Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.005 Hidden File System |
GroupStrider | Strider has used a hidden file system that is stored as a file on disk. |
| T1564.005 Hidden File System |
GroupEquation | Equation has used an encrypted virtual file system stored in the Windows Registry. |
| T1564.008 Email Hiding Rules |
GroupScattered Spider | Scattered Spider creates inbound rules on the compromised email accounts of security personnel to automatically delete emails from vendor security products. |
| T1564.008 Email Hiding Rules |
GroupFIN4 | FIN4 has created rules in victims' Microsoft Outlook accounts to automatically delete emails containing words such as “hacked," "phish," and “malware" in a likely attempt to prevent organizations from communicating about their activities. |
| T1564.011 Ignore Process Interrupts |
GroupKimsuky | Kimsuky has leveraged the PowerShell `-ErrorAction SilentlyContinue` command to continue execution through system events. |
| T1564.011 Ignore Process Interrupts |
GroupUNC3886 | UNC3886 modified the startup file `/etc/init.d/localnet` to execute the line `nohup /bin/support &` so the script would run when the system was rebooted. |
| T1564.011 Ignore Process Interrupts |
GroupSea Turtle | Sea Turtle executed SnappyTCP using the tool NoHup, which keeps the malware running on a system after exiting the shell or terminal. |
| T1564.012 File/Path Exclusions |
GroupTurla | Turla has placed LunarWeb install files into directories that are excluded from scanning. |
| T1565 Data Manipulation |
GroupFIN13 | FIN13 has injected fraudulent transactions into compromised networks that mimic legitimate behavior to siphon off incremental amounts of money. |
| T1565.001 Stored Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK to create, delete, and alter records in databases used for SWIFT transactions. |
| T1565.002 Transmitted Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK to manipulate SWIFT messages en route to a printer. |
| T1565.003 Runtime Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK.FOX to manipulate PDF data as it is accessed to remove traces of fraudulent SWIFT transactions from the data displayed to the end user. |
| T1566 Phishing |
GroupKimsuky | Kimsuky has used spearphishing to gain initial access and intelligence. |
| T1566 Phishing |
GroupAppleJeus | AppleJeus has used spearphishing emails to distribute malicious payloads. |
| T1566 Phishing |
GroupMuddyWater | MuddyWater has sent phishing emails to targets from the email address support@microsoftonlines[.]com. |
| T1566 Phishing |
GroupSea Turtle | Sea Turtle used spear phishing to gain initial access to victims. |
| T1566 Phishing |
GroupAxiom | Axiom has used spear phishing to initially compromise victims. |
| T1566 Phishing |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has conducted malicious spam (malspam) campaigns to gain access to victim's machines. |
| T1566 Phishing |
GroupINC Ransom | INC Ransom has used phishing to gain initial access. |
| T1566 Phishing |
GroupVOID MANTICORE | VOID MANTICORE has emailed victims threatening messages. VOID MANTICORE has used phishing as an initial access vector. |
| T1566.001 Spearphishing Attachment |
GroupAPT38 | APT38 has conducted spearphishing campaigns using malicious email attachments. |
| T1566.001 Spearphishing Attachment |
GroupElderwood | Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
GroupSideCopy | SideCopy has sent spearphishing emails with malicious hta file attachments. |
| T1566.001 Spearphishing Attachment |
GroupKimsuky | Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links. |
| T1566.001 Spearphishing Attachment |
GroupEXOTIC LILY | EXOTIC LILY conducted an e-mail thread-hijacking campaign with malicious ISO attachments. |
| T1566.001 Spearphishing Attachment |
Groupadmin@338 | admin@338 has sent emails with malicious Microsoft Office documents attached. |
| T1566.001 Spearphishing Attachment |
GroupPatchwork | Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims. |
| T1566.001 Spearphishing Attachment |
GroupAPT41 | APT41 sent spearphishing emails with attachments such as compiled HTML (.chm) files to initially compromise their victims. |
| T1566.001 Spearphishing Attachment |
GroupDragonfly | Dragonfly has sent emails with malicious attachments to gain initial access. |
| T1566.001 Spearphishing Attachment |
GroupGorgon Group | Gorgon Group sent emails to victims with malicious Microsoft Office documents attached. |
| T1566.001 Spearphishing Attachment |
GroupmenuPass | menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents. |
| T1566.001 Spearphishing Attachment |
GroupAPT32 | APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet. |
| T1566.001 Spearphishing Attachment |
GroupMuddyWater | MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022ESET_MuddyWater_Dec2025FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024SOCRadar_MuddyWaterDindoor_Mar2026Securelist MuddyWater Oct 2018Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1566.001 Spearphishing Attachment |
GroupNaikon | Naikon has used malicious e-mail attachments to deliver malware. |
| T1566.001 Spearphishing Attachment |
GroupFIN6 | FIN6 has targeted victims with e-mails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
GroupGamaredon Group | Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives. |
| T1566.001 Spearphishing Attachment |
GroupGallmaker | Gallmaker sent emails with malicious Microsoft Office documents attached. |
| T1566.001 Spearphishing Attachment |
GroupFIN7 | FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached. |
| T1566.001 Spearphishing Attachment |
GroupSandworm Team | Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails. |
| T1566.001 Spearphishing Attachment |
GroupMachete | Machete has delivered spearphishing emails that contain a zipped file with malicious contents. |
| T1566.001 Spearphishing Attachment |
GroupAndariel | Andariel has conducted spearphishing campaigns that included malicious Word or Excel attachments. |
| T1566.001 Spearphishing Attachment |
GroupCURIUM | CURIUM has used phishing with malicious attachments for initial access to victim environments. |
| T1566.001 Spearphishing Attachment |
GroupSidewinder | Sidewinder has sent e-mails with malicious attachments often crafted for specific targets. |
| T1566.001 Spearphishing Attachment |
GroupMustang Panda | Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs. 2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024 |
| T1566.001 Spearphishing Attachment |
GroupAPT39 | APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims. |
| T1566.001 Spearphishing Attachment |
GroupTA2541 | TA2541 has sent phishing emails with malicious attachments for initial access including MS Word documents. |
| T1566.001 Spearphishing Attachment |
GroupAPT37 | APT37 delivers malware using spearphishing emails with malicious HWP attachments. |
| T1566.001 Spearphishing Attachment |
GroupOilRig | OilRig has sent spearphising emails with malicious attachments to potential victims using compromised and/or spoofed email accounts. |
| T1566.001 Spearphishing Attachment |
GroupHigaisa | Higaisa has sent spearphishing emails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
GroupTropic Trooper | Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.