ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1583
Acquire Infrastructure
GroupKimsuky

Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure.

T1583
Acquire Infrastructure
GroupSandworm Team

Sandworm Team used various third-party email campaign management services to deliver phishing emails.

T1583
Acquire Infrastructure
GroupContagious Interview

Contagious Interview has used services such as Astrill VPN.

T1583
Acquire Infrastructure
GroupSea Turtle

Sea Turtle accessed victim networks from VPN service provider networks.

T1583
Acquire Infrastructure
GroupStar Blizzard

Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails.

T1583
Acquire Infrastructure
GroupEmber Bear

Ember Bear uses services such as IVPN, SurfShark, and Tor to add anonymization to operations.

T1583
Acquire Infrastructure
GroupAgrius

Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN.

T1583
Acquire Infrastructure
GroupTeamPCP

In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests.

T1583.001
Domains
GroupAPT38

APT38 has created fake domains to imitate legitimate venture capital or bank domains.

T1583.001
Domains
GroupKimsuky

Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges.

T1583.001
Domains
GroupEXOTIC LILY

EXOTIC LILY has registered domains to spoof targeted organizations by changing the top-level domain (TLD) to “.us”, “.co” or “.biz”.

T1583.001
Domains
GroupDragonfly

Dragonfly has registered domains for targeting intended victims.

T1583.001
Domains
GroupmenuPass

menuPass has registered malicious domains for use in intrusion campaigns.

T1583.001
Domains
GroupAPT32

APT32 has set up and operated websites to gather information and deliver malware.

T1583.001
Domains
GroupMuddyWater

MuddyWater has established domains, some of which appeared to spoof legitimate domains for use in operations.

T1583.001
Domains
GroupRedEcho

RedEcho has registered domains spoofing Indian critical infrastructure entities.

T1583.001
Domains
GroupGamaredon Group

Gamaredon Group has registered multiple domains to facilitate payload staging and C2.

T1583.001
Domains
GroupStorm-1811

Storm-1811 has created domains for use with RMM tools.

T1583.001
Domains
GroupTeamTNT

TeamTNT has obtained domains to host their payloads.

T1583.001
Domains
GroupFIN7

FIN7 has registered look-alike domains for use in phishing campaigns. Additionally, FIN7 has registered a malicious domain as `advanced-ip-sccanner[.]com` that redirected to an adversary-controlled Dropbox which contained the malicious executable.

T1583.001
Domains
GroupSandworm Team

Sandworm Team has registered domain names and created URLs that are often designed to mimic or spoof legitimate websites, such as email login pages, online file sharing and storage websites, and password reset pages, while also hosting these items on legitimate, compromised network infrastructure.

T1583.001
Domains
GroupCURIUM

CURIUM created domains to facilitate strategic website compromise and credential capture activities.

T1583.001
Domains
GroupMustang Panda

Mustang Panda has acquired C2 domains prior to operations.

T1583.001
Domains
GroupZIRCONIUM

ZIRCONIUM has purchased domains for use in targeted campaigns.

T1583.001
Domains
GroupScattered Spider

Scattered Spider has registered domains to spoof legitimate corporate login portals.

T1583.001
Domains
GroupContagious Interview

Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2.

T1583.001
Domains
GroupTA2541

TA2541 has registered domains often containing the keywords “kimjoy,” “h0pe,” and “grace,” using domain registrars including Netdorm and No-IP DDNS, and hosting providers including xTom GmbH and Danilenko, Artyom.

T1583.001
Domains
GroupOilRig

OilRig has set up fake VPN portals, conference sign ups, and job application websites to target victims.

T1583.001
Domains
GroupSea Turtle

Sea Turtle registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers.

T1583.001
Domains
GroupFerocious Kitten

Ferocious Kitten has acquired domains imitating legitimate sites.

T1583.001
Domains
GroupAPT1

APT1 has registered hundreds of domains for use in operations.

T1583.001
Domains
GroupLeviathan

Leviathan has established domains that impersonate legitimate entities to use for targeting efforts.

T1583.001
Domains
GroupWinter Vivern

Winter Vivern registered domains mimicking other entities throughout various campaigns.

T1583.001
Domains
GroupTA505

TA505 has registered domains to impersonate services such as Dropbox to distribute malware.

T1583.001
Domains
GroupBITTER

BITTER has registered a variety of domains to host malicious payloads and for C2.

T1583.001
Domains
GroupSilent Librarian

Silent Librarian has acquired domains to establish credential harvesting pages, often spoofing the target organization and using free top level domains .TK, .ML, .GA, .CF, and .GQ.

T1583.001
Domains
GroupStar Blizzard

Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations.

T1583.001
Domains
GroupLazyScripter

LazyScripter has used dynamic DNS providers to create legitimate-looking subdomains for C2.

T1583.001
Domains
GroupAPT28

APT28 registered domains imitating NATO, OSCE security websites, Caucasus information resources, and other organizations.

T1583.001
Domains
GroupAPT42

APT42 has registered domains, several of which masqueraded as news outlets and login services, for use in operations.

T1583.001
Domains
GroupAPT-C-36

APT-C-36 has acquired domains to host malicious payloads.

T1583.001
Domains
GroupWinnti Group

Winnti Group has registered domains for C2 that mimicked sites of their intended targets.

T1583.001
Domains
GroupLazarus Group

Lazarus Group has acquired domains related to their campaigns to act as distribution points and C2 channels.

T1583.001
Domains
GroupEarth Lusca

Earth Lusca has registered domains, intended to look like legitimate target domains, that have been used in watering hole attacks.

T1583.001
Domains
GroupTransparent Tribe

Transparent Tribe has registered domains to mimic file sharing, government, defense, and research websites for use in targeted campaigns.

T1583.001
Domains
GroupIndigoZebra

IndigoZebra has established domains, some of which were designed to look like official government domains, for their operations.

T1583.001
Domains
GroupMoonstone Sleet

Moonstone Sleet registered domains to develop effective personas for fake companies used in phishing activity.

T1583.001
Domains
GroupVOID MANTICORE

VOID MANTICORE has registered domains for messaging purposes. VOID MANTICORE has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion. VOID MANTICORE has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex. VOID MANTICORE has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations.

T1583.001
Domains
GroupHEXANE

HEXANE has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization.

T1583.001
Domains
GroupWIRTE

WIRTE has registered domains designed to mimic legitimate sites for use in phishing campaigns.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.