Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1589.002 Email Addresses |
GroupMagic Hound | Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting. |
| T1589.003 Employee Names |
GroupKimsuky | Kimsuky has collected victim employee name information. |
| T1589.003 Employee Names |
GroupSandworm Team | Sandworm Team's research of potential victim organizations included the identification and collection of employee information. |
| T1589.003 Employee Names |
GroupSilent Librarian | Silent Librarian has collected lists of names for individuals from targeted organizations. |
| T1590 Gather Victim Network Information |
GroupIndrik Spider | Indrik Spider has downloaded tools, such as the Advanced Port Scanner utility and Lansweeper, to conduct internal reconnaissance of the victim network. Indrik Spider has also accessed the victim’s VMware VCenter, which had information about host configuration, clusters, etc. |
| T1590 Gather Victim Network Information |
GroupVolt Typhoon | Volt Typhoon has conducted extensive pre-compromise reconnaissance to learn about the target organization’s network. |
| T1590 Gather Victim Network Information |
GroupHAFNIUM | HAFNIUM gathered the fully qualified domain names (FQDNs) for targeted Exchange servers in the victim's environment. |
| T1590.001 Domain Properties |
GroupSandworm Team | Sandworm Team conducted technical reconnaissance of the Parliament of Georgia's official internet domain prior to its 2019 attack. |
| T1590.004 Network Topology |
GroupVolt Typhoon | Volt Typhoon has conducted extensive reconnaissance of victim networks including identifying network topologies. |
| T1590.004 Network Topology |
GroupSalt Typhoon | Salt Typhoon has used configuration files from exploited network devices to help discover upstream and downstream network segments. |
| T1590.004 Network Topology |
GroupMuddyWater | MuddyWater has mapped target networks; access to this information and more is then shared/sold to other Iran threat actors. |
| T1590.004 Network Topology |
GroupFIN13 | FIN13 has searched for infrastructure that can provide remote access to an environment for targeting efforts. |
| T1590.005 IP Addresses |
GroupHAFNIUM | HAFNIUM has obtained IP addresses for publicly-accessible Exchange servers. |
| T1590.005 IP Addresses |
GroupAndariel | Andariel has limited its watering hole attacks to specific IP address ranges. |
| T1590.005 IP Addresses |
GroupMagic Hound | Magic Hound has captured the IP addresses of visitors to their phishing sites. |
| T1590.006 Network Security Appliances |
GroupVolt Typhoon | Volt Typhoon has identified target network security measures as part of pre-compromise reconnaissance. |
| T1591 Gather Victim Org Information |
GroupKimsuky | Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others. Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest. |
| T1591 Gather Victim Org Information |
GroupVolt Typhoon | Volt Typhoon has conducted extensive reconnaissance pre-compromise to gain information about the targeted organization. |
| T1591 Gather Victim Org Information |
GroupFIN7 | FIN7 has compiled a list of victims by filtering companies by revenue using Zoominfo, which is a service that provides business information. |
| T1591 Gather Victim Org Information |
GroupMirrorFace | MirrorFace has placed specific content in phishing emails to target members of particular political parties. |
| T1591 Gather Victim Org Information |
GroupAPT28 | APT28 has used large language models (LLMs) to gather information about satellite capabilities. |
| T1591 Gather Victim Org Information |
GroupLazarus Group | Lazarus Group has studied publicly available information about a targeted organization to tailor spearphishing efforts against specific departments and/or individuals. |
| T1591 Gather Victim Org Information |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim organizations through email and social media interaction. |
| T1591.001 Determine Physical Locations |
GroupMagic Hound | Magic Hound has collected location information from visitors to their phishing sites. |
| T1591.002 Business Relationships |
GroupDragonfly | Dragonfly has collected open source information to identify relationships between organizations for targeting purposes. |
| T1591.002 Business Relationships |
GroupSandworm Team | In preparation for its attack against the 2018 Winter Olympics, Sandworm Team conducted online research of partner organizations listed on an official PyeongChang Olympics partnership site. |
| T1591.002 Business Relationships |
GroupLAPSUS$ | LAPSUS$ has gathered detailed knowledge of an organization's supply chain relationships. |
| T1591.004 Identify Roles |
GroupVolt Typhoon | Volt Typhoon has identified key network and IT staff members pre-compromise at targeted organizations. |
| T1591.004 Identify Roles |
GroupFIN7 | FIN7 has identified IT staff and employees who had higher levels of administrative rights. |
| T1591.004 Identify Roles |
GroupLAPSUS$ | LAPSUS$ has gathered detailed knowledge of team structures within a target organization. |
| T1591.004 Identify Roles |
GroupHEXANE | HEXANE has identified executives, HR, and IT staff at victim organizations for further targeting. |
| T1592 Gather Victim Host Information |
GroupVolt Typhoon | Volt Typhoon has conducted pre-compromise reconnaissance for victim host information. |
| T1592.002 Software |
GroupSandworm Team | Sandworm Team has researched software code to enable supply-chain operations, most notably for the 2017 NotPetya attack. Sandworm Team also collected a list of computers using specific software as part of its targeting efforts. |
| T1592.002 Software |
GroupAndariel | Andariel has inserted a malicious script within compromised websites to collect potential victim information such as browser type, system language, Flash Player version, and other data. |
| T1592.002 Software |
GroupMagic Hound | Magic Hound has captured the user-agent strings from visitors to their phishing sites. |
| T1592.004 Client Configurations |
GroupHAFNIUM | HAFNIUM has interacted with Office 365 tenants to gather details regarding target's environments. |
| T1593 Search Open Websites/Domains |
GroupVolt Typhoon | Volt Typhoon has conducted pre-compromise web searches for victim information. |
| T1593 Search Open Websites/Domains |
GroupSandworm Team | Sandworm Team researched Ukraine's unique legal entity identifier (called an "EDRPOU" number), including running queries on the EDRPOU website, in preparation for the NotPetya attack. Sandworm Team has also researched third-party websites to help it craft credible spearphishing emails. |
| T1593 Search Open Websites/Domains |
GroupMustang Panda | Mustang Panda has used open-source research to identify information about victims to use in targeting to include creating weaponized phishing lures and attachments. |
| T1593 Search Open Websites/Domains |
GroupContagious Interview | Contagious Interview has utilized open-source indicator of compromise repositories to determine their exposure to include VirusTotal, and MalTrail. |
| T1593 Search Open Websites/Domains |
GroupStar Blizzard | Star Blizzard has used open-source research to identify information about victims to use in targeting. |
| T1593 Search Open Websites/Domains |
GroupAPT-C-36 | APT-C-36 has gathered information on Colombian financial institutions, including Bancolombia, BBVA, Banco Caja Social, and Davivienda to craft phishing pages. |
| T1593.001 Social Media |
GroupKimsuky | Kimsuky has used Twitter to monitor potential victims and to prepare targeted phishing e-mails. |
| T1593.001 Social Media |
GroupEXOTIC LILY | EXOTIC LILY has copied data from social media sites to impersonate targeted individuals. |
| T1593.001 Social Media |
GroupContagious Interview | Contagious Interview had identified and solicited victims through social media such as LinkedIn, X, and Telegram. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Sekoia ClickFake 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1593.002 Search Engines |
GroupKimsuky | Kimsuky has searched for vulnerabilities, tools, and geopolitical trends on Google to target victims. |
| T1593.003 Code Repositories |
GroupHAFNIUM | HAFNIUM has discovered leaked corporate credentials on public repositories including GitHub. |
| T1593.003 Code Repositories |
GroupContagious Interview | Contagious Interview had identified and solicited victims through code repositories such as GitHub. |
| T1593.003 Code Repositories |
GroupLAPSUS$ | LAPSUS$ has searched public code repositories for exposed credentials. |
| T1593.003 Code Repositories |
GroupShinyHunters | ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.