Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.002 Malicious File |
GroupSilence | Silence attempts to get users to launch malicious attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupCobalt Group | Cobalt Group has sent emails containing malicious attachments that require users to execute a file or macro to infect the victim machine. |
| T1204.002 Malicious File |
GroupWizard Spider | Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar. |
| T1204.002 Malicious File |
GroupMolerats | Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives. |
| T1204.002 Malicious File |
GroupTransparent Tribe | Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems. |
| T1204.002 Malicious File |
GroupIndigoZebra | IndigoZebra sent spearphishing emails containing malicious attachments that urged recipients to review modifications in the file which would trigger the attack. |
| T1204.002 Malicious File |
GroupMoonstone Sleet | Moonstone Sleet relied on users interacting with malicious files, such as a trojanized PuTTY installer, for initial execution. |
| T1204.002 Malicious File |
GroupInception | Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware. |
| T1204.002 Malicious File |
GroupVOID MANTICORE | VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file. VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance. |
| T1204.002 Malicious File |
GroupPROMETHIUM | PROMETHIUM has attempted to get users to execute compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities. |
| T1204.002 Malicious File |
GroupAPT30 | APT30 has relied on users to execute malicious file attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupHEXANE | HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware. |
| T1204.002 Malicious File |
GroupRancor | Rancor attempted to get users to click on an embedded macro within a Microsoft Office Excel document to launch their malware. |
| T1204.002 Malicious File |
GroupWIRTE | WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads. |
| T1204.002 Malicious File |
GroupPLATINUM | PLATINUM has attempted to get users to open malicious files by sending spearphishing emails with attachments to victims. |
| T1204.002 Malicious File |
GroupMagic Hound | Magic Hound has attempted to lure victims into opening malicious email attachments. |
| T1204.002 Malicious File |
GroupAjax Security Team | Ajax Security Team has lured victims into executing malicious files. |
| T1204.002 Malicious File |
GroupThreat Group-3390 | Threat Group-3390 has lured victims into opening malicious files containing malware. |
| T1204.002 Malicious File |
GroupAPT33 | APT33 has used malicious e-mail attachments to lure victims into executing malware. |
| T1204.002 Malicious File |
GroupFIN8 | FIN8 has used malicious e-mail attachments to lure victims into executing malware. |
| T1204.002 Malicious File |
GroupAPT19 | APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupNomadic Octopus | Nomadic Octopus as attempted to lure victims into clicking on malicious attachments within spearphishing emails. |
| T1204.003 Malicious Image |
GroupTeamTNT | TeamTNT has relied on users to download and execute malicious Docker images. |
| T1204.004 Malicious Copy and Paste |
GroupKimsuky | Kimsuky has leveraged ClickFix type tactics enticing victims to copy and paste malicious code. |
| T1204.004 Malicious Copy and Paste |
GroupMuddyWater | MuddyWater has leveraged ClickFix type tactics enticing victims to copy and paste malicious PowerShell code. |
| T1204.004 Malicious Copy and Paste |
GroupContagious Interview | Contagious Interview has leveraged ClickFix type tactics enticing victims to copy and paste malicious code. |
| T1204.005 Malicious Library |
GroupContagious Interview | Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Securonix Contagious Interview DEVPOPPER April 2024Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1205 Traffic Signaling |
GroupKimsuky | Kimsuky has used TRANSLATEXT to redirect clients to legitimate Gmail, Naver or Kakao pages if the clients connect with no parameters. |
| T1205 Traffic Signaling |
GroupMustang Panda | Mustang Panda has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of “17 03 03” or “46 77 4d”. |
| T1205 Traffic Signaling |
GroupUNC3886 | UNC3886 has used the TABLEFLIP traffic redirection utility to listen for specialized command packets on compromised FortiManager devices. |
| T1205.001 Port Knocking |
GroupUNC3886 | UNC3886 maintained persistence on FortiGate Firewalls through ICMP port knocking. |
| T1205.001 Port Knocking |
GroupPROMETHIUM | PROMETHIUM has used a script that configures the knockd service and firewall to only accept C2 connections from systems that use a specified sequence of knock ports. |
| T1210 Exploitation of Remote Services |
GroupDragonfly | Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers. |
| T1210 Exploitation of Remote Services |
GroupmenuPass | menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472). |
| T1210 Exploitation of Remote Services |
GroupMuddyWater | MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472). |
| T1210 Exploitation of Remote Services |
GroupFIN7 | FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers. |
| T1210 Exploitation of Remote Services |
GroupEmber Bear | Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations. |
| T1210 Exploitation of Remote Services |
GroupAPT28 | APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement. |
| T1210 Exploitation of Remote Services |
GroupFox Kitten | Fox Kitten has exploited known vulnerabilities in remote services including RDP. |
| T1210 Exploitation of Remote Services |
GroupTonto Team | Tonto Team has used EternalBlue exploits for lateral movement. |
| T1210 Exploitation of Remote Services |
GroupEarth Lusca | Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472). |
| T1210 Exploitation of Remote Services |
GroupWizard Spider | Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities. |
| T1210 Exploitation of Remote Services |
GroupThreat Group-3390 | Threat Group-3390 has exploited MS17-010 to move laterally to other systems on the network. |
| T1210 Exploitation of Remote Services |
GroupShinyHunters | ShinyHunters has exploited vulnerabilities in remote services for lateral movement. |
| T1211 Exploitation for Stealth |
GroupAPT28 | APT28 has used CVE-2015-4902 to bypass security features. |
| T1211 Exploitation for Stealth |
GroupVelvet Ant | Velvet Ant exploited CVE-2024-20399 in Cisco Switches to which the threat actor was already able to authenticate in order to escape the NX-OS command line interface and gain access to the underlying operating system for arbitrary command execution. |
| T1212 Exploitation for Credential Access |
GroupUNC3886 | UNC3886 exploited CVE-2022-22948 in VMware vCenter to obtain encrypted credentials from the vCenter postgresDB. |
| T1213 Data from Information Repositories |
GroupAPT28 | APT28 has collected files from various information repositories. |
| T1213.001 Confluence |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials. |
| T1213.002 Sharepoint |
GroupHAFNIUM | HAFNIUM has abused compromised credentials to exfiltrate data from SharePoint. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.