Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.003 Spearphishing via Service |
GroupAPT29 | APT29 has used the legitimate mailing service Constant Contact to send phishing e-mails. |
| T1566.003 Spearphishing via Service |
GroupDark Caracal | Dark Caracal spearphished victims via Facebook and Whatsapp. |
| T1566.003 Spearphishing via Service |
GroupWindshift | Windshift has used fake personas on social media to engage and target victims. |
| T1566.003 Spearphishing via Service |
GroupToddyCat | ToddyCat has sent loaders configured to run Ninja as zip archives via Telegram. |
| T1566.003 Spearphishing via Service |
GroupLazarus Group | Lazarus Group has used social media platforms, including LinkedIn and Twitter, to send spearphishing messages. |
| T1566.003 Spearphishing via Service |
GroupMoonstone Sleet | Moonstone Sleet has used social media services to spear phish victims to deliver trojainized software. |
| T1566.003 Spearphishing via Service |
GroupMagic Hound | Magic Hound used various social media channels (such as LinkedIn) as well as messaging services (such as WhatsApp) to spearphish victims. |
| T1566.003 Spearphishing via Service |
GroupAjax Security Team | Ajax Security Team has used various social media channels to spearphish victims. |
| T1566.004 Spearphishing Voice |
GroupStorm-1811 | Storm-1811 has initiated voice calls with victims posing as IT support to prompt users to download and execute scripts and other tools for initial access. |
| T1567 Exfiltration Over Web Service |
GroupBlackByte | BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data. |
| T1567 Exfiltration Over Web Service |
GroupContagious Interview | Contagious Interview has leveraged Telegram API to exfiltrate stolen data. |
| T1567 Exfiltration Over Web Service |
GroupAPT28 | APT28 can exfiltrate data over Google Drive. |
| T1567 Exfiltration Over Web Service |
GroupMagic Hound | Magic Hound has used the Telegram API `sendMessage` to relay data on compromised devices. |
| T1567 Exfiltration Over Web Service |
GroupShinyHunters | ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data. |
| T1567.002 Exfiltration to Cloud Storage |
GroupIndrik Spider | Indrik Spider has exfiltrated data using Rclone or MEGASync prior to deploying ransomware. |
| T1567.002 Exfiltration to Cloud Storage |
GroupKimsuky | Kimsuky has exfiltrated stolen files and data to actor-controlled Blogspot accounts. Kimsuky has also leveraged Dropbox for uploading victim system information. |
| T1567.002 Exfiltration to Cloud Storage |
GroupHAFNIUM | HAFNIUM has exfiltrated data to file sharing sites, including MEGA. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMuddyWater | MuddyWater has attempted to exfiltrate data to Wasabi, a cloud storage service, using Rclone. |
| T1567.002 Exfiltration to Cloud Storage |
GroupFIN7 | FIN7 has exfiltrated stolen data to the MEGA file sharing site. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMustang Panda | Mustang Panda has also exfiltrated archived files to cloud services such as Dropbox using `curl`. |
| T1567.002 Exfiltration to Cloud Storage |
GroupZIRCONIUM | ZIRCONIUM has exfiltrated stolen data to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
GroupScattered Spider | Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets. |
| T1567.002 Exfiltration to Cloud Storage |
GroupContagious Interview | Contagious Interview has exfiltrated stolen passwords to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
GroupAkira | Akira will exfiltrate victim data using applications such as Rclone. |
| T1567.002 Exfiltration to Cloud Storage |
GroupPOLONIUM | POLONIUM has exfiltrated stolen data to POLONIUM-owned OneDrive and Dropbox accounts. |
| T1567.002 Exfiltration to Cloud Storage |
GroupConfucius | Confucius has exfiltrated victim data to cloud storage service accounts. |
| T1567.002 Exfiltration to Cloud Storage |
GroupLeviathan | Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
GroupTurla | Turla has used WebDAV to upload stolen USB files to a cloud drive. Turla has also exfiltrated stolen files to OneDrive and 4shared. |
| T1567.002 Exfiltration to Cloud Storage |
GroupStorm-0501 | Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI). |
| T1567.002 Exfiltration to Cloud Storage |
GroupCinnamon Tempest | Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS. |
| T1567.002 Exfiltration to Cloud Storage |
GroupChimera | Chimera has exfiltrated stolen data to OneDrive accounts. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMedusa Group | Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage. |
| T1567.002 Exfiltration to Cloud Storage |
GroupEmber Bear | Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`. |
| T1567.002 Exfiltration to Cloud Storage |
GroupToddyCat | ToddyCat has used a DropBox uploader to exfiltrate stolen files. |
| T1567.002 Exfiltration to Cloud Storage |
GroupLuminousMoth | LuminousMoth has exfiltrated data to Google Drive. |
| T1567.002 Exfiltration to Cloud Storage |
GroupEarth Lusca | Earth Lusca has used the megacmd tool to upload stolen files from a victim network to MEGA. |
| T1567.002 Exfiltration to Cloud Storage |
GroupWizard Spider | Wizard Spider has exfiltrated stolen victim data to various cloud storage providers. |
| T1567.002 Exfiltration to Cloud Storage |
GroupHEXANE | HEXANE has used cloud services, including OneDrive, for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
GroupThreat Group-3390 | Threat Group-3390 has exfiltrated stolen data to Dropbox. |
| T1568 Dynamic Resolution |
GroupKimsuky | Kimsuky has used Dynamic DNS (DDNS) services, such as FreeDNS or No-IP DDNS, to include servers located in South Korea. |
| T1568 Dynamic Resolution |
GroupRedEcho | RedEcho used dynamic DNS domains associated with malicious infrastructure. |
| T1568 Dynamic Resolution |
GroupGamaredon Group | Gamaredon Group has incorporated dynamic DNS domains in its infrastructure. |
| T1568 Dynamic Resolution |
GroupTA2541 | TA2541 has used dynamic DNS services for C2 infrastructure. |
| T1568 Dynamic Resolution |
GroupBITTER | BITTER has used DDNS for C2 communications. |
| T1568 Dynamic Resolution |
GroupAPT29 | APT29 has used Dynamic DNS providers for their malware C2 infrastructure. |
| T1568 Dynamic Resolution |
GroupAPT-C-36 | APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants. |
| T1568 Dynamic Resolution |
GroupTransparent Tribe | Transparent Tribe has used dynamic DNS services to set up C2. |
| T1568.001 Fast Flux DNS |
GroupmenuPass | menuPass has used dynamic DNS service providers to host malicious domains. |
| T1568.001 Fast Flux DNS |
GroupGamaredon Group | Gamaredon Group has used fast flux DNS to mask their command and control channel behind rotating IP addresses. Additionally, Gamaredon Group has used a low-frequency variant of the single-flux method. |
| T1568.001 Fast Flux DNS |
GroupTA505 | TA505 has used fast flux to mask botnets by distributing payloads across multiple IPs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.