ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1583.001
Domains
GroupMagic Hound

Magic Hound has registered fraudulent domains such as "mail-newyorker.com" and "news12.com.recover-session-service.site" to target specific victims with phishing attacks.

T1583.001
Domains
GroupThreat Group-3390

Threat Group-3390 has registered domains for C2.

T1583.001
Domains
GroupTeamPCP

TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data.

T1583.001
Domains
GroupShinyHunters

ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data. Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com.

T1583.002
DNS Server
GroupSea Turtle

Sea Turtle built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials.

T1583.002
DNS Server
GroupAxiom

Axiom has acquired dynamic DNS services for use in the targeting of intended victims.

T1583.002
DNS Server
GroupHEXANE

HEXANE has set up custom DNS servers to send commands to compromised hosts via TXT records.

T1583.003
Virtual Private Server
GroupBlackByte

BlackByte staged encryption keys on virtual private servers operated by the adversary.

T1583.003
Virtual Private Server
GroupDragonfly

Dragonfly has acquired VPS infrastructure for use in malicious campaigns.

T1583.003
Virtual Private Server
GroupHAFNIUM

HAFNIUM has operated from leased virtual private servers (VPS) in the United States.

T1583.003
Virtual Private Server
GroupGamaredon Group

Gamaredon Group has used VPS hosting providers for infrastructure outside of Russia.

T1583.003
Virtual Private Server
GroupCURIUM

CURIUM created virtual private server instances to facilitate use of malicious domains and other items.

T1583.003
Virtual Private Server
GroupContagious Interview

Contagious Interview has acquired virtual private servers from services such as Stark Industries Solutions and RouterHosting. Contagious Interview has also utilized hosting providers to include Tier[.]Net, Majestic Hosting, Leaseweb Singapore, and Kaopu Cloud.

T1583.003
Virtual Private Server
GroupSea Turtle

Sea Turtle created adversary-in-the-middle servers to impersonate legitimate services and enable credential capture.

T1583.003
Virtual Private Server
GroupWinter Vivern

Winter Vivern used adversary-owned and -controlled servers to host web vulnerability scanning applications.

T1583.003
Virtual Private Server
GroupAxiom

Axiom has used VPS hosting providers in targeting of intended victims.

T1583.003
Virtual Private Server
GroupEmber Bear

Ember Bear has used virtual private servers (VPSs) to host tools, perform reconnaissance, exploit victim infrastructure, and as a destination for data exfiltration.

T1583.003
Virtual Private Server
GroupAPT28

APT28 hosted phishing domains on free services for brief periods of time during campaigns.

T1583.003
Virtual Private Server
GroupAPT42

APT42 has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment.

T1583.003
Virtual Private Server
GroupAPT-C-36

APT-C-36 has incorporated virtual private servers (VPS) into its operational infrastructure.

T1583.003
Virtual Private Server
GroupLAPSUS$

LAPSUS$ has used VPS hosting providers for infrastructure.

T1583.003
Virtual Private Server
GroupMoonstone Sleet

Moonstone Sleet registered virtual private servers to host payloads for download.

T1583.003
Virtual Private Server
GroupVOID MANTICORE

VOID MANTICORE has utilized VPS solutions for C2.

T1583.004
Server
GroupGALLIUM

GALLIUM has used Taiwan-based servers that appear to be exclusive to GALLIUM.

T1583.004
Server
GroupMustard Tempest

Mustard Tempest has acquired servers to host second-stage payloads that remain active for a period of either days, weeks, or months.

T1583.004
Server
GroupKimsuky

Kimsuky has purchased hosting servers with virtual currency and prepaid cards.

T1583.004
Server
GroupSandworm Team

Sandworm Team has leased servers from resellers instead of leasing infrastructure directly from hosting companies to enable its operations.

T1583.004
Server
GroupCURIUM

CURIUM has created dedicated servers for command and control and exfiltration purposes.

T1583.004
Server
GroupEarth Lusca

Earth Lusca has acquired multiple servers for some of their operations, using each server for a different role.

T1583.004
Server
GroupVOID MANTICORE

VOID MANTICORE has leveraged backend servers within Iran.

T1583.004
Server
GroupTeamPCP

TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982.

T1583.004
Server
GroupShinyHunters

ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files.

T1583.005
Botnet
GroupHAFNIUM

HAFNIUM has incorporated leased devices into covert networks to obfuscate communications.

T1583.005
Botnet
GroupKe3chang

Ke3chang has utilized an ORB (operational relay box) network for reconnaissance and vulnerability exploitation.

T1583.005
Botnet
GroupAPT5

APT5 has acquired a network of compromised systems – specifically an ORB (operational relay box) network – for follow on activities.

T1583.006
Web Services
GroupAPT17

APT17 has created profile pages in Microsoft TechNet that were used as C2 infrastructure.

T1583.006
Web Services
GroupKimsuky

Kimsuky has hosted content used for targeting efforts via web services such as Blogspot. Kimsuky has also leveraged Dropbox for hosting payloads and uploading victim system information.

T1583.006
Web Services
GroupAPT32

APT32 has set up Dropbox, Amazon S3, and Google Drive to host malicious downloads.

T1583.006
Web Services
GroupHAFNIUM

HAFNIUM has acquired web services for use in C2 and exfiltration.

T1583.006
Web Services
GroupMuddyWater

MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools.

T1583.006
Web Services
GroupGamaredon Group

Gamaredon Group has used Cloudflare’s TryClouldflare service to obtain C2 nodes.

T1583.006
Web Services
GroupFIN7

FIN7 has set up Amazon S3 buckets to host trojanized digital products.

T1583.006
Web Services
GroupMustang Panda

Mustang Panda has set up Dropbox and Google Drive to host malicious downloads.

T1583.006
Web Services
GroupZIRCONIUM

ZIRCONIUM has used GitHub to host malware linked in spearphishing e-mails.

T1583.006
Web Services
GroupContagious Interview

Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities.

T1583.006
Web Services
GroupTA2541

TA2541 has hosted malicious files on various platforms including Google Drive, OneDrive, Discord, PasteText, ShareText, and GitHub.

T1583.006
Web Services
GroupPOLONIUM

POLONIUM has created and used legitimate Microsoft OneDrive accounts for their operations.

T1583.006
Web Services
GroupSaint Bear

Saint Bear has leveraged the Discord content delivery network to host malicious content for retrieval during initial access operations.

T1583.006
Web Services
GroupConfucius

Confucius has obtained cloud storage service accounts to host stolen data.

T1583.006
Web Services
GroupTurla

Turla has created web accounts including Dropbox and GitHub for C2 and document exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.