ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1588.003
Code Signing Certificates
GroupMustang Panda

Mustang Panda has used revoked code signing certificates for its malicious payloads.

T1588.003
Code Signing Certificates
GroupOilRig

OilRig has obtained stolen code signing certificates to digitally sign malware.

T1588.003
Code Signing Certificates
GroupBlackTech

BlackTech has used stolen code-signing certificates for its malicious payloads.

T1588.003
Code Signing Certificates
GroupWizard Spider

Wizard Spider has obtained code signing certificates signed by DigiCert, GlobalSign, and COMOOD for malware payloads.

T1588.003
Code Signing Certificates
GroupThreat Group-3390

Threat Group-3390 has obtained stolen valid certificates, including from VMProtect and the Chinese instant messaging application Youdu, for their operations.

T1588.003
Code Signing Certificates
GroupFIN8

FIN8 has used an expired open-source X.509 certificate for testing in the OpenSSL repository, to connect to actor-controlled C2 servers.

T1588.004
Digital Certificates
GroupMustang Panda

Mustang Panda has obtained SSL certificates for their C2 domains.

T1588.004
Digital Certificates
GroupUNC3886

UNC3886 has deployed malware using the victim's legitimate TLS certificate obtained from a compromised FortiGate device.

T1588.004
Digital Certificates
GroupSea Turtle

Sea Turtle created new certificates using a technique called the actors performed "certificate impersonation," a technique in which Sea Turtle obtained a certificate authority-signed X.509 certificate from another provider for the same domain imitating the one already used by the targeted organization.

T1588.004
Digital Certificates
GroupBlackTech

BlackTech has used valid, stolen digital certificates for some of their malware and tools.

T1588.004
Digital Certificates
GroupSilent Librarian

Silent Librarian has obtained free Let's Encrypt SSL certificates for use on their phishing pages.

T1588.004
Digital Certificates
GroupLuminousMoth

LuminousMoth has used a valid digital certificate for some of their malware.

T1588.004
Digital Certificates
GroupLazarus Group

Lazarus Group has obtained SSL certificates for their C2 domains.

T1588.005
Exploits
GroupKimsuky

Kimsuky has obtained exploit code for various CVEs.

T1588.005
Exploits
GroupEmber Bear

Ember Bear has obtained exploitation scripts against publicly-disclosed vulnerabilities from public repositories.

T1588.006
Vulnerabilities
GroupVolt Typhoon

Volt Typhoon has used publicly available exploit code for initial access.

T1588.006
Vulnerabilities
GroupSandworm Team

In 2017, Sandworm Team conducted technical research related to vulnerabilities associated with websites used by the Korean Sport and Olympic Committee, a Korean power company, and a Korean airport.

T1588.006
Vulnerabilities
GroupStorm-0501

Storm-0501 has obtained capabilities to exploit N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203).

T1588.007
Artificial Intelligence
GroupContagious Interview

Contagious Interview has appeared to have used AI to generate images and content to facilitate their campaigns.

T1588.007
Artificial Intelligence
GroupAPT28

APT28 has deployed LAMEHUG which can can query an LLM to generate and return commands for post compromise activity on targeted systems.

T1588.007
Artificial Intelligence
GroupShinyHunters

ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks.

T1589
Gather Victim Identity Information
GroupVolt Typhoon

Volt Typhoon has gathered victim identify information during pre-compromise reconnaissance.

T1589
Gather Victim Identity Information
GroupAPT32

APT32 has conducted targeted surveillance against activists and bloggers.

T1589
Gather Victim Identity Information
GroupScattered Spider

Scattered Spider has used information from previous data breaches to identify employee names to be used in social engineering.

T1589
Gather Victim Identity Information
GroupContagious Interview

Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies.

T1589
Gather Victim Identity Information
GroupStar Blizzard

Star Blizzard has identified ways to engage targets by researching potential victims' interests and social or professional contacts.

T1589
Gather Victim Identity Information
GroupLAPSUS$

LAPSUS$ has gathered detailed information of target employees to enhance their social engineering lures.

T1589
Gather Victim Identity Information
GroupVOID MANTICORE

VOID MANTICORE has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks.

T1589
Gather Victim Identity Information
GroupHEXANE

HEXANE has identified specific potential victims at targeted organizations.

T1589
Gather Victim Identity Information
GroupMagic Hound

Magic Hound has acquired mobile phone numbers of potential targets, possibly for mobile malware or additional phishing operations.

T1589
Gather Victim Identity Information
GroupFIN13

FIN13 has researched employees to target for social engineering attacks.

T1589.001
Credentials
GroupLeviathan

Leviathan has collected compromised credentials to use for targeting efforts.

T1589.001
Credentials
GroupChimera

Chimera has collected credentials for the target organization from previous breaches for use in brute force attacks.

T1589.001
Credentials
GroupAPT28

APT28 has harvested user's login credentials.

T1589.001
Credentials
GroupLAPSUS$

LAPSUS$ has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials.

T1589.001
Credentials
GroupMagic Hound

Magic Hound gathered credentials from two victims that they then attempted to validate across 75 different websites. Magic Hound has also collected credentials from over 900 Fortinet VPN servers in the US, Europe, and Israel.

T1589.001
Credentials
GroupShinyHunters

ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS.

T1589.002
Email Addresses
GroupKimsuky

Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering.

T1589.002
Email Addresses
GroupEXOTIC LILY

EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms.

T1589.002
Email Addresses
GroupVolt Typhoon

Volt Typhoon has targeted the personal emails of key network and IT staff at victim organizations.

T1589.002
Email Addresses
GroupAPT32

APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware.

T1589.002
Email Addresses
GroupHAFNIUM

HAFNIUM has collected e-mail addresses for users they intended to target.

T1589.002
Email Addresses
GroupSandworm Team

Sandworm Team has obtained valid emails addresses while conducting research against target organizations that were subsequently used in spearphishing campaigns.

T1589.002
Email Addresses
GroupSaint Bear

Saint Bear gathered victim email information in advance of phishing operations for targeted attacks.

T1589.002
Email Addresses
GroupSilent Librarian

Silent Librarian has collected e-mail addresses from targeted organizations from open Internet searches.

T1589.002
Email Addresses
GroupTA551

TA551 has used spoofed company emails that were acquired from email clients on previously infected hosts to target other individuals.

T1589.002
Email Addresses
GroupLazarus Group

Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns.

T1589.002
Email Addresses
GroupLAPSUS$

LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts.

T1589.002
Email Addresses
GroupMoonstone Sleet

Moonstone Sleet gathered victim email address information for follow-on phishing activity.

T1589.002
Email Addresses
GroupHEXANE

HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.