Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1526 Cloud Service Discovery |
GroupStorm-0501 | Storm-0501 has discovered the victim environment’s protections to include Azure policies, resource locks, and Azure Storage immutability policies. |
| T1528 Steal Application Access Token |
GroupAPT29 | APT29 uses stolen tokens to access victim accounts, without needing a password. |
| T1528 Steal Application Access Token |
GroupAPT28 | APT28 has used several malicious applications to steal user OAuth access tokens including applications masquerading as "Google Defender" "Google Email Protection," and "Google Scanner" for Gmail users. They also targeted Yahoo users with applications masquerading as "Delivery Service" and "McAfee Email Protection". |
| T1528 Steal Application Access Token |
GroupTeamPCP | TeamPCP has used malware to steal access tokens from targeted cloud and developer environments. |
| T1528 Steal Application Access Token |
GroupShinyHunters | ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository. Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms. |
| T1529 System Shutdown/Reboot |
GroupAPT38 | APT38 has used a custom MBR wiper named BOOTWRECK, which will initiate a system reboot after wiping the victim's MBR. |
| T1529 System Shutdown/Reboot |
GroupAPT37 | APT37 has used malware that will issue the command |
| T1529 System Shutdown/Reboot |
GroupMedusa Group | Medusa Group has manually turned off and encrypted virtual machines. |
| T1529 System Shutdown/Reboot |
GroupLazarus Group | Lazarus Group has rebooted systems after destroying files and wiping the MBR on infected systems. |
| T1530 Data from Cloud Storage |
GroupHAFNIUM | HAFNIUM has exfitrated data from OneDrive. |
| T1530 Data from Cloud Storage |
GroupScattered Spider | Scattered Spider enumerates data stored in cloud resources for collection and exfiltration purposes. |
| T1530 Data from Cloud Storage |
GroupStorm-0501 | Storm-0501 had modified Azure Storage account resources through the `Microsoft.Storage/storageAccounts/write` operation to expose non-remotely accessible accounts for data exfiltration. |
| T1530 Data from Cloud Storage |
GroupAPT42 | APT42 has collected data from Microsoft 365 environments. |
| T1530 Data from Cloud Storage |
GroupFox Kitten | Fox Kitten has obtained files from the victim's cloud storage instances. |
| T1530 Data from Cloud Storage |
GroupShinyHunters | ShinyHunters has collected data from insecure cloud buckets. |
| T1531 Account Access Removal |
GroupAkira | Akira deletes administrator accounts in victim networks prior to encryption. |
| T1531 Account Access Removal |
GroupLAPSUS$ | LAPSUS$ has removed a targeted organization's global admin accounts to lock the organization out of all access. |
| T1534 Internal Spearphishing |
GroupKimsuky | Kimsuky has sent internal spearphishing emails for lateral movement after stealing victim information. |
| T1534 Internal Spearphishing |
GroupMuddyWater | MuddyWater has used compromised mailboxes within target organizations to send spearphishing emails. |
| T1534 Internal Spearphishing |
GroupGamaredon Group | Gamaredon Group has used an Outlook VBA module on infected systems to send phishing emails with malicious attachments to other employees within the organization. |
| T1534 Internal Spearphishing |
GroupLeviathan | Leviathan has conducted internal spearphishing within the victim's environment for lateral movement. |
| T1534 Internal Spearphishing |
GroupAPT-C-36 | APT-C-36 has used a compromised account to send a phishing email to an address likely used and monitored by the IT team within the same targeted organization. |
| T1534 Internal Spearphishing |
GroupHEXANE | HEXANE has conducted internal spearphishing attacks against executives, HR, and IT personnel to gain information and access. |
| T1537 Transfer Data to Cloud Account |
GroupStorm-0501 | Storm-0501 has copied data from the victims environment to their own infrastructure leveraging AzCopy CLI. |
| T1537 Transfer Data to Cloud Account |
GroupRedCurl | RedCurl has used cloud storage to exfiltrate data, in particular the megatools utilities were used to exfiltrate data to Mega, a file storage service. |
| T1537 Transfer Data to Cloud Account |
GroupINC Ransom | INC Ransom has used Megasync to exfiltrate data to the cloud. |
| T1538 Cloud Service Dashboard |
GroupScattered Spider | Scattered Spider abused AWS Systems Manager Inventory to identify targets on the compromised network prior to lateral movement. |
| T1539 Steal Web Session Cookie |
GroupKimsuky | Kimsuky has used malware, such as TRANSLATEXT, to steal and exfiltrate browser cookies. |
| T1539 Steal Web Session Cookie |
GroupEvilnum | Evilnum can steal cookies and session information from browsers. |
| T1539 Steal Web Session Cookie |
GroupSandworm Team | Sandworm Team used information stealer malware to collect browser session cookies. |
| T1539 Steal Web Session Cookie |
GroupScattered Spider | Scattered Spider retrieves browser cookies via Raccoon Stealer. |
| T1539 Steal Web Session Cookie |
GroupLotus Blossom | Lotus Blossom has used publicly-available tools to steal cookies from browsers such as Chrome. |
| T1539 Steal Web Session Cookie |
GroupStar Blizzard | Star Blizzard has used EvilGinx to steal the session cookies of victims directed to |
| T1539 Steal Web Session Cookie |
GroupLuminousMoth | LuminousMoth has used an unnamed post-exploitation tool to steal cookies from the Chrome browser. |
| T1539 Steal Web Session Cookie |
GroupAPT42 | APT42 has used custom malware to steal login and cookie data from common browsers. |
| T1542.002 Component Firmware |
GroupEquation | Equation is known to have the capability to overwrite the firmware on hard drives from some manufacturers. |
| T1542.003 Bootkit |
GroupAPT41 | APT41 deployed Master Boot Record bootkits on Windows systems to hide their malware and maintain persistence on victim systems. |
| T1542.003 Bootkit |
GroupAPT28 | APT28 has deployed a bootkit along with Downdelph to ensure its persistence on the victim. The bootkit shares code with some variants of BlackEnergy. |
| T1542.003 Bootkit |
GroupLazarus Group | Lazarus Group malware WhiskeyAlfa-Three modifies sector 0 of the Master Boot Record (MBR) to ensure that the malware will persist even if a victim machine shuts down. |
| T1543.001 Launch Agent |
GroupContagious Interview | Contagious Interview has established persistence using InvisibleFerret malware to create file to run the script on Startup via LaunchAgents. Contagious Interview has also utilized a plist file located in `/Library/LaunchAgents` to enable a malicious bash script the ability to persist. |
| T1543.002 Systemd Service |
GroupTeamTNT | TeamTNT has established persistence through the creation of a cryptocurrency mining system service using |
| T1543.002 Systemd Service |
GroupRocke | Rocke has installed a systemd service script to maintain persistence. |
| T1543.002 Systemd Service |
GroupScattered Spider | Scattered Spider has run `SYSTEMD_UNIT_PATH="/lib/systemd/ |
| T1543.002 Systemd Service |
GroupTeamPCP | TeamPCP has used the systemd user service for malware persistence in targeted environments. |
| T1543.003 Windows Service |
GroupAPT38 | APT38 has installed a new Windows service to establish persistence. |
| T1543.003 Windows Service |
GroupBlackByte | BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines. |
| T1543.003 Windows Service |
GroupAPT3 | APT3 has a tool that creates a new service for persistence. |
| T1543.003 Windows Service |
GroupKimsuky | Kimsuky has created new services for persistence. |
| T1543.003 Windows Service |
GroupAPT41 | APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike. |
| T1543.003 Windows Service |
GroupAPT32 | APT32 modified Windows Services to ensure PowerShell scripts were loaded on the system. APT32 also creates a Windows service to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.