Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1585 Establish Accounts |
GroupFox Kitten | Fox Kitten has created KeyBase accounts to communicate with ransomware victims. |
| T1585.001 Social Media Accounts |
GroupKimsuky | Kimsuky has created social media accounts to monitor news and security trends as well as potential targets. |
| T1585.001 Social Media Accounts |
GroupEXOTIC LILY | EXOTIC LILY has established social media profiles to mimic employees of targeted companies. |
| T1585.001 Social Media Accounts |
GroupAPT32 | APT32 has set up Facebook pages in tandem with fake websites. |
| T1585.001 Social Media Accounts |
GroupSandworm Team | Sandworm Team has established social media accounts to disseminate victim internal-only documents and other sensitive data. |
| T1585.001 Social Media Accounts |
GroupCURIUM | CURIUM has established a network of fictitious social media accounts, including on Facebook and LinkedIn, to establish relationships with victims, often posing as an attractive woman. |
| T1585.001 Social Media Accounts |
GroupScattered Spider | Scattered Spider has created matching fake social media profiles to support new accounts created in victim environments. |
| T1585.001 Social Media Accounts |
GroupContagious Interview | Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts. ESET Contagious Interview BeaverTail InvisibleFerret February 2025PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1585.001 Social Media Accounts |
GroupLeviathan | Leviathan has created new social media accounts for targeting efforts. |
| T1585.001 Social Media Accounts |
GroupCleaver | Cleaver has created fake LinkedIn profiles that included profile photos, details, and connections. |
| T1585.001 Social Media Accounts |
GroupMedusa Group | Medusa Group has created social media accounts including Telegram and X to publicize their activities. |
| T1585.001 Social Media Accounts |
GroupStar Blizzard | Star Blizzard has established fraudulent profiles on professional networking sites to conduct reconnaissance. |
| T1585.001 Social Media Accounts |
GroupWater Galura | Water Galura operates a news channel on Telegram to make announcements for the Qilin RaaS. |
| T1585.001 Social Media Accounts |
GroupFox Kitten | Fox Kitten has used a Twitter account to communicate with ransomware victims. |
| T1585.001 Social Media Accounts |
GroupLazarus Group | Lazarus Group has created new Twitter accounts to conduct social engineering against potential victims. |
| T1585.001 Social Media Accounts |
GroupMoonstone Sleet | Moonstone Sleet has created social media accounts to interact with victims. |
| T1585.001 Social Media Accounts |
GroupVOID MANTICORE | VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures. |
| T1585.001 Social Media Accounts |
GroupHEXANE | HEXANE has established fraudulent LinkedIn accounts impersonating HR department employees to target potential victims with fake job offers. |
| T1585.001 Social Media Accounts |
GroupMagic Hound | Magic Hound has created fake LinkedIn and other social media accounts to contact targets and convince them--through messages and voice communications--to open malicious links. |
| T1585.001 Social Media Accounts |
GroupTeamPCP | TeamPCP has used its own Telegram channel and X accounts @pcpcats and @xploitrsturtle2 for external communications. |
| T1585.002 Email Accounts |
GroupIndrik Spider | Indrik Spider has created email accounts to communicate with their ransomware victims, to include providing payment and decryption details. |
| T1585.002 Email Accounts |
GroupKimsuky | Kimsuky has created email accounts for phishing operations. |
| T1585.002 Email Accounts |
GroupEXOTIC LILY | EXOTIC LILY has created e-mail accounts to spoof targeted organizations. |
| T1585.002 Email Accounts |
GroupSandworm Team | Sandworm Team has created email accounts that mimic legitimate organizations for its spearphishing operations. |
| T1585.002 Email Accounts |
GroupCURIUM | CURIUM has created dedicated email accounts for use with tools such as IMAPLoader. |
| T1585.002 Email Accounts |
GroupMustang Panda | Mustang Panda has leveraged the legitimate email marketing service SMTP2Go for phishing campaigns. Mustang Panda has also created fake Google accounts to distribute malware via spear-phishing emails. Mustang Panda has also created accounts for spearphishing operations including the use of services such as Proton Mail. |
| T1585.002 Email Accounts |
GroupContagious Interview | Contagious Interview has created fake email accounts to correspond with social media accounts, fake LinkedIn personas, code repository accounts, and job announcements on development job board services. Contagious Interview has also utilized fake email accounts with Threat Intelligence vendor services. ESET Contagious Interview BeaverTail InvisibleFerret February 2025PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Sentinel One Contagious Interview ClickFix September 2025Socket HexEval BeaverTail Contagious Interview June 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1585.002 Email Accounts |
GroupAPT1 | APT1 has created email accounts for later use in social engineering, phishing, and when registering domains. |
| T1585.002 Email Accounts |
GroupLeviathan | Leviathan has created new email accounts for targeting efforts. |
| T1585.002 Email Accounts |
GroupSilent Librarian | Silent Librarian has established e-mail accounts to receive e-mails forwarded from compromised accounts. |
| T1585.002 Email Accounts |
GroupMedusa Group | Medusa Group has created email accounts used in ransomware negotiations. |
| T1585.002 Email Accounts |
GroupStar Blizzard | Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target. |
| T1585.002 Email Accounts |
GroupAPT42 | APT42 has created email accounts to use in spearphishing operations. |
| T1585.002 Email Accounts |
GroupLazarus Group | Lazarus Group has created new email accounts for spearphishing operations. |
| T1585.002 Email Accounts |
GroupWizard Spider | Wizard Spider has leveraged ProtonMail email addresses in ransom notes when delivering Ryuk ransomware. |
| T1585.002 Email Accounts |
GroupMoonstone Sleet | Moonstone Sleet has created email accounts to interact with victims, including for phishing purposes. |
| T1585.002 Email Accounts |
GroupVOID MANTICORE | VOID MANTICORE has created email accounts to send threatening messages to victims to include ‘Handala_Team[@]outlook[.]com’. |
| T1585.002 Email Accounts |
GroupHEXANE | HEXANE has established email accounts for use in domain registration including for ProtonMail addresses. |
| T1585.002 Email Accounts |
GroupMagic Hound | Magic Hound has established email accounts using fake personas for spearphishing operations. |
| T1585.002 Email Accounts |
GroupShinyHunters | ShinyHunters has established multiple email accounts, such as shinycorp@tutonota[.]com, for use in extortion activities. |
| T1585.003 Cloud Accounts |
GroupStorm-1811 | Storm-1811 has created malicious accounts to enable activity via Microsoft Teams, typically spoofing various IT support and helpdesk themes. |
| T1586.001 Social Media Accounts |
GroupSandworm Team | Sandworm Team creates credential capture webpages to compromise existing, legitimate social media accounts. |
| T1586.001 Social Media Accounts |
GroupLeviathan | Leviathan has compromised social media accounts to conduct social engineering attacks. |
| T1586.002 Email Accounts |
GroupKimsuky | Kimsuky has compromised email accounts to send spearphishing e-mails. |
| T1586.002 Email Accounts |
GroupTA577 | TA577 has sent thread hijacked messages from compromised emails. |
| T1586.002 Email Accounts |
GroupMustang Panda | Mustang Panda has compromised legitimate email accounts to use in their spear-phishing operations. |
| T1586.002 Email Accounts |
GroupOilRig | OilRig has compromised email accounts to send phishing emails. |
| T1586.002 Email Accounts |
GroupLeviathan | Leviathan has compromised email accounts to conduct social engineering attacks. |
| T1586.002 Email Accounts |
GroupAPT29 | APT29 has compromised email accounts to further enable phishing campaigns and taken control of dormant accounts. |
| T1586.002 Email Accounts |
GroupStar Blizzard | Star Blizzard has used compromised email accounts to conduct spearphishing against |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.