Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583 Acquire Infrastructure |
GroupKimsuky | Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure. |
| T1583 Acquire Infrastructure |
GroupSandworm Team | Sandworm Team used various third-party email campaign management services to deliver phishing emails. |
| T1583 Acquire Infrastructure |
GroupContagious Interview | Contagious Interview has used services such as Astrill VPN. |
| T1583 Acquire Infrastructure |
GroupSea Turtle | Sea Turtle accessed victim networks from VPN service provider networks. |
| T1583 Acquire Infrastructure |
GroupStar Blizzard | Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails. |
| T1583 Acquire Infrastructure |
GroupEmber Bear | Ember Bear uses services such as IVPN, SurfShark, and Tor to add anonymization to operations. |
| T1583 Acquire Infrastructure |
GroupAgrius | Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN. |
| T1583 Acquire Infrastructure |
GroupTeamPCP | In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests. |
| T1583.001 Domains |
GroupAPT38 | APT38 has created fake domains to imitate legitimate venture capital or bank domains. |
| T1583.001 Domains |
GroupKimsuky | Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges. |
| T1583.001 Domains |
GroupEXOTIC LILY | EXOTIC LILY has registered domains to spoof targeted organizations by changing the top-level domain (TLD) to “.us”, “.co” or “.biz”. |
| T1583.001 Domains |
GroupDragonfly | Dragonfly has registered domains for targeting intended victims. |
| T1583.001 Domains |
GroupmenuPass | menuPass has registered malicious domains for use in intrusion campaigns. |
| T1583.001 Domains |
GroupAPT32 | APT32 has set up and operated websites to gather information and deliver malware. |
| T1583.001 Domains |
GroupMuddyWater | MuddyWater has established domains, some of which appeared to spoof legitimate domains for use in operations. |
| T1583.001 Domains |
GroupRedEcho | RedEcho has registered domains spoofing Indian critical infrastructure entities. |
| T1583.001 Domains |
GroupGamaredon Group | Gamaredon Group has registered multiple domains to facilitate payload staging and C2. |
| T1583.001 Domains |
GroupStorm-1811 | Storm-1811 has created domains for use with RMM tools. |
| T1583.001 Domains |
GroupTeamTNT | TeamTNT has obtained domains to host their payloads. |
| T1583.001 Domains |
GroupFIN7 | FIN7 has registered look-alike domains for use in phishing campaigns. Additionally, FIN7 has registered a malicious domain as `advanced-ip-sccanner[.]com` that redirected to an adversary-controlled Dropbox which contained the malicious executable. |
| T1583.001 Domains |
GroupSandworm Team | Sandworm Team has registered domain names and created URLs that are often designed to mimic or spoof legitimate websites, such as email login pages, online file sharing and storage websites, and password reset pages, while also hosting these items on legitimate, compromised network infrastructure. |
| T1583.001 Domains |
GroupCURIUM | CURIUM created domains to facilitate strategic website compromise and credential capture activities. |
| T1583.001 Domains |
GroupMustang Panda | Mustang Panda has acquired C2 domains prior to operations. CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023McAfee Dianxun March 2021Palo Alto Networks, Unit 42Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015 |
| T1583.001 Domains |
GroupZIRCONIUM | ZIRCONIUM has purchased domains for use in targeted campaigns. |
| T1583.001 Domains |
GroupScattered Spider | Scattered Spider has registered domains to spoof legitimate corporate login portals. |
| T1583.001 Domains |
GroupContagious Interview | Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2. ESET Contagious Interview BeaverTail InvisibleFerret February 2025PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Sekoia ClickFake 2025Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1583.001 Domains |
GroupTA2541 | TA2541 has registered domains often containing the keywords “kimjoy,” “h0pe,” and “grace,” using domain registrars including Netdorm and No-IP DDNS, and hosting providers including xTom GmbH and Danilenko, Artyom. |
| T1583.001 Domains |
GroupOilRig | OilRig has set up fake VPN portals, conference sign ups, and job application websites to target victims. |
| T1583.001 Domains |
GroupSea Turtle | Sea Turtle registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers. |
| T1583.001 Domains |
GroupFerocious Kitten | Ferocious Kitten has acquired domains imitating legitimate sites. |
| T1583.001 Domains |
GroupAPT1 | APT1 has registered hundreds of domains for use in operations. |
| T1583.001 Domains |
GroupLeviathan | Leviathan has established domains that impersonate legitimate entities to use for targeting efforts. |
| T1583.001 Domains |
GroupWinter Vivern | Winter Vivern registered domains mimicking other entities throughout various campaigns. |
| T1583.001 Domains |
GroupTA505 | TA505 has registered domains to impersonate services such as Dropbox to distribute malware. |
| T1583.001 Domains |
GroupBITTER | BITTER has registered a variety of domains to host malicious payloads and for C2. |
| T1583.001 Domains |
GroupSilent Librarian | Silent Librarian has acquired domains to establish credential harvesting pages, often spoofing the target organization and using free top level domains .TK, .ML, .GA, .CF, and .GQ. |
| T1583.001 Domains |
GroupStar Blizzard | Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations. |
| T1583.001 Domains |
GroupLazyScripter | LazyScripter has used dynamic DNS providers to create legitimate-looking subdomains for C2. |
| T1583.001 Domains |
GroupAPT28 | APT28 registered domains imitating NATO, OSCE security websites, Caucasus information resources, and other organizations. |
| T1583.001 Domains |
GroupAPT42 | APT42 has registered domains, several of which masqueraded as news outlets and login services, for use in operations. |
| T1583.001 Domains |
GroupAPT-C-36 | APT-C-36 has acquired domains to host malicious payloads. |
| T1583.001 Domains |
GroupWinnti Group | Winnti Group has registered domains for C2 that mimicked sites of their intended targets. |
| T1583.001 Domains |
GroupLazarus Group | Lazarus Group has acquired domains related to their campaigns to act as distribution points and C2 channels. |
| T1583.001 Domains |
GroupEarth Lusca | Earth Lusca has registered domains, intended to look like legitimate target domains, that have been used in watering hole attacks. |
| T1583.001 Domains |
GroupTransparent Tribe | Transparent Tribe has registered domains to mimic file sharing, government, defense, and research websites for use in targeted campaigns. |
| T1583.001 Domains |
GroupIndigoZebra | IndigoZebra has established domains, some of which were designed to look like official government domains, for their operations. |
| T1583.001 Domains |
GroupMoonstone Sleet | Moonstone Sleet registered domains to develop effective personas for fake companies used in phishing activity. |
| T1583.001 Domains |
GroupVOID MANTICORE | VOID MANTICORE has registered domains for messaging purposes. VOID MANTICORE has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion. VOID MANTICORE has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex. VOID MANTICORE has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations. |
| T1583.001 Domains |
GroupHEXANE | HEXANE has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization. |
| T1583.001 Domains |
GroupWIRTE | WIRTE has registered domains designed to mimic legitimate sites for use in phishing campaigns. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.