ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1589.002
Email Addresses
GroupMagic Hound

Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting.

T1589.003
Employee Names
GroupKimsuky

Kimsuky has collected victim employee name information.

T1589.003
Employee Names
GroupSandworm Team

Sandworm Team's research of potential victim organizations included the identification and collection of employee information.

T1589.003
Employee Names
GroupSilent Librarian

Silent Librarian has collected lists of names for individuals from targeted organizations.

T1590
Gather Victim Network Information
GroupIndrik Spider

Indrik Spider has downloaded tools, such as the Advanced Port Scanner utility and Lansweeper, to conduct internal reconnaissance of the victim network. Indrik Spider has also accessed the victim’s VMware VCenter, which had information about host configuration, clusters, etc.

T1590
Gather Victim Network Information
GroupVolt Typhoon

Volt Typhoon has conducted extensive pre-compromise reconnaissance to learn about the target organization’s network.

T1590
Gather Victim Network Information
GroupHAFNIUM

HAFNIUM gathered the fully qualified domain names (FQDNs) for targeted Exchange servers in the victim's environment.

T1590.001
Domain Properties
GroupSandworm Team

Sandworm Team conducted technical reconnaissance of the Parliament of Georgia's official internet domain prior to its 2019 attack.

T1590.004
Network Topology
GroupVolt Typhoon

Volt Typhoon has conducted extensive reconnaissance of victim networks including identifying network topologies.

T1590.004
Network Topology
GroupSalt Typhoon

Salt Typhoon has used configuration files from exploited network devices to help discover upstream and downstream network segments.

T1590.004
Network Topology
GroupMuddyWater

MuddyWater has mapped target networks; access to this information and more is then shared/sold to other Iran threat actors.

T1590.004
Network Topology
GroupFIN13

FIN13 has searched for infrastructure that can provide remote access to an environment for targeting efforts.

T1590.005
IP Addresses
GroupHAFNIUM

HAFNIUM has obtained IP addresses for publicly-accessible Exchange servers.

T1590.005
IP Addresses
GroupAndariel

Andariel has limited its watering hole attacks to specific IP address ranges.

T1590.005
IP Addresses
GroupMagic Hound

Magic Hound has captured the IP addresses of visitors to their phishing sites.

T1590.006
Network Security Appliances
GroupVolt Typhoon

Volt Typhoon has identified target network security measures as part of pre-compromise reconnaissance.

T1591
Gather Victim Org Information
GroupKimsuky

Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others. Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest.

T1591
Gather Victim Org Information
GroupVolt Typhoon

Volt Typhoon has conducted extensive reconnaissance pre-compromise to gain information about the targeted organization.

T1591
Gather Victim Org Information
GroupFIN7

FIN7 has compiled a list of victims by filtering companies by revenue using Zoominfo, which is a service that provides business information.

T1591
Gather Victim Org Information
GroupMirrorFace

MirrorFace has placed specific content in phishing emails to target members of particular political parties.

T1591
Gather Victim Org Information
GroupAPT28

APT28 has used large language models (LLMs) to gather information about satellite capabilities.

T1591
Gather Victim Org Information
GroupLazarus Group

Lazarus Group has studied publicly available information about a targeted organization to tailor spearphishing efforts against specific departments and/or individuals.

T1591
Gather Victim Org Information
GroupMoonstone Sleet

Moonstone Sleet has gathered information on victim organizations through email and social media interaction.

T1591.001
Determine Physical Locations
GroupMagic Hound

Magic Hound has collected location information from visitors to their phishing sites.

T1591.002
Business Relationships
GroupDragonfly

Dragonfly has collected open source information to identify relationships between organizations for targeting purposes.

T1591.002
Business Relationships
GroupSandworm Team

In preparation for its attack against the 2018 Winter Olympics, Sandworm Team conducted online research of partner organizations listed on an official PyeongChang Olympics partnership site.

T1591.002
Business Relationships
GroupLAPSUS$

LAPSUS$ has gathered detailed knowledge of an organization's supply chain relationships.

T1591.004
Identify Roles
GroupVolt Typhoon

Volt Typhoon has identified key network and IT staff members pre-compromise at targeted organizations.

T1591.004
Identify Roles
GroupFIN7

FIN7 has identified IT staff and employees who had higher levels of administrative rights.

T1591.004
Identify Roles
GroupLAPSUS$

LAPSUS$ has gathered detailed knowledge of team structures within a target organization.

T1591.004
Identify Roles
GroupHEXANE

HEXANE has identified executives, HR, and IT staff at victim organizations for further targeting.

T1592
Gather Victim Host Information
GroupVolt Typhoon

Volt Typhoon has conducted pre-compromise reconnaissance for victim host information.

T1592.002
Software
GroupSandworm Team

Sandworm Team has researched software code to enable supply-chain operations, most notably for the 2017 NotPetya attack. Sandworm Team also collected a list of computers using specific software as part of its targeting efforts.

T1592.002
Software
GroupAndariel

Andariel has inserted a malicious script within compromised websites to collect potential victim information such as browser type, system language, Flash Player version, and other data.

T1592.002
Software
GroupMagic Hound

Magic Hound has captured the user-agent strings from visitors to their phishing sites.

T1592.004
Client Configurations
GroupHAFNIUM

HAFNIUM has interacted with Office 365 tenants to gather details regarding target's environments.

T1593
Search Open Websites/Domains
GroupVolt Typhoon

Volt Typhoon has conducted pre-compromise web searches for victim information.

T1593
Search Open Websites/Domains
GroupSandworm Team

Sandworm Team researched Ukraine's unique legal entity identifier (called an "EDRPOU" number), including running queries on the EDRPOU website, in preparation for the NotPetya attack. Sandworm Team has also researched third-party websites to help it craft credible spearphishing emails.

T1593
Search Open Websites/Domains
GroupMustang Panda

Mustang Panda has used open-source research to identify information about victims to use in targeting to include creating weaponized phishing lures and attachments.

T1593
Search Open Websites/Domains
GroupContagious Interview

Contagious Interview has utilized open-source indicator of compromise repositories to determine their exposure to include VirusTotal, and MalTrail.

T1593
Search Open Websites/Domains
GroupStar Blizzard

Star Blizzard has used open-source research to identify information about victims to use in targeting.

T1593
Search Open Websites/Domains
GroupAPT-C-36

APT-C-36 has gathered information on Colombian financial institutions, including Bancolombia, BBVA, Banco Caja Social, and Davivienda to craft phishing pages.

T1593.001
Social Media
GroupKimsuky

Kimsuky has used Twitter to monitor potential victims and to prepare targeted phishing e-mails.

T1593.001
Social Media
GroupEXOTIC LILY

EXOTIC LILY has copied data from social media sites to impersonate targeted individuals.

T1593.001
Social Media
GroupContagious Interview

Contagious Interview had identified and solicited victims through social media such as LinkedIn, X, and Telegram.

T1593.002
Search Engines
GroupKimsuky

Kimsuky has searched for vulnerabilities, tools, and geopolitical trends on Google to target victims.

T1593.003
Code Repositories
GroupHAFNIUM

HAFNIUM has discovered leaked corporate credentials on public repositories including GitHub.

T1593.003
Code Repositories
GroupContagious Interview

Contagious Interview had identified and solicited victims through code repositories such as GitHub.

T1593.003
Code Repositories
GroupLAPSUS$

LAPSUS$ has searched public code repositories for exposed credentials.

T1593.003
Code Repositories
GroupShinyHunters

ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.