Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.001 Domains |
GroupMagic Hound | Magic Hound has registered fraudulent domains such as "mail-newyorker.com" and "news12.com.recover-session-service.site" to target specific victims with phishing attacks. |
| T1583.001 Domains |
GroupThreat Group-3390 | Threat Group-3390 has registered domains for C2. |
| T1583.001 Domains |
GroupTeamPCP | TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data. |
| T1583.001 Domains |
GroupShinyHunters | ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data. Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com. |
| T1583.002 DNS Server |
GroupSea Turtle | Sea Turtle built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials. |
| T1583.002 DNS Server |
GroupAxiom | Axiom has acquired dynamic DNS services for use in the targeting of intended victims. |
| T1583.002 DNS Server |
GroupHEXANE | HEXANE has set up custom DNS servers to send commands to compromised hosts via TXT records. |
| T1583.003 Virtual Private Server |
GroupBlackByte | BlackByte staged encryption keys on virtual private servers operated by the adversary. |
| T1583.003 Virtual Private Server |
GroupDragonfly | Dragonfly has acquired VPS infrastructure for use in malicious campaigns. |
| T1583.003 Virtual Private Server |
GroupHAFNIUM | HAFNIUM has operated from leased virtual private servers (VPS) in the United States. |
| T1583.003 Virtual Private Server |
GroupGamaredon Group | Gamaredon Group has used VPS hosting providers for infrastructure outside of Russia. |
| T1583.003 Virtual Private Server |
GroupCURIUM | CURIUM created virtual private server instances to facilitate use of malicious domains and other items. |
| T1583.003 Virtual Private Server |
GroupContagious Interview | Contagious Interview has acquired virtual private servers from services such as Stark Industries Solutions and RouterHosting. Contagious Interview has also utilized hosting providers to include Tier[.]Net, Majestic Hosting, Leaseweb Singapore, and Kaopu Cloud. |
| T1583.003 Virtual Private Server |
GroupSea Turtle | Sea Turtle created adversary-in-the-middle servers to impersonate legitimate services and enable credential capture. |
| T1583.003 Virtual Private Server |
GroupWinter Vivern | Winter Vivern used adversary-owned and -controlled servers to host web vulnerability scanning applications. |
| T1583.003 Virtual Private Server |
GroupAxiom | Axiom has used VPS hosting providers in targeting of intended victims. |
| T1583.003 Virtual Private Server |
GroupEmber Bear | Ember Bear has used virtual private servers (VPSs) to host tools, perform reconnaissance, exploit victim infrastructure, and as a destination for data exfiltration. |
| T1583.003 Virtual Private Server |
GroupAPT28 | APT28 hosted phishing domains on free services for brief periods of time during campaigns. |
| T1583.003 Virtual Private Server |
GroupAPT42 | APT42 has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment. |
| T1583.003 Virtual Private Server |
GroupAPT-C-36 | APT-C-36 has incorporated virtual private servers (VPS) into its operational infrastructure. |
| T1583.003 Virtual Private Server |
GroupLAPSUS$ | LAPSUS$ has used VPS hosting providers for infrastructure. |
| T1583.003 Virtual Private Server |
GroupMoonstone Sleet | Moonstone Sleet registered virtual private servers to host payloads for download. |
| T1583.003 Virtual Private Server |
GroupVOID MANTICORE | VOID MANTICORE has utilized VPS solutions for C2. |
| T1583.004 Server |
GroupGALLIUM | GALLIUM has used Taiwan-based servers that appear to be exclusive to GALLIUM. |
| T1583.004 Server |
GroupMustard Tempest | Mustard Tempest has acquired servers to host second-stage payloads that remain active for a period of either days, weeks, or months. |
| T1583.004 Server |
GroupKimsuky | Kimsuky has purchased hosting servers with virtual currency and prepaid cards. |
| T1583.004 Server |
GroupSandworm Team | Sandworm Team has leased servers from resellers instead of leasing infrastructure directly from hosting companies to enable its operations. |
| T1583.004 Server |
GroupCURIUM | CURIUM has created dedicated servers for command and control and exfiltration purposes. |
| T1583.004 Server |
GroupEarth Lusca | Earth Lusca has acquired multiple servers for some of their operations, using each server for a different role. |
| T1583.004 Server |
GroupVOID MANTICORE | VOID MANTICORE has leveraged backend servers within Iran. |
| T1583.004 Server |
GroupTeamPCP | TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982. |
| T1583.004 Server |
GroupShinyHunters | ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files. |
| T1583.005 Botnet |
GroupHAFNIUM | HAFNIUM has incorporated leased devices into covert networks to obfuscate communications. |
| T1583.005 Botnet |
GroupKe3chang | Ke3chang has utilized an ORB (operational relay box) network for reconnaissance and vulnerability exploitation. |
| T1583.005 Botnet |
GroupAPT5 | APT5 has acquired a network of compromised systems – specifically an ORB (operational relay box) network – for follow on activities. |
| T1583.006 Web Services |
GroupAPT17 | APT17 has created profile pages in Microsoft TechNet that were used as C2 infrastructure. |
| T1583.006 Web Services |
GroupKimsuky | Kimsuky has hosted content used for targeting efforts via web services such as Blogspot. Kimsuky has also leveraged Dropbox for hosting payloads and uploading victim system information. |
| T1583.006 Web Services |
GroupAPT32 | APT32 has set up Dropbox, Amazon S3, and Google Drive to host malicious downloads. |
| T1583.006 Web Services |
GroupHAFNIUM | HAFNIUM has acquired web services for use in C2 and exfiltration. |
| T1583.006 Web Services |
GroupMuddyWater | MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools. |
| T1583.006 Web Services |
GroupGamaredon Group | Gamaredon Group has used Cloudflare’s TryClouldflare service to obtain C2 nodes. |
| T1583.006 Web Services |
GroupFIN7 | FIN7 has set up Amazon S3 buckets to host trojanized digital products. |
| T1583.006 Web Services |
GroupMustang Panda | Mustang Panda has set up Dropbox and Google Drive to host malicious downloads. |
| T1583.006 Web Services |
GroupZIRCONIUM | ZIRCONIUM has used GitHub to host malware linked in spearphishing e-mails. |
| T1583.006 Web Services |
GroupContagious Interview | Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities. Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Sekoia ClickFake 2025Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1583.006 Web Services |
GroupTA2541 | TA2541 has hosted malicious files on various platforms including Google Drive, OneDrive, Discord, PasteText, ShareText, and GitHub. |
| T1583.006 Web Services |
GroupPOLONIUM | POLONIUM has created and used legitimate Microsoft OneDrive accounts for their operations. |
| T1583.006 Web Services |
GroupSaint Bear | Saint Bear has leveraged the Discord content delivery network to host malicious content for retrieval during initial access operations. |
| T1583.006 Web Services |
GroupConfucius | Confucius has obtained cloud storage service accounts to host stolen data. |
| T1583.006 Web Services |
GroupTurla | Turla has created web accounts including Dropbox and GitHub for C2 and document exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.