ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1213.002
Sharepoint
GroupAkira

Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.

T1213.002
Sharepoint
GroupKe3chang

Ke3chang used a SharePoint enumeration and data dumping tool known as spwebmember.

T1213.002
Sharepoint
GroupChimera

Chimera has collected documents from the victim's SharePoint.

T1213.002
Sharepoint
GroupAPT28

APT28 has collected information from Microsoft SharePoint services within target networks.

T1213.002
Sharepoint
GroupLAPSUS$

LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials.

T1213.002
Sharepoint
GroupVOID MANTICORE

VOID MANTICORE has accessed victim’s public facing SharePoint servers and exfiltrated data.

T1213.003
Code Repositories
GroupAPT41

APT41 cloned victim user Git repositories during intrusions.

T1213.003
Code Repositories
GroupScattered Spider

Scattered Spider enumerates data stored within victim code repositories, such as internal GitHub repositories.

T1213.003
Code Repositories
GroupLAPSUS$

LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials.

T1213.003
Code Repositories
GroupShinyHunters

ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code.

T1213.005
Messaging Applications
GroupScattered Spider

Scattered Spider threat actors search the victim’s Slack and Microsoft Teams for conversations about the intrusion and incident response.

T1213.005
Messaging Applications
GroupFox Kitten

Fox Kitten has accessed victim security and IT environments and Microsoft Teams to mine valuable information.

T1213.005
Messaging Applications
GroupLAPSUS$

LAPSUS$ has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials.

T1213.006
Databases
GroupFIN6

FIN6 has collected schemas and user accounts from systems running SQL Server.

T1213.006
Databases
GroupSandworm Team

Sandworm Team exfiltrates data of interest from enterprise databases using Adminer.

T1213.006
Databases
GroupSea Turtle

Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines.

T1213.006
Databases
GroupTurla

Turla has used a custom .NET tool to collect documents from an organization's internal central database.

T1213.006
Databases
GroupShinyHunters

ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors.

T1216.001
PubPrn
GroupAPT32

APT32 has used PubPrn.vbs within execution scripts to execute malware, possibly bypassing defenses.

T1217
Browser Information Discovery
GroupAPT38

APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources.

T1217
Browser Information Discovery
GroupKimsuky

Kimsuky has collected sensitive browser data using the function `GetBrowserData()` to include login credentials, bookmarks, cookies, and encryption keys.

T1217
Browser Information Discovery
GroupVolt Typhoon

Volt Typhoon has targeted the browsing history of network administrators.

T1217
Browser Information Discovery
GroupScattered Spider

Scattered Spider retrieves browser histories via infostealer malware such as Raccoon Stealer.

T1217
Browser Information Discovery
GroupChimera

Chimera has used type \\<hostname>\c$\Users\<username>\Favorites\Links\Bookmarks bar\Imported From IE\*citrix* for bookmark discovery.

T1217
Browser Information Discovery
GroupFox Kitten

Fox Kitten has used Google Chrome bookmarks to identify internal resources and assets.

T1217
Browser Information Discovery
GroupMoonstone Sleet

Moonstone Sleet deployed malware such as YouieLoader capable of capturing victim system browser information.

T1218
System Binary Proxy Execution
GroupVolt Typhoon

Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks.

T1218
System Binary Proxy Execution
GroupLazarus Group

Lazarus Group lnk files used for persistence have abused the Windows Update Client (wuauclt.exe) to execute a malicious DLL.

T1218.001
Compiled HTML File
GroupAPT38

APT38 has used CHM files to move concealed payloads.

T1218.001
Compiled HTML File
GroupAPT41

APT41 used compiled HTML (.chm) files for targeting.

T1218.001
Compiled HTML File
GroupOilRig

OilRig has used a CHM payload to load and execute another malicious file once delivered to a victim.

T1218.001
Compiled HTML File
GroupDark Caracal

Dark Caracal leveraged a compiled HTML file that contained a command to download and run an executable.

T1218.001
Compiled HTML File
GroupSilence

Silence has weaponized CHM files in their phishing campaigns.

T1218.003
CMSTP
GroupMuddyWater

MuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload.

T1218.003
CMSTP
GroupCobalt Group

Cobalt Group has used the command cmstp.exe /s /ns C:\Users\ADMINI~W\AppData\Local\Temp\XKNqbpzl.txt to bypass AppLocker and launch a malicious script.

T1218.004
InstallUtil
GroupmenuPass

menuPass has used InstallUtil.exe to execute malicious software.

T1218.004
InstallUtil
GroupMustang Panda

Mustang Panda has used InstallUtil.exe to execute a malicious Beacon stager.

T1218.005
Mshta
GroupAPT38

APT38 has used a renamed version of `mshta.exe` to execute malicious HTML files.

T1218.005
Mshta
GroupSideCopy

SideCopy has utilized `mshta.exe` to execute a malicious hta file.

T1218.005
Mshta
GroupKimsuky

Kimsuky has used mshta.exe to run malicious scripts on the system.

T1218.005
Mshta
GroupAPT32

APT32 has used mshta.exe for code execution.

T1218.005
Mshta
GroupMuddyWater

MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution.

T1218.005
Mshta
GroupGamaredon Group

Gamaredon Group has used `mshta.exe` to execute malicious files.

T1218.005
Mshta
GroupFIN7

FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.

T1218.005
Mshta
GroupSidewinder

Sidewinder has used mshta.exe to execute malicious payloads.

T1218.005
Mshta
GroupMustang Panda

Mustang Panda has used mshta.exe to launch collection scripts.

T1218.005
Mshta
GroupTA2541

TA2541 has used `mshta` to execute scripts including VBS.

T1218.005
Mshta
GroupConfucius

Confucius has used mshta.exe to execute malicious VBScript.

T1218.005
Mshta
GroupAPT29

APT29 has use `mshta` to execute malicious scripts on a compromised host.

T1218.005
Mshta
GroupTA551

TA551 has used mshta.exe to execute malicious payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.