ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1583.006
Web Services
GroupAPT29

APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations.

T1583.006
Web Services
GroupMedusa Group

Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions.

T1583.006
Web Services
GroupTA578

TA578 has used Google Firebase to host malicious scripts.

T1583.006
Web Services
GroupLazyScripter

LazyScripter has established GitHub accounts to host its toolsets.

T1583.006
Web Services
GroupAPT28

APT28 has used newly-created Blogspot pages for credential harvesting operations.

T1583.006
Web Services
GroupAPT-C-36

APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox.

T1583.006
Web Services
GroupLazarus Group

Lazarus Group has hosted malicious downloads on Github.

T1583.006
Web Services
GroupEarth Lusca

Earth Lusca has established GitHub accounts to host their malware.

T1583.006
Web Services
GroupIndigoZebra

IndigoZebra created Dropbox accounts for their operations.

T1583.006
Web Services
GroupVOID MANTICORE

VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure.

T1583.006
Web Services
GroupMagic Hound

Magic Hound has acquired Amazon S3 buckets to use in C2.

T1583.006
Web Services
GroupTeamPCP

TeamPCP has set up Clouflare Tunnels for malware C2. TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via  *.getsession[.]org to recipient  ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`.

T1583.008
Malvertising
GroupMustard Tempest

Mustard Tempest has posted false advertisements including for software packages and browser updates in order to distribute malware.

T1584.001
Domains
GroupSideCopy

SideCopy has compromised domains for some of their infrastructure, including for C2 and staging malware.

T1584.001
Domains
GroupMustard Tempest

Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page.

T1584.001
Domains
GroupKimsuky

Kimsuky has compromised legitimate sites and used them to distribute malware.

T1584.001
Domains
GroupAPT1

APT1 hijacked FQDNs associated with legitimate websites hosted by hop points.

T1584.001
Domains
GroupTransparent Tribe

Transparent Tribe has compromised domains for use in targeted malicious campaigns.

T1584.001
Domains
GroupMagic Hound

Magic Hound has used compromised domains to host links targeted to specific phishing victims.

T1584.002
DNS Server
GroupSea Turtle

Sea Turtle modified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers to provide responses for all DNS lookups.

T1584.002
DNS Server
GroupLAPSUS$

LAPSUS$ has reconfigured a victim's DNS records to actor-controlled domains and websites.

T1584.003
Virtual Private Server
GroupVolt Typhoon

Volt Typhoon has compromised Virtual Private Servers (VPS) to proxy C2 traffic.

T1584.003
Virtual Private Server
GroupTurla

Turla has used the VPS infrastructure of compromised Iranian threat actors.

T1584.004
Server
GroupIndrik Spider

Indrik Spider has served fake updates via legitimate websites that have been compromised.

T1584.004
Server
GroupVolt Typhoon

Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2.

T1584.004
Server
GroupDragonfly

Dragonfly has compromised legitimate websites to host C2 and malware modules.

T1584.004
Server
GroupSandworm Team

Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns.

T1584.004
Server
GroupLeviathan

Leviathan has used compromised legitimate websites as command and control nodes for operations.

T1584.004
Server
GroupTurla

Turla has used compromised servers as infrastructure.

T1584.004
Server
GroupLazarus Group

Lazarus Group has compromised servers to stage malicious tools.

T1584.004
Server
GroupEarth Lusca

Earth Lusca has used compromised web servers as part of their operational infrastructure.

T1584.004
Server
GroupAPT16

APT16 has compromised otherwise legitimate sites as staging servers for second-stage payloads.

T1584.004
Server
GroupDaggerfly

Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion.

T1584.005
Botnet
GroupVolt Typhoon

Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations.

T1584.005
Botnet
GroupHAFNIUM

HAFNIUM has used compromised devices in covert networks to obfuscate communications.

T1584.005
Botnet
GroupSandworm Team

Sandworm Team has used a large-scale botnet to target Small Office/Home Office (SOHO) network devices.

T1584.005
Botnet
GroupAxiom

Axiom has used large groups of compromised machines for use as proxy nodes.

T1584.005
Botnet
GroupAPT-C-36

APT-C-36 has used a botnet management interface to control large numbers of compromised hosts.

T1584.006
Web Services
GroupCURIUM

CURIUM has compromised legitimate websites to enable strategic website compromise attacks.

T1584.006
Web Services
GroupWinter Vivern

Winter Vivern has used compromised WordPress sites to host malicious payloads for download.

T1584.006
Web Services
GroupTurla

Turla has frequently used compromised WordPress sites for C2 infrastructure.

T1584.006
Web Services
GroupEarth Lusca

Earth Lusca has compromised Google Drive repositories.

T1584.008
Network Devices
GroupVolt Typhoon

Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic.

T1584.008
Network Devices
GroupZIRCONIUM

ZIRCONIUM has compromised network devices such as small office and home office (SOHO) routers and IoT devices for ORB (operational relay box) Proxy networks.

T1584.008
Network Devices
GroupLeviathan

Leviathan has used compromised networking devices, such as small office/home office (SOHO) devices, as operational command and control infrastructure.

T1584.008
Network Devices
GroupAPT28

APT28 compromised Ubiquiti network devices to act as collection devices for credentials compromised via phishing webpages.

T1585
Establish Accounts
GroupAPT17

APT17 has created and cultivated profile pages in Microsoft TechNet. To make profile pages appear more legitimate, APT17 has created biographical sections and posted in forum threads.

T1585
Establish Accounts
GroupKimsuky

Kimsuky has leveraged stolen PII to create accounts.

T1585
Establish Accounts
GroupContagious Interview

Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads.

T1585
Establish Accounts
GroupEmber Bear

Ember Bear has created accounts on dark web forums to obtain various tools and malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.