Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1106 Native API |
GroupmenuPass | menuPass has used native APIs including |
| T1106 Native API |
GroupGamaredon Group | Gamaredon Group malware has used |
| T1106 Native API |
GroupSandworm Team | Sandworm Team uses Prestige to disable and restore file system redirection by using the following functions: `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()`. |
| T1106 Native API |
GroupMustang Panda | Mustang Panda has used various Windows API calls during execution and defense evasion. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDABroadcomEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Sophos Mustang Panda PLUGXTrend Micro Mustang Panda Earth Preta Toneshell February 2025ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1106 Native API |
GroupAPT37 | APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection. |
| T1106 Native API |
GroupHigaisa | Higaisa has called various native OS APIs. |
| T1106 Native API |
GroupTropic Trooper | Tropic Trooper has used multiple Windows APIs including HttpInitialize, HttpCreateHttpHandle, and HttpAddUrl. |
| T1106 Native API |
GroupBlackTech | BlackTech has used built-in API functions. |
| T1106 Native API |
GroupTurla | Turla and its RPC backdoors have used APIs calls for various tasks related to subverting AMSI and accessing then executing commands through RPC and/or named pipes. |
| T1106 Native API |
GroupTA505 | TA505 has deployed payloads that use Windows API calls on a compromised host. |
| T1106 Native API |
GroupChimera | Chimera has used direct Windows system calls by leveraging Dumpert. |
| T1106 Native API |
GroupMedusa Group | Medusa Group has leveraged Windows Native API functions to execute payloads. |
| T1106 Native API |
GroupToddyCat | ToddyCat has used `WinExec` to execute commands received from C2 on compromised hosts. |
| T1106 Native API |
GroupLazarus Group | Lazarus Group has used the Windows API |
| T1106 Native API |
GroupSilence | Silence has leveraged the Windows API, including using CreateProcess() or ShellExecute(), to perform a variety of tasks. |
| T1106 Native API |
GroupWIRTE | WIRTE has used the `RtlIpv4StringToAddressA` to convert IP-formatted string to a byte array. |
| T1110 Brute Force |
GroupAPT38 | APT38 has used brute force techniques to attempt account access when passwords are unknown or when password hashes are unavailable. |
| T1110 Brute Force |
GroupAPT41 | APT41 performed password brute-force attacks on the local admin account. |
| T1110 Brute Force |
GroupDragonfly | Dragonfly has attempted to brute force credentials to gain access. |
| T1110 Brute Force |
GroupAPT39 | APT39 has used Ncrack to reveal credentials. |
| T1110 Brute Force |
GroupOilRig | OilRig has used brute force techniques to obtain credentials. |
| T1110 Brute Force |
GroupTurla | Turla may attempt to connect to systems within a victim's network using |
| T1110 Brute Force |
GroupStorm-0501 | Storm-0501 has leveraged brute force attacks to obtain credentials. |
| T1110 Brute Force |
GroupDarkVishnya | DarkVishnya used brute-force attack to obtain login data. |
| T1110 Brute Force |
GroupFIN5 | FIN5 has has used the tool GET2 Penetrator to look for remote login and hard-coded credentials. |
| T1110 Brute Force |
GroupEmber Bear | Ember Bear used the `su-bruteforce` tool to brute force specific users using the `su` command. |
| T1110 Brute Force |
GroupAgrius | Agrius engaged in various brute forcing activities via SMB in victim environments. |
| T1110 Brute Force |
GroupAPT28 | APT28 can perform brute force attacks to obtain credentials. |
| T1110 Brute Force |
GroupFox Kitten | Fox Kitten has brute forced RDP credentials. |
| T1110 Brute Force |
GroupVOID MANTICORE | VOID MANTICORE has conducted brute-force attempts against organizational VPN infrastructure. |
| T1110 Brute Force |
GroupHEXANE | HEXANE has used brute force attacks to compromise valid credentials. |
| T1110 Brute Force |
GroupShinyHunters | ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions. |
| T1110.001 Password Guessing |
GroupAPT29 | APT29 has successfully conducted password guessing attacks against a list of mailboxes. |
| T1110.001 Password Guessing |
GroupAPT28 | APT28 has used a brute-force/password-spray tooling that operated in two modes: in brute-force mode it typically sent over 300 authentication attempts per hour per targeted account over the course of several hours or days. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password guessing attacks. |
| T1110.001 Password Guessing |
GroupVOID MANTICORE | VOID MANTICORE has conducted password guessing to gain initial access. |
| T1110.002 Password Cracking |
GroupAPT3 | APT3 has been known to brute force password hashes to be able to leverage plain text credentials. |
| T1110.002 Password Cracking |
GroupSalt Typhoon | Salt Typhoon has cracked passwords for accounts with weak encryption obtained from the configuration files of compromised network devices. |
| T1110.002 Password Cracking |
GroupDragonfly | Dragonfly has dropped and executed tools used for password cracking, including Hydra and CrackMapExec. |
| T1110.002 Password Cracking |
GroupFIN6 | FIN6 has extracted password hashes from ntds.dit to crack offline. |
| T1110.003 Password Spraying |
GroupHAFNIUM | HAFNIUM has gained initial access through password spray attacks. |
| T1110.003 Password Spraying |
GroupLeafminer | Leafminer used a tool called Total SMB BruteForcer to perform internal password spraying. |
| T1110.003 Password Spraying |
GroupAPT29 | APT29 has conducted brute force password spray attacks. |
| T1110.003 Password Spraying |
GroupChimera | Chimera has used multiple password spraying attacks against victim's remote services to obtain valid user and administrator accounts. |
| T1110.003 Password Spraying |
GroupSilent Librarian | Silent Librarian has used collected lists of names and e-mail accounts to use in password spraying attacks against private sector targets. |
| T1110.003 Password Spraying |
GroupEmber Bear | Ember Bear has conducted password spraying against Outlook Web Access (OWA) infrastructure to identify valid user names and passwords. |
| T1110.003 Password Spraying |
GroupAgrius | Agrius engaged in password spraying via SMB in victim environments. |
| T1110.003 Password Spraying |
GroupAPT28 | APT28 has used a brute-force/password-spray tooling that operated in two modes: in password-spraying mode it conducted approximately four authentication attempts per hour per targeted account over the course of several days or weeks. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password spray attacks. |
| T1110.003 Password Spraying |
GroupLazarus Group | Lazarus Group malware attempts to connect to Windows shares for lateral movement by using a generated list of usernames, which center around permutations of the username Administrator, and weak passwords. |
| T1110.003 Password Spraying |
GroupHEXANE | HEXANE has used password spraying attacks to obtain valid credentials. |
| T1110.003 Password Spraying |
GroupAPT33 | APT33 has used password spraying to gain access to target systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.