling hosted image payloads then committing command execution output to files in specific directories. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.