Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1588.003 Code Signing Certificates |
GroupMustang Panda | Mustang Panda has used revoked code signing certificates for its malicious payloads. |
| T1588.003 Code Signing Certificates |
GroupOilRig | OilRig has obtained stolen code signing certificates to digitally sign malware. |
| T1588.003 Code Signing Certificates |
GroupBlackTech | BlackTech has used stolen code-signing certificates for its malicious payloads. |
| T1588.003 Code Signing Certificates |
GroupWizard Spider | Wizard Spider has obtained code signing certificates signed by DigiCert, GlobalSign, and COMOOD for malware payloads. |
| T1588.003 Code Signing Certificates |
GroupThreat Group-3390 | Threat Group-3390 has obtained stolen valid certificates, including from VMProtect and the Chinese instant messaging application Youdu, for their operations. |
| T1588.003 Code Signing Certificates |
GroupFIN8 | FIN8 has used an expired open-source X.509 certificate for testing in the OpenSSL repository, to connect to actor-controlled C2 servers. |
| T1588.004 Digital Certificates |
GroupMustang Panda | Mustang Panda has obtained SSL certificates for their C2 domains. |
| T1588.004 Digital Certificates |
GroupUNC3886 | UNC3886 has deployed malware using the victim's legitimate TLS certificate obtained from a compromised FortiGate device. |
| T1588.004 Digital Certificates |
GroupSea Turtle | Sea Turtle created new certificates using a technique called the actors performed "certificate impersonation," a technique in which Sea Turtle obtained a certificate authority-signed X.509 certificate from another provider for the same domain imitating the one already used by the targeted organization. |
| T1588.004 Digital Certificates |
GroupBlackTech | BlackTech has used valid, stolen digital certificates for some of their malware and tools. |
| T1588.004 Digital Certificates |
GroupSilent Librarian | Silent Librarian has obtained free Let's Encrypt SSL certificates for use on their phishing pages. |
| T1588.004 Digital Certificates |
GroupLuminousMoth | LuminousMoth has used a valid digital certificate for some of their malware. |
| T1588.004 Digital Certificates |
GroupLazarus Group | Lazarus Group has obtained SSL certificates for their C2 domains. |
| T1588.005 Exploits |
GroupKimsuky | Kimsuky has obtained exploit code for various CVEs. |
| T1588.005 Exploits |
GroupEmber Bear | Ember Bear has obtained exploitation scripts against publicly-disclosed vulnerabilities from public repositories. |
| T1588.006 Vulnerabilities |
GroupVolt Typhoon | Volt Typhoon has used publicly available exploit code for initial access. |
| T1588.006 Vulnerabilities |
GroupSandworm Team | In 2017, Sandworm Team conducted technical research related to vulnerabilities associated with websites used by the Korean Sport and Olympic Committee, a Korean power company, and a Korean airport. |
| T1588.006 Vulnerabilities |
GroupStorm-0501 | Storm-0501 has obtained capabilities to exploit N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203). |
| T1588.007 Artificial Intelligence |
GroupContagious Interview | Contagious Interview has appeared to have used AI to generate images and content to facilitate their campaigns. |
| T1588.007 Artificial Intelligence |
GroupAPT28 | APT28 has deployed LAMEHUG which can can query an LLM to generate and return commands for post compromise activity on targeted systems. |
| T1588.007 Artificial Intelligence |
GroupShinyHunters | ShinyHunters has used Bland AI to create conversational pathways tailored to specific scenarios during voice phishing attacks. |
| T1589 Gather Victim Identity Information |
GroupVolt Typhoon | Volt Typhoon has gathered victim identify information during pre-compromise reconnaissance. |
| T1589 Gather Victim Identity Information |
GroupAPT32 | APT32 has conducted targeted surveillance against activists and bloggers. |
| T1589 Gather Victim Identity Information |
GroupScattered Spider | Scattered Spider has used information from previous data breaches to identify employee names to be used in social engineering. |
| T1589 Gather Victim Identity Information |
GroupContagious Interview | Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Securonix Contagious Interview DEVPOPPER April 2024Sekoia ClickFake 2025Sentinel One Contagious Interview ClickFix September 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1589 Gather Victim Identity Information |
GroupStar Blizzard | Star Blizzard has identified ways to engage targets by researching potential victims' interests and social or professional contacts. |
| T1589 Gather Victim Identity Information |
GroupLAPSUS$ | LAPSUS$ has gathered detailed information of target employees to enhance their social engineering lures. |
| T1589 Gather Victim Identity Information |
GroupVOID MANTICORE | VOID MANTICORE has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks. |
| T1589 Gather Victim Identity Information |
GroupHEXANE | HEXANE has identified specific potential victims at targeted organizations. |
| T1589 Gather Victim Identity Information |
GroupMagic Hound | Magic Hound has acquired mobile phone numbers of potential targets, possibly for mobile malware or additional phishing operations. |
| T1589 Gather Victim Identity Information |
GroupFIN13 | FIN13 has researched employees to target for social engineering attacks. |
| T1589.001 Credentials |
GroupLeviathan | Leviathan has collected compromised credentials to use for targeting efforts. |
| T1589.001 Credentials |
GroupChimera | Chimera has collected credentials for the target organization from previous breaches for use in brute force attacks. |
| T1589.001 Credentials |
GroupAPT28 | APT28 has harvested user's login credentials. |
| T1589.001 Credentials |
GroupLAPSUS$ | LAPSUS$ has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials. |
| T1589.001 Credentials |
GroupMagic Hound | Magic Hound gathered credentials from two victims that they then attempted to validate across 75 different websites. Magic Hound has also collected credentials from over 900 Fortinet VPN servers in the US, Europe, and Israel. |
| T1589.001 Credentials |
GroupShinyHunters | ShinyHunters has collected credentials containing PII, ultimately selling the information on their DLS. |
| T1589.002 Email Addresses |
GroupKimsuky | Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering. |
| T1589.002 Email Addresses |
GroupEXOTIC LILY | EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms. |
| T1589.002 Email Addresses |
GroupVolt Typhoon | Volt Typhoon has targeted the personal emails of key network and IT staff at victim organizations. |
| T1589.002 Email Addresses |
GroupAPT32 | APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware. |
| T1589.002 Email Addresses |
GroupHAFNIUM | HAFNIUM has collected e-mail addresses for users they intended to target. |
| T1589.002 Email Addresses |
GroupSandworm Team | Sandworm Team has obtained valid emails addresses while conducting research against target organizations that were subsequently used in spearphishing campaigns. |
| T1589.002 Email Addresses |
GroupSaint Bear | Saint Bear gathered victim email information in advance of phishing operations for targeted attacks. |
| T1589.002 Email Addresses |
GroupSilent Librarian | Silent Librarian has collected e-mail addresses from targeted organizations from open Internet searches. |
| T1589.002 Email Addresses |
GroupTA551 | TA551 has used spoofed company emails that were acquired from email clients on previously infected hosts to target other individuals. |
| T1589.002 Email Addresses |
GroupLazarus Group | Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns. |
| T1589.002 Email Addresses |
GroupLAPSUS$ | LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts. |
| T1589.002 Email Addresses |
GroupMoonstone Sleet | Moonstone Sleet gathered victim email address information for follow-on phishing activity. |
| T1589.002 Email Addresses |
GroupHEXANE | HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.