Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1190 Exploit Public-Facing Application |
GroupPlay | Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange. |
| T1190 Exploit Public-Facing Application |
GroupMagic Hound | Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379). |
| T1190 Exploit Public-Facing Application |
GroupThreat Group-3390 | Threat Group-3390 has exploited the Microsoft SharePoint vulnerability CVE-2019-0604 and CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in Exchange Server. |
| T1190 Exploit Public-Facing Application |
GroupFIN13 | FIN13 has exploited known vulnerabilities such as CVE-2017-1000486 (Primefaces Application Expression Language Injection), CVE-2015-7450 (WebSphere Application Server SOAP Deserialization Exploit), CVE-2010-5326 (SAP NewWeaver Invoker Servlet Exploit), and EDB-ID-24963 (SAP NetWeaver ConfigServlet Remote Code Execution) to gain initial access. |
| T1190 Exploit Public-Facing Application |
GroupTeamPCP | TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints. |
| T1190 Exploit Public-Facing Application |
GroupShinyHunters | ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure. ShinyHunters has exploited known vulnerabilities in internet-facing servers. |
| T1195 Supply Chain Compromise |
GroupSandworm Team | Sandworm Team staged compromised versions of legitimate software installers on forums to achieve initial, untargetetd access in victim environments. |
| T1195 Supply Chain Compromise |
GroupOilRig | OilRig has leveraged compromised organizations to conduct supply chain attacks on government entities. |
| T1195 Supply Chain Compromise |
GroupEmber Bear | Ember Bear has compromised information technology providers and software developers providing services to targets of interest, building initial access to ultimate victims at least in part through compromise of service providers that work with the victim organizations. |
| T1195.001 Compromise Software Dependencies and Development Tools |
GroupTeamPCP | TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages. Aikido TeamPCP Telnyx MAR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1195.001 Compromise Software Dependencies and Development Tools |
GroupShinyHunters | ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms. |
| T1195.002 Compromise Software Supply Chain |
GroupAPT41 | APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users. |
| T1195.002 Compromise Software Supply Chain |
GroupDragonfly | Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores. |
| T1195.002 Compromise Software Supply Chain |
GroupFIN7 | FIN7 has gained initial access by compromising a victim's software supply chain. |
| T1195.002 Compromise Software Supply Chain |
GroupSandworm Team | Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one. |
| T1195.002 Compromise Software Supply Chain |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has distributed ransomware by backdooring software installers via a strategic web compromise of the site hosting Italian WinRAR. |
| T1195.002 Compromise Software Supply Chain |
GroupCobalt Group | Cobalt Group has compromised legitimate web browser updates to deliver a backdoor. |
| T1195.002 Compromise Software Supply Chain |
GroupMoonstone Sleet | Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims. |
| T1195.002 Compromise Software Supply Chain |
GroupDaggerfly | Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims. |
| T1195.002 Compromise Software Supply Chain |
GroupThreat Group-3390 | Threat Group-3390 has compromised the Able Desktop installer to gain access to victim's environments. |
| T1197 BITS Jobs |
GroupPatchwork | Patchwork has used BITS jobs to download malicious payloads. |
| T1197 BITS Jobs |
GroupAPT41 | |
| T1197 BITS Jobs |
GroupAPT39 | APT39 has used the BITS protocol to exfiltrate stolen data from a compromised host. |
| T1197 BITS Jobs |
GroupLeviathan | |
| T1197 BITS Jobs |
GroupWizard Spider | Wizard Spider has used batch scripts that utilizes WMIC to execute a BITSAdmin transfer of a ransomware payload to each compromised machine. |
| T1199 Trusted Relationship |
GroupmenuPass | menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest. |
| T1199 Trusted Relationship |
GroupHAFNIUM | HAFNIUM has used stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to access downstream customer environments. |
| T1199 Trusted Relationship |
GroupSandworm Team | Sandworm Team has used dedicated network connections from one victim organization to gain unauthorized access to a separate organization. Additionally, Sandworm Team has accessed Internet service providers and telecommunication entities that provide mobile connectivity. |
| T1199 Trusted Relationship |
GroupSea Turtle | Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers. |
| T1199 Trusted Relationship |
GroupPOLONIUM | POLONIUM has used compromised credentials from an IT company to target downstream customers including a law firm and aviation company. |
| T1199 Trusted Relationship |
GroupRedCurl | RedCurl has gained access to a contractor to pivot to the victim’s infrastructure. |
| T1199 Trusted Relationship |
GroupAPT29 | APT29 has compromised IT, cloud services, and managed services providers to gain broad access to multiple customers for subsequent operations. |
| T1199 Trusted Relationship |
GroupAPT28 | Once APT28 gained access to the DCCC network, the group then proceeded to use that access to compromise the DNC network. |
| T1199 Trusted Relationship |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has breached Managed Service Providers (MSP's) to deliver malware to MSP customers. |
| T1199 Trusted Relationship |
GroupLAPSUS$ | LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations. |
| T1199 Trusted Relationship |
GroupVOID MANTICORE | VOID MANTICORE has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access. |
| T1199 Trusted Relationship |
GroupThreat Group-3390 | Threat Group-3390 has compromised third party service providers to gain access to victim's environments. |
| T1200 Hardware Additions |
GroupDarkVishnya | DarkVishnya physically connected Bash Bunny, Raspberry Pi, netbooks, and inexpensive laptops to the target organization's environment to access the company’s local network. |
| T1201 Password Policy Discovery |
GroupOilRig | OilRig has used net.exe in a script with |
| T1201 Password Policy Discovery |
GroupTurla | Turla has used |
| T1201 Password Policy Discovery |
GroupChimera | Chimera has used the NtdsAudit utility to collect information related to accounts and passwords. |
| T1202 Indirect Command Execution |
GroupRedCurl | RedCurl has used pcalua.exe to obfuscate binary execution and remote connections. |
| T1202 Indirect Command Execution |
GroupLazarus Group | Lazarus Group persistence mechanisms have used |
| T1203 Exploitation for Client Execution |
GroupElderwood | Elderwood has used exploitation of endpoint software, including Microsoft Internet Explorer Adobe Flash vulnerabilities, to gain execution. They have also used zero-day exploits. |
| T1203 Exploitation for Client Execution |
GroupAPT3 | APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113 and Internet Explorer vulnerability CVE-2014-1776. |
| T1203 Exploitation for Client Execution |
GroupEXOTIC LILY | EXOTIC LILY has used malicious documents containing exploits for CVE-2021-40444 affecting Microsoft MSHTML. |
| T1203 Exploitation for Client Execution |
Groupadmin@338 | admin@338 has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158. |
| T1203 Exploitation for Client Execution |
GroupPatchwork | Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641. |
| T1203 Exploitation for Client Execution |
GroupAPT41 | APT41 leveraged the follow exploits in their operations: CVE-2012-0158, CVE-2015-1641, CVE-2017-0199, CVE-2017-11882, and CVE-2019-3396. |
| T1203 Exploitation for Client Execution |
GroupDragonfly | Dragonfly has exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.