ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1594
Search Victim-Owned Websites
GroupKimsuky

Kimsuky has searched for information on the target company's website.

T1594
Search Victim-Owned Websites
GroupEXOTIC LILY

EXOTIC LILY has used contact forms on victim websites to generate phishing e-mails.

T1594
Search Victim-Owned Websites
GroupVolt Typhoon

Volt Typhoon has conducted pre-compromise reconnaissance on victim-owned sites.

T1594
Search Victim-Owned Websites
GroupSandworm Team

Sandworm Team has conducted research against potential victim websites as part of its operational planning.

T1594
Search Victim-Owned Websites
GroupSilent Librarian

Silent Librarian has searched victim's websites to identify the interests and academic areas of targeted individuals and to scrape source code, branding, and organizational contact information for phishing pages.

T1594
Search Victim-Owned Websites
GroupTA578

TA578 has filled out contact forms on victims' websites to direct them to adversary-controlled URLs.

T1595.001
Scanning IP Blocks
GroupTeamTNT

TeamTNT has scanned specific lists of target IP addresses.

T1595.001
Scanning IP Blocks
GroupEmber Bear

Ember Bear has targeted IP ranges for vulnerability scanning related to government and critical infrastructure organizations.

T1595.002
Vulnerability Scanning
GroupAPT41

APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications.

T1595.002
Vulnerability Scanning
GroupDragonfly

Dragonfly has scanned targeted systems for vulnerable Citrix and Microsoft Exchange services.

T1595.002
Vulnerability Scanning
GroupTeamTNT

TeamTNT has scanned for vulnerabilities in IoT devices and other related resources such as the Docker API.

T1595.002
Vulnerability Scanning
GroupSandworm Team

Sandworm Team has scanned network infrastructure for vulnerabilities as part of its operational planning.

T1595.002
Vulnerability Scanning
GroupAquatic Panda

Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228).

T1595.002
Vulnerability Scanning
GroupLeviathan

Leviathan has conducted reconnaissance against target networks of interest looking for vulnerable, end-of-life, or no longer maintainted devices against which to rapidly deploy exploits.

T1595.002
Vulnerability Scanning
GroupWinter Vivern

Winter Vivern has used remotely-hosted instances of the Acunetix vulnerability scanner.

T1595.002
Vulnerability Scanning
GroupAPT29

APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit.

T1595.002
Vulnerability Scanning
GroupEmber Bear

Ember Bear has used publicly available tools such as MASSCAN and Acunetix for vulnerability scanning of public-facing infrastructure.

T1595.002
Vulnerability Scanning
GroupVolatile Cedar

Volatile Cedar has performed vulnerability scans of the target server.

T1595.002
Vulnerability Scanning
GroupAPT28

APT28 has performed large-scale scans in an attempt to find vulnerable servers.

T1595.002
Vulnerability Scanning
GroupEarth Lusca

Earth Lusca has scanned for vulnerabilities in the public-facing servers of their targets.

T1595.002
Vulnerability Scanning
GroupVOID MANTICORE

VOID MANTICORE has scanned victim environments for susceptibility to vulnerability exploitation.

T1595.002
Vulnerability Scanning
GroupMagic Hound

Magic Hound has conducted widespread scanning to identify public-facing systems vulnerable to CVE-2021-44228 in Log4j and ProxyShell vulnerabilities; CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in on-premises MS Exchange Servers; and CVE-2018-13379 in Fortinet FortiOS SSL VPNs.

T1595.002
Vulnerability Scanning
GroupShinyHunters

ShinyHunters has searched through victim companies’ GitHub repositories for vulnerabilities.

T1595.003
Wordlist Scanning
GroupAPT41

APT41 leverages various tools and frameworks to brute-force directories on web servers.

T1595.003
Wordlist Scanning
GroupVolatile Cedar

Volatile Cedar has used DirBuster and GoBuster to brute force web directories and DNS subdomains.

T1596
Search Open Technical Databases
GroupKimsuky

Kimsuky has used LLMs to better understand publicly reported vulnerabilities.

T1596
Search Open Technical Databases
GroupAPT28

APT28 has used large language models (LLMs) to assist in script development and deployment.

T1596.005
Scan Databases
GroupVolt Typhoon

Volt Typhoon has used FOFA, Shodan, and Censys to search for exposed victim infrastructure.

T1596.005
Scan Databases
GroupAPT41

APT41 uses the Chinese website fofa.su, similar to the Shodan scanning service, for passive scanning of victims.

T1597
Search Closed Sources
GroupEXOTIC LILY

EXOTIC LILY has searched for information on targeted individuals on business databases including RocketReach and CrunchBase.

T1597.002
Purchase Technical Data
GroupLAPSUS$

LAPSUS$ has purchased credentials and session tokens from criminal underground forums.

T1598
Phishing for Information
GroupKimsuky

Kimsuky has used tailored spearphishing emails to gather victim information including contat lists to identify additional targets.

T1598
Phishing for Information
GroupZIRCONIUM

ZIRCONIUM targeted presidential campaign staffers with credential phishing e-mails.

T1598
Phishing for Information
GroupScattered Spider

Scattered Spider has used a combination of credential phishing and social engineering to capture one-time-password (OTP) codes.

T1598
Phishing for Information
GroupAPT28

APT28 has used spearphishing to compromise credentials.

T1598
Phishing for Information
GroupMoonstone Sleet

Moonstone Sleet has interacted with victims to gather information via email.

T1598
Phishing for Information
GroupShinyHunters

ShinyHunters has sent phishing emails to Microsoft Office 365 corporate users in order to steal credentials.

T1598.002
Spearphishing Attachment
GroupSideCopy

SideCopy has crafted generic lures for spam campaigns to collect emails and credentials for targeting efforts.

T1598.002
Spearphishing Attachment
GroupDragonfly

Dragonfly has used spearphishing with Microsoft Office attachments to enable harvesting of user credentials.

T1598.002
Spearphishing Attachment
GroupSidewinder

Sidewinder has sent e-mails with malicious attachments that lead victims to credential harvesting websites.

T1598.002
Spearphishing Attachment
GroupStar Blizzard

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential-stealing sites.

T1598.003
Spearphishing Link
GroupKimsuky

Kimsuky has used links in e-mail to steal account information including web beacons for target profiling. Kimsuky has also utilized QR codes (also known as Quishing) to direct victims to malicious links through the reliance of a mobile device to scan a code with an embedded malicious URL.

T1598.003
Spearphishing Link
GroupPatchwork

Patchwork has used embedded image tags (known as web bugs) with unique, per-recipient tracking links in their emails for the purpose of identifying which recipients opened messages.

T1598.003
Spearphishing Link
GroupDragonfly

Dragonfly has used spearphishing with PDF attachments containing malicious links that redirected to credential harvesting websites.

T1598.003
Spearphishing Link
GroupAPT32

APT32 has used malicious links to direct users to web pages designed to harvest credentials.

T1598.003
Spearphishing Link
GroupSandworm Team

Sandworm Team has crafted spearphishing emails with hyperlinks designed to trick unwitting recipients into revealing their account credentials.

T1598.003
Spearphishing Link
GroupCURIUM

CURIUM used malicious links to adversary-controlled resources for credential harvesting.

T1598.003
Spearphishing Link
GroupSidewinder

Sidewinder has sent e-mails with malicious links to credential harvesting websites.

T1598.003
Spearphishing Link
GroupMustang Panda

Mustang Panda has delivered web bugs to profile their intended targets.

T1598.003
Spearphishing Link
GroupZIRCONIUM

ZIRCONIUM has used web beacons in e-mails to track hits to attacker-controlled URL's.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.