ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1586.002
Email Accounts
GroupAPT28

APT28 has used compromised email accounts to send credential phishing emails.

T1586.002
Email Accounts
GroupAPT-C-36

APT-C-36 has regularly used compromised email accounts in spearphishing campaigns.

T1586.002
Email Accounts
GroupLAPSUS$

LAPSUS$ has payed employees, suppliers, and business partners of target organizations for credentials.

T1586.002
Email Accounts
GroupIndigoZebra

IndigoZebra has compromised legitimate email accounts to use in their spearphishing operations.

T1586.002
Email Accounts
GroupHEXANE

HEXANE has used compromised accounts to send spearphishing emails.

T1586.002
Email Accounts
GroupWIRTE

WIRTE has used compromised emails, including one belonging to an Israel-based technology reseller, to deliver targeted spearphishing messages.

T1586.002
Email Accounts
GroupMagic Hound

Magic Hound has compromised personal email accounts through the use of legitimate credentials and gathered additional victim information.

T1586.003
Cloud Accounts
GroupAPT29

APT29 has used residential proxies, including Azure Virtual Machines, to obfuscate their access to victim environments.

T1586.003
Cloud Accounts
GroupAPT-C-36

APT-C-36 has used compromised Google Drive accounts including one associated with a Colombian government organization.

T1587
Develop Capabilities
GroupKimsuky

Kimsuky created and used a mailing toolkit to use in spearphishing attacks.

T1587
Develop Capabilities
GroupContagious Interview

Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims.

T1587
Develop Capabilities
GroupMoonstone Sleet

Moonstone Sleet developed malicious npm packages for delivery to or retrieval by victims.

T1587.001
Malware
GroupIndrik Spider

Indrik Spider has developed malware for their operations, including ransomware such as BitPaymer and WastedLocker.

T1587.001
Malware
GroupKimsuky

Kimsuky has developed its own unique malware such as MailFetch.py for use in operations.

T1587.001
Malware
GroupSalt Typhoon

Salt Typhoon has used custom tooling including JumbledPath.

T1587.001
Malware
GroupTeamTNT

TeamTNT has developed custom malware such as Hildegard.

T1587.001
Malware
GroupFIN7

FIN7 has developed malware for use in operations, including the creation of infected removable media.

T1587.001
Malware
GroupSandworm Team

Sandworm Team has developed malware for its operations, including malicious mobile applications and destructive malware such as NotPetya and Olympic Destroyer.

T1587.001
Malware
GroupMustang Panda

Mustang Panda has developed custom malware for use in their operations.

T1587.001
Malware
GroupUNC3886

UNC3886 has deployed custom malware families on Fortinet and VMware systems.

T1587.001
Malware
GroupContagious Interview

Contagious Interview has developed malware that utilizes Qt cross-platform framework to include BeaverTail.

T1587.001
Malware
GroupMoses Staff

Moses Staff has built malware, such as DCSrv and PyDCrypt, for targeting victims' machines.

T1587.001
Malware
GroupOilRig

OilRig actively developed and used a series of downloaders during 2022.

T1587.001
Malware
GroupAoqin Dragon

Aoqin Dragon has used custom malware, including Mongall and Heyoka Backdoor, in their operations.

T1587.001
Malware
GroupKe3chang

Ke3chang has developed custom malware that allowed them to maintain persistence on victim networks.

T1587.001
Malware
GroupTurla

Turla has developed its own unique malware for use in operations.

T1587.001
Malware
GroupRedCurl

RedCurl has created its own tools to use during operations.

T1587.001
Malware
GroupAPT29

APT29 has used unique malware in many of their operations.

T1587.001
Malware
GroupMirrorFace

MirrorFace has created and continued to develop custom strains of malware including LODEINFO.

T1587.001
Malware
GroupCleaver

Cleaver has created customized tools and payloads for functions including ARP poisoning, encryption, credential dumping, ASP.NET shells, web backdoors, process enumeration, WMI querying, HTTP and SMB communications, network interface sniffing, and keystroke logging.

T1587.001
Malware
GroupLuminousMoth

LuminousMoth has used unique malware for information theft and exfiltration.

T1587.001
Malware
GroupAPT-C-36

APT-C-36 has customized existing malware with new capabilities including njRAT, AsyncRAT, LimeRAT, and BitRAT.

T1587.001
Malware
GroupLazarus Group

Lazarus Group has developed custom malware for use in their operations.

T1587.001
Malware
GroupMoonstone Sleet

Moonstone Sleet has developed custom malware, including a malware delivery mechanism masquerading as a legitimate game.

T1587.001
Malware
GroupVOID MANTICORE

VOID MANTICORE has utilized custom-malware and wipers to include BiBi Wiper.

T1587.001
Malware
GroupPlay

Play developed and employ Playcrypt ransomware.

T1587.001
Malware
GroupFIN13

FIN13 has utilized custom malware to maintain persistence in a compromised environment.

T1587.001
Malware
GroupTeamPCP

TeamPCP has developed and deployed custom malware including TeamPCP Cloud Stealer, CanisterWorm, and Mini Shai-Hulud.

T1587.002
Code Signing Certificates
GroupPatchwork

Patchwork has created self-signed certificates from fictitious and spoofed legitimate software companies that were later used to sign malware.

T1587.002
Code Signing Certificates
GroupPROMETHIUM

PROMETHIUM has created self-signed certificates to sign malicious installers.

T1587.002
Code Signing Certificates
GroupDaggerfly

Daggerfly created code signing certificates to sign malicious macOS files.

T1587.003
Digital Certificates
GroupGamaredon Group

Gamaredon Group has used the same TLS certificate across its infrastructure.

T1587.003
Digital Certificates
GroupStorm-0501

Storm-0501 has utilized their own self-signed TLS certificate “Microsoft IT TLS CA 5” with their infrastructure.

T1587.003
Digital Certificates
GroupAPT29

APT29 has created self-signed digital certificates to enable mutual TLS authentication for malware.

T1587.003
Digital Certificates
GroupPROMETHIUM

PROMETHIUM has created self-signed digital certificates for use in HTTPS C2 traffic.

T1587.004
Exploits
GroupVolt Typhoon

Volt Typhoon has exploited zero-day vulnerabilities for initial access.

T1587.004
Exploits
GroupUNC3886

UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter.

T1587.004
Exploits
GroupLeviathan

Leviathan has rapidly transformed and adapted public exploit proof-of-concept code for new vulnerabilities and utilized them against target networks.

T1587.004
Exploits
GroupShinyHunters

ShinyHunters has exploited zero-day vulnerability CVE-2026-35273 against Oracle PeopleSoft application infrastructure.

T1588.001
Malware
GroupMuddyWater

MuddyWater has used publicly available malware for operations, likely to blend in with other cybercriminals.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.