Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.006 Web Services |
GroupAPT29 | APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations. |
| T1583.006 Web Services |
GroupMedusa Group | Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions. |
| T1583.006 Web Services |
GroupTA578 | TA578 has used Google Firebase to host malicious scripts. |
| T1583.006 Web Services |
GroupLazyScripter | LazyScripter has established GitHub accounts to host its toolsets. |
| T1583.006 Web Services |
GroupAPT28 | APT28 has used newly-created Blogspot pages for credential harvesting operations. |
| T1583.006 Web Services |
GroupAPT-C-36 | APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox. |
| T1583.006 Web Services |
GroupLazarus Group | Lazarus Group has hosted malicious downloads on Github. |
| T1583.006 Web Services |
GroupEarth Lusca | Earth Lusca has established GitHub accounts to host their malware. |
| T1583.006 Web Services |
GroupIndigoZebra | IndigoZebra created Dropbox accounts for their operations. |
| T1583.006 Web Services |
GroupVOID MANTICORE | VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure. |
| T1583.006 Web Services |
GroupMagic Hound | Magic Hound has acquired Amazon S3 buckets to use in C2. |
| T1583.006 Web Services |
GroupTeamPCP | TeamPCP has set up Clouflare Tunnels for malware C2. TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via *.getsession[.]org to recipient ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`. |
| T1583.008 Malvertising |
GroupMustard Tempest | Mustard Tempest has posted false advertisements including for software packages and browser updates in order to distribute malware. |
| T1584.001 Domains |
GroupSideCopy | SideCopy has compromised domains for some of their infrastructure, including for C2 and staging malware. |
| T1584.001 Domains |
GroupMustard Tempest | Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page. |
| T1584.001 Domains |
GroupKimsuky | Kimsuky has compromised legitimate sites and used them to distribute malware. |
| T1584.001 Domains |
GroupAPT1 | APT1 hijacked FQDNs associated with legitimate websites hosted by hop points. |
| T1584.001 Domains |
GroupTransparent Tribe | Transparent Tribe has compromised domains for use in targeted malicious campaigns. |
| T1584.001 Domains |
GroupMagic Hound | Magic Hound has used compromised domains to host links targeted to specific phishing victims. |
| T1584.002 DNS Server |
GroupSea Turtle | Sea Turtle modified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers to provide responses for all DNS lookups. |
| T1584.002 DNS Server |
GroupLAPSUS$ | LAPSUS$ has reconfigured a victim's DNS records to actor-controlled domains and websites. |
| T1584.003 Virtual Private Server |
GroupVolt Typhoon | Volt Typhoon has compromised Virtual Private Servers (VPS) to proxy C2 traffic. |
| T1584.003 Virtual Private Server |
GroupTurla | Turla has used the VPS infrastructure of compromised Iranian threat actors. |
| T1584.004 Server |
GroupIndrik Spider | Indrik Spider has served fake updates via legitimate websites that have been compromised. |
| T1584.004 Server |
GroupVolt Typhoon | Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2. |
| T1584.004 Server |
GroupDragonfly | Dragonfly has compromised legitimate websites to host C2 and malware modules. |
| T1584.004 Server |
GroupSandworm Team | Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns. |
| T1584.004 Server |
GroupLeviathan | Leviathan has used compromised legitimate websites as command and control nodes for operations. |
| T1584.004 Server |
GroupTurla | Turla has used compromised servers as infrastructure. |
| T1584.004 Server |
GroupLazarus Group | Lazarus Group has compromised servers to stage malicious tools. |
| T1584.004 Server |
GroupEarth Lusca | Earth Lusca has used compromised web servers as part of their operational infrastructure. |
| T1584.004 Server |
GroupAPT16 | APT16 has compromised otherwise legitimate sites as staging servers for second-stage payloads. |
| T1584.004 Server |
GroupDaggerfly | Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion. |
| T1584.005 Botnet |
GroupVolt Typhoon | Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations. |
| T1584.005 Botnet |
GroupHAFNIUM | HAFNIUM has used compromised devices in covert networks to obfuscate communications. |
| T1584.005 Botnet |
GroupSandworm Team | Sandworm Team has used a large-scale botnet to target Small Office/Home Office (SOHO) network devices. |
| T1584.005 Botnet |
GroupAxiom | Axiom has used large groups of compromised machines for use as proxy nodes. |
| T1584.005 Botnet |
GroupAPT-C-36 | APT-C-36 has used a botnet management interface to control large numbers of compromised hosts. |
| T1584.006 Web Services |
GroupCURIUM | CURIUM has compromised legitimate websites to enable strategic website compromise attacks. |
| T1584.006 Web Services |
GroupWinter Vivern | Winter Vivern has used compromised WordPress sites to host malicious payloads for download. |
| T1584.006 Web Services |
GroupTurla | Turla has frequently used compromised WordPress sites for C2 infrastructure. |
| T1584.006 Web Services |
GroupEarth Lusca | Earth Lusca has compromised Google Drive repositories. |
| T1584.008 Network Devices |
GroupVolt Typhoon | Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic. |
| T1584.008 Network Devices |
GroupZIRCONIUM | ZIRCONIUM has compromised network devices such as small office and home office (SOHO) routers and IoT devices for ORB (operational relay box) Proxy networks. |
| T1584.008 Network Devices |
GroupLeviathan | Leviathan has used compromised networking devices, such as small office/home office (SOHO) devices, as operational command and control infrastructure. |
| T1584.008 Network Devices |
GroupAPT28 | APT28 compromised Ubiquiti network devices to act as collection devices for credentials compromised via phishing webpages. |
| T1585 Establish Accounts |
GroupAPT17 | APT17 has created and cultivated profile pages in Microsoft TechNet. To make profile pages appear more legitimate, APT17 has created biographical sections and posted in forum threads. |
| T1585 Establish Accounts |
GroupKimsuky | Kimsuky has leveraged stolen PII to create accounts. |
| T1585 Establish Accounts |
GroupContagious Interview | Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1585 Establish Accounts |
GroupEmber Bear | Ember Bear has created accounts on dark web forums to obtain various tools and malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.