Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1189 Drive-by Compromise |
GroupRTM | RTM has distributed its malware via the RIG and SUNDOWN exploit kits, as well as online advertising network |
| T1189 Drive-by Compromise |
GroupLazarus Group | Lazarus Group delivered RATANKBA and other malicious code to victims via a compromised legitimate website. |
| T1189 Drive-by Compromise |
GroupEarth Lusca | Earth Lusca has performed watering hole attacks. |
| T1189 Drive-by Compromise |
GroupTransparent Tribe | Transparent Tribe has used websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools. |
| T1189 Drive-by Compromise |
GroupPROMETHIUM | PROMETHIUM has used watering hole attacks to deliver malicious versions of legitimate installers. |
| T1189 Drive-by Compromise |
GroupDaggerfly | Daggerfly has used strategic website compromise for initial access against victims. |
| T1189 Drive-by Compromise |
GroupPLATINUM | PLATINUM has sometimes used drive-by attacks against vulnerable browser plugins. |
| T1189 Drive-by Compromise |
GroupMagic Hound | Magic Hound has conducted watering-hole attacks through media and magazine websites. |
| T1189 Drive-by Compromise |
GroupThreat Group-3390 | Threat Group-3390 has extensively used strategic web compromises to target victims. |
| T1189 Drive-by Compromise |
GroupAPT19 | APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets. |
| T1190 Exploit Public-Facing Application |
GroupBlackByte | BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments. |
| T1190 Exploit Public-Facing Application |
GroupGALLIUM | GALLIUM exploited a publicly-facing servers including Wildfly/JBoss servers to gain access to the network. |
| T1190 Exploit Public-Facing Application |
GroupKimsuky | Kimsuky has exploited various vulnerabilities for initial access, including Microsoft Exchange vulnerability CVE-2020-0688. |
| T1190 Exploit Public-Facing Application |
GroupVolt Typhoon | Volt Typhoon has gained initial access through exploitation of multiple vulnerabilities in internet-facing software and appliances such as Fortinet, Ivanti (formerly Pulse Secure), NETGEAR, Citrix, and Cisco. |
| T1190 Exploit Public-Facing Application |
GroupAPT41 | APT41 exploited CVE-2020-10189 against Zoho ManageEngine Desktop Central through unsafe deserialization, and CVE-2019-19781 to compromise Citrix Application Delivery Controllers (ADC) and gateway devices. APT41 leveraged vulnerabilities such as ProxyLogon exploitation or SQL injection for initial access. APT41 exploited CVE-2021-26855 against a vulnerable Microsoft Exchange Server to gain initial access to the victim network. |
| T1190 Exploit Public-Facing Application |
GroupSalt Typhoon | Salt Typhoon has exploited CVE-2018-0171 in the Smart Install feature of Cisco IOS and Cisco IOS XE software for initial access. |
| T1190 Exploit Public-Facing Application |
GroupDragonfly | Dragonfly has conducted SQL injection attacks, exploited vulnerabilities CVE-2019-19781 and CVE-2020-0688 for Citrix and MS Exchange, and CVE-2018-13379 for Fortinet VPNs. |
| T1190 Exploit Public-Facing Application |
GroupmenuPass | menuPass has leveraged vulnerabilities in Pulse Secure VPNs to hijack sessions. |
| T1190 Exploit Public-Facing Application |
GroupHAFNIUM | HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server. |
| T1190 Exploit Public-Facing Application |
GroupMuddyWater | MuddyWater has exploited the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688). |
| T1190 Exploit Public-Facing Application |
GroupFIN7 | FIN7 has compromised targeted organizations through exploitation of CVE-2021-31207 in Exchange. |
| T1190 Exploit Public-Facing Application |
GroupSandworm Team | Sandworm Team exploits public-facing applications for initial access and to acquire infrastructure, such as exploitation of the EXIM mail transfer agent in Linux systems. |
| T1190 Exploit Public-Facing Application |
GroupRocke | Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware. |
| T1190 Exploit Public-Facing Application |
GroupAPT39 | APT39 has used SQL injection for initial compromise. |
| T1190 Exploit Public-Facing Application |
GroupUNC3886 | UNC3886 has exploited CVE-2022-42475 in FortiOS SSL VPNs to obtain access. |
| T1190 Exploit Public-Facing Application |
GroupMoses Staff | Moses Staff has exploited known vulnerabilities in public-facing infrastructure such as Microsoft Exchange Servers. |
| T1190 Exploit Public-Facing Application |
GroupSea Turtle | Sea Turtle gained access to victim environments by exploiting multiple known vulnerabilities over several campaigns. |
| T1190 Exploit Public-Facing Application |
GroupKe3chang | Ke3chang has compromised networks by exploiting Internet-facing applications, including vulnerable Microsoft Exchange and SharePoint servers. |
| T1190 Exploit Public-Facing Application |
GroupBlackTech | BlackTech has exploited a buffer overflow vulnerability in Microsoft Internet Information Services (IIS) 6.0, CVE-2017-7269, in order to establish a new HTTP or command and control (C2) server. |
| T1190 Exploit Public-Facing Application |
GroupLeviathan | Leviathan has used exploits against publicly-disclosed vulnerabilities for initial access into victim networks. |
| T1190 Exploit Public-Facing Application |
GroupBlue Mockingbird | Blue Mockingbird has gained initial access by exploiting CVE-2019-18935, a vulnerability within Telerik UI for ASP.NET AJAX. |
| T1190 Exploit Public-Facing Application |
GroupWinter Vivern | Winter Vivern has exploited known and zero-day vulnerabilities in software usch as Roundcube Webmail servers and the "Follina" vulnerability. |
| T1190 Exploit Public-Facing Application |
GroupStorm-0501 | Storm-0501 has exploited N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203). |
| T1190 Exploit Public-Facing Application |
GroupAPT29 | APT29 has exploited CVE-2019-19781 for Citrix, CVE-2019-11510 for Pulse Secure VPNs, CVE-2018-13379 for FortiGate VPNs, and CVE-2019-9670 in Zimbra software to gain access. |
| T1190 Exploit Public-Facing Application |
GroupCinnamon Tempest | Cinnamon Tempest has exploited multiple unpatched vulnerabilities for initial access including vulnerabilities in Microsoft Exchange, Manage Engine AdSelfService Plus, Confluence, and Log4j. |
| T1190 Exploit Public-Facing Application |
GroupMirrorFace | MirrorFace has exploited vulnerabilities in Fortigate and Array AG devices for initial access. |
| T1190 Exploit Public-Facing Application |
GroupMedusa Group | Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access. Medusa Group has also utilized CVE-2024-1709 in ScreenConnect, and CVE-2023-48788 in Fortinet EMS for initial access to victim environments. |
| T1190 Exploit Public-Facing Application |
GroupBackdoorDiplomacy | BackdoorDiplomacy has exploited CVE-2020-5902, an F5 BIP-IP vulnerability, to drop a Linux backdoor. BackdoorDiplomacy has also exploited mis-configured Plesk servers. |
| T1190 Exploit Public-Facing Application |
GroupAxiom | Axiom has been observed using SQL injection to gain access to systems. |
| T1190 Exploit Public-Facing Application |
GroupEmber Bear | Ember Bear gains initial access to victim environments by exploiting external-facing services. Examples include exploitation of CVE-2021-26084 in Confluence servers; CVE-2022-41040, ProxyShell, and other vulnerabilities in Microsoft Exchange; and multiple vulnerabilities in open-source platforms such as content management systems. |
| T1190 Exploit Public-Facing Application |
GroupVolatile Cedar | Volatile Cedar has targeted publicly facing web servers, with both automatic and manual vulnerability discovery. |
| T1190 Exploit Public-Facing Application |
GroupToddyCat | ToddyCat has exploited the ProxyLogon vulnerability (CVE-2021-26855) to compromise Exchange Servers at multiple organizations. |
| T1190 Exploit Public-Facing Application |
GroupAgrius | Agrius exploits public-facing applications for initial access to victim environments. Examples include widespread attempts to exploit CVE-2018-13379 in FortiOS devices and SQL injection activity. |
| T1190 Exploit Public-Facing Application |
GroupAPT28 | APT28 has used a variety of public exploits, including CVE 2020-0688 and CVE 2020-17144, to gain execution on vulnerable Microsoft Exchange; they have also conducted SQL injection attacks against external websites. |
| T1190 Exploit Public-Facing Application |
GroupAPT5 | APT5 has exploited vulnerabilities in externally facing software and devices including Pulse Secure VPNs and Citrix Application Delivery Controllers. |
| T1190 Exploit Public-Facing Application |
GroupFox Kitten | Fox Kitten has exploited known vulnerabilities in Fortinet, PulseSecure, and Palo Alto VPN appliances. |
| T1190 Exploit Public-Facing Application |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has exploited Oracle WebLogic vulnerabilities for initial compromise. |
| T1190 Exploit Public-Facing Application |
GroupINC Ransom | INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access. |
| T1190 Exploit Public-Facing Application |
GroupEarth Lusca | Earth Lusca has compromised victims by directly exploiting vulnerabilities of public-facing servers, including those associated with Microsoft Exchange and Oracle GlassFish. |
| T1190 Exploit Public-Facing Application |
GroupVOID MANTICORE | VOID MANTICORE has exploited public facing vulnerabilities within victim environments to include SharePoint CVE-2019-0604. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.