ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1204.002
Malicious File
GroupSilence

Silence attempts to get users to launch malicious attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupCobalt Group

Cobalt Group has sent emails containing malicious attachments that require users to execute a file or macro to infect the victim machine.

T1204.002
Malicious File
GroupWizard Spider

Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar.

T1204.002
Malicious File
GroupMolerats

Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives.

T1204.002
Malicious File
GroupTransparent Tribe

Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems.

T1204.002
Malicious File
GroupIndigoZebra

IndigoZebra sent spearphishing emails containing malicious attachments that urged recipients to review modifications in the file which would trigger the attack.

T1204.002
Malicious File
GroupMoonstone Sleet

Moonstone Sleet relied on users interacting with malicious files, such as a trojanized PuTTY installer, for initial execution.

T1204.002
Malicious File
GroupInception

Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware.

T1204.002
Malicious File
GroupVOID MANTICORE

VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file. VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance.

T1204.002
Malicious File
GroupPROMETHIUM

PROMETHIUM has attempted to get users to execute compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.

T1204.002
Malicious File
GroupAPT30

APT30 has relied on users to execute malicious file attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupHEXANE

HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware.

T1204.002
Malicious File
GroupRancor

Rancor attempted to get users to click on an embedded macro within a Microsoft Office Excel document to launch their malware.

T1204.002
Malicious File
GroupWIRTE

WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads.

T1204.002
Malicious File
GroupPLATINUM

PLATINUM has attempted to get users to open malicious files by sending spearphishing emails with attachments to victims.

T1204.002
Malicious File
GroupMagic Hound

Magic Hound has attempted to lure victims into opening malicious email attachments.

T1204.002
Malicious File
GroupAjax Security Team

Ajax Security Team has lured victims into executing malicious files.

T1204.002
Malicious File
GroupThreat Group-3390

Threat Group-3390 has lured victims into opening malicious files containing malware.

T1204.002
Malicious File
GroupAPT33

APT33 has used malicious e-mail attachments to lure victims into executing malware.

T1204.002
Malicious File
GroupFIN8

FIN8 has used malicious e-mail attachments to lure victims into executing malware.

T1204.002
Malicious File
GroupAPT19

APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupNomadic Octopus

Nomadic Octopus as attempted to lure victims into clicking on malicious attachments within spearphishing emails.

T1204.003
Malicious Image
GroupTeamTNT

TeamTNT has relied on users to download and execute malicious Docker images.

T1204.004
Malicious Copy and Paste
GroupKimsuky

Kimsuky has leveraged ClickFix type tactics enticing victims to copy and paste malicious code.

T1204.004
Malicious Copy and Paste
GroupMuddyWater

MuddyWater has leveraged ClickFix type tactics enticing victims to copy and paste malicious PowerShell code.

T1204.004
Malicious Copy and Paste
GroupContagious Interview

Contagious Interview has leveraged ClickFix type tactics enticing victims to copy and paste malicious code.

T1204.005
Malicious Library
GroupContagious Interview

Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data.

T1205
Traffic Signaling
GroupKimsuky

Kimsuky has used TRANSLATEXT to redirect clients to legitimate Gmail, Naver or Kakao pages if the clients connect with no parameters.

T1205
Traffic Signaling
GroupMustang Panda

Mustang Panda has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of “17 03 03” or “46 77 4d”.

T1205
Traffic Signaling
GroupUNC3886

UNC3886 has used the TABLEFLIP traffic redirection utility to listen for specialized command packets on compromised FortiManager devices.

T1205.001
Port Knocking
GroupUNC3886

UNC3886 maintained persistence on FortiGate Firewalls through ICMP port knocking.

T1205.001
Port Knocking
GroupPROMETHIUM

PROMETHIUM has used a script that configures the knockd service and firewall to only accept C2 connections from systems that use a specified sequence of knock ports.

T1210
Exploitation of Remote Services
GroupDragonfly

Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers.

T1210
Exploitation of Remote Services
GroupmenuPass

menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472).

T1210
Exploitation of Remote Services
GroupMuddyWater

MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472).

T1210
Exploitation of Remote Services
GroupFIN7

FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers.

T1210
Exploitation of Remote Services
GroupEmber Bear

Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations.

T1210
Exploitation of Remote Services
GroupAPT28

APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement.

T1210
Exploitation of Remote Services
GroupFox Kitten

Fox Kitten has exploited known vulnerabilities in remote services including RDP.

T1210
Exploitation of Remote Services
GroupTonto Team

Tonto Team has used EternalBlue exploits for lateral movement.

T1210
Exploitation of Remote Services
GroupEarth Lusca

Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).

T1210
Exploitation of Remote Services
GroupWizard Spider

Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities.

T1210
Exploitation of Remote Services
GroupThreat Group-3390

Threat Group-3390 has exploited MS17-010 to move laterally to other systems on the network.

T1210
Exploitation of Remote Services
GroupShinyHunters

ShinyHunters has exploited vulnerabilities in remote services for lateral movement.

T1211
Exploitation for Stealth
GroupAPT28

APT28 has used CVE-2015-4902 to bypass security features.

T1211
Exploitation for Stealth
GroupVelvet Ant

Velvet Ant exploited CVE-2024-20399 in Cisco Switches to which the threat actor was already able to authenticate in order to escape the NX-OS command line interface and gain access to the underlying operating system for arbitrary command execution.

T1212
Exploitation for Credential Access
GroupUNC3886

UNC3886 exploited CVE-2022-22948 in VMware vCenter to obtain encrypted credentials from the vCenter postgresDB.

T1213
Data from Information Repositories
GroupAPT28

APT28 has collected files from various information repositories.

T1213.001
Confluence
GroupLAPSUS$

LAPSUS$ has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials.

T1213.002
Sharepoint
GroupHAFNIUM

HAFNIUM has abused compromised credentials to exfiltrate data from SharePoint.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.