ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1190
Exploit Public-Facing Application
GroupPlay

Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange.

T1190
Exploit Public-Facing Application
GroupMagic Hound

Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379).

T1190
Exploit Public-Facing Application
GroupThreat Group-3390

Threat Group-3390 has exploited the Microsoft SharePoint vulnerability CVE-2019-0604 and CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in Exchange Server.

T1190
Exploit Public-Facing Application
GroupFIN13

FIN13 has exploited known vulnerabilities such as CVE-2017-1000486 (Primefaces Application Expression Language Injection), CVE-2015-7450 (WebSphere Application Server SOAP Deserialization Exploit), CVE-2010-5326 (SAP NewWeaver Invoker Servlet Exploit), and EDB-ID-24963 (SAP NetWeaver ConfigServlet Remote Code Execution) to gain initial access.

T1190
Exploit Public-Facing Application
GroupTeamPCP

TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints.

T1190
Exploit Public-Facing Application
GroupShinyHunters

ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure. ShinyHunters has exploited known vulnerabilities in internet-facing servers.

T1195
Supply Chain Compromise
GroupSandworm Team

Sandworm Team staged compromised versions of legitimate software installers on forums to achieve initial, untargetetd access in victim environments.

T1195
Supply Chain Compromise
GroupOilRig

OilRig has leveraged compromised organizations to conduct supply chain attacks on government entities.

T1195
Supply Chain Compromise
GroupEmber Bear

Ember Bear has compromised information technology providers and software developers providing services to targets of interest, building initial access to ultimate victims at least in part through compromise of service providers that work with the victim organizations.

T1195.001
Compromise Software Dependencies and Development Tools
GroupTeamPCP

TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.

T1195.001
Compromise Software Dependencies and Development Tools
GroupShinyHunters

ShinyHunters has compromised CI/CD pipelines by gaining access to high privilege engineering accounts on Git version control, BrowserStack, JFrog and other cloud project management platforms.

T1195.002
Compromise Software Supply Chain
GroupAPT41

APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users.

T1195.002
Compromise Software Supply Chain
GroupDragonfly

Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores.

T1195.002
Compromise Software Supply Chain
GroupFIN7

FIN7 has gained initial access by compromising a victim's software supply chain.

T1195.002
Compromise Software Supply Chain
GroupSandworm Team

Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one.

T1195.002
Compromise Software Supply Chain
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has distributed ransomware by backdooring software installers via a strategic web compromise of the site hosting Italian WinRAR.

T1195.002
Compromise Software Supply Chain
GroupCobalt Group

Cobalt Group has compromised legitimate web browser updates to deliver a backdoor.

T1195.002
Compromise Software Supply Chain
GroupMoonstone Sleet

Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims.

T1195.002
Compromise Software Supply Chain
GroupDaggerfly

Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims.

T1195.002
Compromise Software Supply Chain
GroupThreat Group-3390

Threat Group-3390 has compromised the Able Desktop installer to gain access to victim's environments.

T1197
BITS Jobs
GroupPatchwork

Patchwork has used BITS jobs to download malicious payloads.

T1197
BITS Jobs
GroupAPT41

APT41 used BITSAdmin to download and install payloads.

T1197
BITS Jobs
GroupAPT39

APT39 has used the BITS protocol to exfiltrate stolen data from a compromised host.

T1197
BITS Jobs
GroupLeviathan

Leviathan has used BITSAdmin to download additional tools.

T1197
BITS Jobs
GroupWizard Spider

Wizard Spider has used batch scripts that utilizes WMIC to execute a BITSAdmin transfer of a ransomware payload to each compromised machine.

T1199
Trusted Relationship
GroupmenuPass

menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest.

T1199
Trusted Relationship
GroupHAFNIUM

HAFNIUM has used stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to access downstream customer environments.

T1199
Trusted Relationship
GroupSandworm Team

Sandworm Team has used dedicated network connections from one victim organization to gain unauthorized access to a separate organization. Additionally, Sandworm Team has accessed Internet service providers and telecommunication entities that provide mobile connectivity.

T1199
Trusted Relationship
GroupSea Turtle

Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers.

T1199
Trusted Relationship
GroupPOLONIUM

POLONIUM has used compromised credentials from an IT company to target downstream customers including a law firm and aviation company.

T1199
Trusted Relationship
GroupRedCurl

RedCurl has gained access to a contractor to pivot to the victim’s infrastructure.

T1199
Trusted Relationship
GroupAPT29

APT29 has compromised IT, cloud services, and managed services providers to gain broad access to multiple customers for subsequent operations.

T1199
Trusted Relationship
GroupAPT28

Once APT28 gained access to the DCCC network, the group then proceeded to use that access to compromise the DNC network.

T1199
Trusted Relationship
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has breached Managed Service Providers (MSP's) to deliver malware to MSP customers.

T1199
Trusted Relationship
GroupLAPSUS$

LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations.

T1199
Trusted Relationship
GroupVOID MANTICORE

VOID MANTICORE has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access.

T1199
Trusted Relationship
GroupThreat Group-3390

Threat Group-3390 has compromised third party service providers to gain access to victim's environments.

T1200
Hardware Additions
GroupDarkVishnya

DarkVishnya physically connected Bash Bunny, Raspberry Pi, netbooks, and inexpensive laptops to the target organization's environment to access the company’s local network.

T1201
Password Policy Discovery
GroupOilRig

OilRig has used net.exe in a script with net accounts /domain to find the password policy of a domain.

T1201
Password Policy Discovery
GroupTurla

Turla has used net accounts and net accounts /domain to acquire password policy information.

T1201
Password Policy Discovery
GroupChimera

Chimera has used the NtdsAudit utility to collect information related to accounts and passwords.

T1202
Indirect Command Execution
GroupRedCurl

RedCurl has used pcalua.exe to obfuscate binary execution and remote connections.

T1202
Indirect Command Execution
GroupLazarus Group

Lazarus Group persistence mechanisms have used forfiles.exe to execute .htm files.

T1203
Exploitation for Client Execution
GroupElderwood

Elderwood has used exploitation of endpoint software, including Microsoft Internet Explorer Adobe Flash vulnerabilities, to gain execution. They have also used zero-day exploits.

T1203
Exploitation for Client Execution
GroupAPT3

APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113 and Internet Explorer vulnerability CVE-2014-1776.

T1203
Exploitation for Client Execution
GroupEXOTIC LILY

EXOTIC LILY has used malicious documents containing exploits for CVE-2021-40444 affecting Microsoft MSHTML.

T1203
Exploitation for Client Execution
Groupadmin@338

admin@338 has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158.

T1203
Exploitation for Client Execution
GroupPatchwork

Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641.

T1203
Exploitation for Client Execution
GroupAPT41

APT41 leveraged the follow exploits in their operations: CVE-2012-0158, CVE-2015-1641, CVE-2017-0199, CVE-2017-11882, and CVE-2019-3396.

T1203
Exploitation for Client Execution
GroupDragonfly

Dragonfly has exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.