ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1566.003
Spearphishing via Service
GroupAPT29

APT29 has used the legitimate mailing service Constant Contact to send phishing e-mails.

T1566.003
Spearphishing via Service
GroupDark Caracal

Dark Caracal spearphished victims via Facebook and Whatsapp.

T1566.003
Spearphishing via Service
GroupWindshift

Windshift has used fake personas on social media to engage and target victims.

T1566.003
Spearphishing via Service
GroupToddyCat

ToddyCat has sent loaders configured to run Ninja as zip archives via Telegram.

T1566.003
Spearphishing via Service
GroupLazarus Group

Lazarus Group has used social media platforms, including LinkedIn and Twitter, to send spearphishing messages.

T1566.003
Spearphishing via Service
GroupMoonstone Sleet

Moonstone Sleet has used social media services to spear phish victims to deliver trojainized software.

T1566.003
Spearphishing via Service
GroupMagic Hound

Magic Hound used various social media channels (such as LinkedIn) as well as messaging services (such as WhatsApp) to spearphish victims.

T1566.003
Spearphishing via Service
GroupAjax Security Team

Ajax Security Team has used various social media channels to spearphish victims.

T1566.004
Spearphishing Voice
GroupStorm-1811

Storm-1811 has initiated voice calls with victims posing as IT support to prompt users to download and execute scripts and other tools for initial access.

T1567
Exfiltration Over Web Service
GroupBlackByte

BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data.

T1567
Exfiltration Over Web Service
GroupContagious Interview

Contagious Interview has leveraged Telegram API to exfiltrate stolen data.

T1567
Exfiltration Over Web Service
GroupAPT28

APT28 can exfiltrate data over Google Drive.

T1567
Exfiltration Over Web Service
GroupMagic Hound

Magic Hound has used the Telegram API `sendMessage` to relay data on compromised devices.

T1567
Exfiltration Over Web Service
GroupShinyHunters

ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data.

T1567.002
Exfiltration to Cloud Storage
GroupIndrik Spider

Indrik Spider has exfiltrated data using Rclone or MEGASync prior to deploying ransomware.

T1567.002
Exfiltration to Cloud Storage
GroupKimsuky

Kimsuky has exfiltrated stolen files and data to actor-controlled Blogspot accounts. Kimsuky has also leveraged Dropbox for uploading victim system information.

T1567.002
Exfiltration to Cloud Storage
GroupHAFNIUM

HAFNIUM has exfiltrated data to file sharing sites, including MEGA.

T1567.002
Exfiltration to Cloud Storage
GroupMuddyWater

MuddyWater has attempted to exfiltrate data to Wasabi, a cloud storage service, using Rclone.

T1567.002
Exfiltration to Cloud Storage
GroupFIN7

FIN7 has exfiltrated stolen data to the MEGA file sharing site.

T1567.002
Exfiltration to Cloud Storage
GroupMustang Panda

Mustang Panda has also exfiltrated archived files to cloud services such as Dropbox using `curl`.

T1567.002
Exfiltration to Cloud Storage
GroupZIRCONIUM

ZIRCONIUM has exfiltrated stolen data to Dropbox.

T1567.002
Exfiltration to Cloud Storage
GroupScattered Spider

Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets.

T1567.002
Exfiltration to Cloud Storage
GroupContagious Interview

Contagious Interview has exfiltrated stolen passwords to Dropbox.

T1567.002
Exfiltration to Cloud Storage
GroupAkira

Akira will exfiltrate victim data using applications such as Rclone.

T1567.002
Exfiltration to Cloud Storage
GroupPOLONIUM

POLONIUM has exfiltrated stolen data to POLONIUM-owned OneDrive and Dropbox accounts.

T1567.002
Exfiltration to Cloud Storage
GroupConfucius

Confucius has exfiltrated victim data to cloud storage service accounts.

T1567.002
Exfiltration to Cloud Storage
GroupLeviathan

Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox.

T1567.002
Exfiltration to Cloud Storage
GroupTurla

Turla has used WebDAV to upload stolen USB files to a cloud drive. Turla has also exfiltrated stolen files to OneDrive and 4shared.

T1567.002
Exfiltration to Cloud Storage
GroupStorm-0501

Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI).

T1567.002
Exfiltration to Cloud Storage
GroupCinnamon Tempest

Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS.

T1567.002
Exfiltration to Cloud Storage
GroupChimera

Chimera has exfiltrated stolen data to OneDrive accounts.

T1567.002
Exfiltration to Cloud Storage
GroupMedusa Group

Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage.

T1567.002
Exfiltration to Cloud Storage
GroupEmber Bear

Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`.

T1567.002
Exfiltration to Cloud Storage
GroupToddyCat

ToddyCat has used a DropBox uploader to exfiltrate stolen files.

T1567.002
Exfiltration to Cloud Storage
GroupLuminousMoth

LuminousMoth has exfiltrated data to Google Drive.

T1567.002
Exfiltration to Cloud Storage
GroupEarth Lusca

Earth Lusca has used the megacmd tool to upload stolen files from a victim network to MEGA.

T1567.002
Exfiltration to Cloud Storage
GroupWizard Spider

Wizard Spider has exfiltrated stolen victim data to various cloud storage providers.

T1567.002
Exfiltration to Cloud Storage
GroupHEXANE

HEXANE has used cloud services, including OneDrive, for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
GroupThreat Group-3390

Threat Group-3390 has exfiltrated stolen data to Dropbox.

T1568
Dynamic Resolution
GroupKimsuky

Kimsuky has used Dynamic DNS (DDNS) services, such as FreeDNS or No-IP DDNS, to include servers located in South Korea.

T1568
Dynamic Resolution
GroupRedEcho

RedEcho used dynamic DNS domains associated with malicious infrastructure.

T1568
Dynamic Resolution
GroupGamaredon Group

Gamaredon Group has incorporated dynamic DNS domains in its infrastructure.

T1568
Dynamic Resolution
GroupTA2541

TA2541 has used dynamic DNS services for C2 infrastructure.

T1568
Dynamic Resolution
GroupBITTER

BITTER has used DDNS for C2 communications.

T1568
Dynamic Resolution
GroupAPT29

APT29 has used Dynamic DNS providers for their malware C2 infrastructure.

T1568
Dynamic Resolution
GroupAPT-C-36

APT-C-36 has used DDNS services such as DuckDNS, noip[.]com, and con-ip[.]com to redirect victims to sites or repositories hosting malware implants.

T1568
Dynamic Resolution
GroupTransparent Tribe

Transparent Tribe has used dynamic DNS services to set up C2.

T1568.001
Fast Flux DNS
GroupmenuPass

menuPass has used dynamic DNS service providers to host malicious domains.

T1568.001
Fast Flux DNS
GroupGamaredon Group

Gamaredon Group has used fast flux DNS to mask their command and control channel behind rotating IP addresses. Additionally, Gamaredon Group has used a low-frequency variant of the single-flux method.

T1568.001
Fast Flux DNS
GroupTA505

TA505 has used fast flux to mask botnets by distributing payloads across multiple IPs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.