ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1598.003
Spearphishing Link
GroupScattered Spider

Scattered Spider has used domains mirroring corporate login portals to socially engineer victims into providing credentials.

T1598.003
Spearphishing Link
GroupSilent Librarian

Silent Librarian has used links in e-mails to direct victims to credential harvesting websites designed to appear like the targeted organization's login page.

T1598.003
Spearphishing Link
GroupStar Blizzard

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites.

T1598.003
Spearphishing Link
GroupAPT28

APT28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites.

T1598.003
Spearphishing Link
GroupMoonstone Sleet

Moonstone Sleet used spearphishing messages containing items such as tracking pixels to determine if users interacted with malicious messages.

T1598.003
Spearphishing Link
GroupMagic Hound

Magic Hound has used SMS and email messages with links designed to steal credentials or track victims.

T1598.003
Spearphishing Link
GroupShinyHunters

ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials.

T1598.004
Spearphishing Voice
GroupScattered Spider

Scattered Spider has used help desk voice-based phishing and also called employees at target organizations and compelled them to navigate to fake login portals using adversary-in-the-middle toolkits.

T1598.004
Spearphishing Voice
GroupLAPSUS$

LAPSUS$ has called victims' help desk to convince the support personnel to reset a privileged account’s credentials.

T1599
Network Boundary Bridging
GroupAPT41

APT41 used `NATBypass` to bypass firewall restrictions and to access compromised systems via RDP.

T1602.002
Network Device Configuration Dump
GroupSalt Typhoon

Salt Typhoon has attempted to acquire credentials by dumping network device configurations.

T1608
Stage Capabilities
GroupMustang Panda

Mustang Panda has used servers under their control to validate tracking pixels sent to phishing victims.

T1608.001
Upload Malware
GroupBlackByte

BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites.

T1608.001
Upload Malware
GroupSideCopy

SideCopy has used compromised domains to host its malicious payloads.

T1608.001
Upload Malware
GroupMustard Tempest

Mustard Tempest has hosted payloads on acquired second-stage servers for periods of either days, weeks, or months.

T1608.001
Upload Malware
GroupKimsuky

Kimsuky has used compromised and acquired infrastructure to host and deliver malware including Blogspot to host beacons, file exfiltrators, and implants. Kimsuky has also hosted malicious payloads on Dropbox.

T1608.001
Upload Malware
GroupEXOTIC LILY

EXOTIC LILY has uploaded malicious payloads to file-sharing services including TransferNow, TransferXL, WeTransfer, and OneDrive.

T1608.001
Upload Malware
GroupAPT32

APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting.

T1608.001
Upload Malware
GroupGamaredon Group

Gamaredon Group has registered domains to stage payloads.

T1608.001
Upload Malware
GroupTeamTNT

TeamTNT has uploaded backdoored Docker images to Docker Hub.

T1608.001
Upload Malware
GroupFIN7

FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3. FIN7 has also used an open directory web server as a staging server for payloads and other tools, such as OpenSSH and 7zip.

T1608.001
Upload Malware
GroupSandworm Team

Sandworm Team staged compromised versions of legitimate software installers in forums to enable initial access to executing user.

T1608.001
Upload Malware
GroupMustang Panda

Mustang Panda has hosted malicious payloads on DropBox including PlugX.

T1608.001
Upload Malware
GroupContagious Interview

Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download.

T1608.001
Upload Malware
GroupTA2541

TA2541 has uploaded malware to various platforms including Google Drive, Pastetext, Sharetext, and GitHub.

T1608.001
Upload Malware
GroupOilRig

OilRig has hosted malware on fake websites designed to target specific audiences.

T1608.001
Upload Malware
GroupSaint Bear

Saint Bear has used the Discord content delivery network for hosting malicious content referenced in links and emails.

T1608.001
Upload Malware
GroupTA505

TA505 has staged malware on actor-controlled domains.

T1608.001
Upload Malware
GroupBITTER

BITTER has registered domains to stage payloads.

T1608.001
Upload Malware
GroupStar Blizzard

Star Blizzard has uploaded malicious payloads to cloud storage sites.

T1608.001
Upload Malware
GroupLazyScripter

LazyScripter has hosted open-source remote access Trojans used in its operations in GitHub.

T1608.001
Upload Malware
GroupLuminousMoth

LuminousMoth has hosted malicious payloads on Dropbox.

T1608.001
Upload Malware
GroupAPT42

APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application.

T1608.001
Upload Malware
GroupAPT-C-36

APT-C-36 has staged malware implants on group-owned repositories and sites.

T1608.001
Upload Malware
GroupEarth Lusca

Earth Lusca has staged malware and malicious files on compromised web servers, GitHub, and Google Drive.

T1608.001
Upload Malware
GroupMoonstone Sleet

Moonstone Sleet staged malicious capabilities online for follow-on download by victims or malware.

T1608.001
Upload Malware
GroupHEXANE

HEXANE has staged malware on fraudulent websites set up to impersonate targeted organizations.

T1608.001
Upload Malware
GroupWIRTE

WIRTE has directed victims to malicious payloads staged on file sharing services.

T1608.001
Upload Malware
GroupThreat Group-3390

Threat Group-3390 has hosted malicious payloads on Dropbox.

T1608.001
Upload Malware
GroupTeamPCP

TeamPCP has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains.

T1608.002
Upload Tool
GroupMedusa Group

Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise.

T1608.002
Upload Tool
GroupThreat Group-3390

Threat Group-3390 has staged tools, including gsecdump and WCE, on previously compromised websites.

T1608.003
Install Digital Certificate
GroupSea Turtle

Sea Turtle captured legitimate SSL certificates from victim organizations and installed these on Sea Turtle-controlled infrastructure to enable subsequent adversary-in-the-middle operations.

T1608.004
Drive-by Target
GroupMustard Tempest

Mustard Tempest has injected malicious JavaScript into compromised websites to infect victims via drive-by download.

T1608.004
Drive-by Target
GroupDragonfly

Dragonfly has compromised websites to redirect traffic and to host exploit kits.

T1608.004
Drive-by Target
GroupAPT32

APT32 has stood up websites containing numerous articles and content scraped from the Internet to make them appear legitimate, but some of these pages include malicious JavaScript to profile the potential victim or infect them via a fake software update.

T1608.004
Drive-by Target
GroupFIN7

FIN7 has compromised a digital product website and modified multiple download links to point to trojanized versions of offered digital products.

T1608.004
Drive-by Target
GroupCURIUM

CURIUM used strategic website compromise to fingerprint then target victims.

T1608.004
Drive-by Target
GroupLuminousMoth

LuminousMoth has redirected compromised machines to an actor-controlled webpage through HTML injection.

T1608.004
Drive-by Target
GroupTransparent Tribe

Transparent Tribe has set up websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.