Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1598.003 Spearphishing Link |
GroupScattered Spider | Scattered Spider has used domains mirroring corporate login portals to socially engineer victims into providing credentials. |
| T1598.003 Spearphishing Link |
GroupSilent Librarian | Silent Librarian has used links in e-mails to direct victims to credential harvesting websites designed to appear like the targeted organization's login page. |
| T1598.003 Spearphishing Link |
GroupStar Blizzard | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites. |
| T1598.003 Spearphishing Link |
GroupAPT28 | APT28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites. |
| T1598.003 Spearphishing Link |
GroupMoonstone Sleet | Moonstone Sleet used spearphishing messages containing items such as tracking pixels to determine if users interacted with malicious messages. |
| T1598.003 Spearphishing Link |
GroupMagic Hound | Magic Hound has used SMS and email messages with links designed to steal credentials or track victims. |
| T1598.003 Spearphishing Link |
GroupShinyHunters | ShinyHunters has used spearphishing emails with malicious links to gain initial access and credentials. |
| T1598.004 Spearphishing Voice |
GroupScattered Spider | Scattered Spider has used help desk voice-based phishing and also called employees at target organizations and compelled them to navigate to fake login portals using adversary-in-the-middle toolkits. |
| T1598.004 Spearphishing Voice |
GroupLAPSUS$ | LAPSUS$ has called victims' help desk to convince the support personnel to reset a privileged account’s credentials. |
| T1599 Network Boundary Bridging |
GroupAPT41 | APT41 used `NATBypass` to bypass firewall restrictions and to access compromised systems via RDP. |
| T1602.002 Network Device Configuration Dump |
GroupSalt Typhoon | Salt Typhoon has attempted to acquire credentials by dumping network device configurations. |
| T1608 Stage Capabilities |
GroupMustang Panda | Mustang Panda has used servers under their control to validate tracking pixels sent to phishing victims. |
| T1608.001 Upload Malware |
GroupBlackByte | BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites. |
| T1608.001 Upload Malware |
GroupSideCopy | SideCopy has used compromised domains to host its malicious payloads. |
| T1608.001 Upload Malware |
GroupMustard Tempest | Mustard Tempest has hosted payloads on acquired second-stage servers for periods of either days, weeks, or months. |
| T1608.001 Upload Malware |
GroupKimsuky | Kimsuky has used compromised and acquired infrastructure to host and deliver malware including Blogspot to host beacons, file exfiltrators, and implants. Kimsuky has also hosted malicious payloads on Dropbox. |
| T1608.001 Upload Malware |
GroupEXOTIC LILY | EXOTIC LILY has uploaded malicious payloads to file-sharing services including TransferNow, TransferXL, WeTransfer, and OneDrive. |
| T1608.001 Upload Malware |
GroupAPT32 | APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting. |
| T1608.001 Upload Malware |
GroupGamaredon Group | Gamaredon Group has registered domains to stage payloads. |
| T1608.001 Upload Malware |
GroupTeamTNT | TeamTNT has uploaded backdoored Docker images to Docker Hub. |
| T1608.001 Upload Malware |
GroupFIN7 | FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3. FIN7 has also used an open directory web server as a staging server for payloads and other tools, such as OpenSSH and 7zip. |
| T1608.001 Upload Malware |
GroupSandworm Team | Sandworm Team staged compromised versions of legitimate software installers in forums to enable initial access to executing user. |
| T1608.001 Upload Malware |
GroupMustang Panda | Mustang Panda has hosted malicious payloads on DropBox including PlugX. |
| T1608.001 Upload Malware |
GroupContagious Interview | Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview October 2024Securonix Contagious Interview DEVPOPPER April 2024Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1608.001 Upload Malware |
GroupTA2541 | TA2541 has uploaded malware to various platforms including Google Drive, Pastetext, Sharetext, and GitHub. |
| T1608.001 Upload Malware |
GroupOilRig | OilRig has hosted malware on fake websites designed to target specific audiences. |
| T1608.001 Upload Malware |
GroupSaint Bear | Saint Bear has used the Discord content delivery network for hosting malicious content referenced in links and emails. |
| T1608.001 Upload Malware |
GroupTA505 | TA505 has staged malware on actor-controlled domains. |
| T1608.001 Upload Malware |
GroupBITTER | BITTER has registered domains to stage payloads. |
| T1608.001 Upload Malware |
GroupStar Blizzard | Star Blizzard has uploaded malicious payloads to cloud storage sites. |
| T1608.001 Upload Malware |
GroupLazyScripter | LazyScripter has hosted open-source remote access Trojans used in its operations in GitHub. |
| T1608.001 Upload Malware |
GroupLuminousMoth | LuminousMoth has hosted malicious payloads on Dropbox. |
| T1608.001 Upload Malware |
GroupAPT42 | APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application. |
| T1608.001 Upload Malware |
GroupAPT-C-36 | APT-C-36 has staged malware implants on group-owned repositories and sites. |
| T1608.001 Upload Malware |
GroupEarth Lusca | Earth Lusca has staged malware and malicious files on compromised web servers, GitHub, and Google Drive. |
| T1608.001 Upload Malware |
GroupMoonstone Sleet | Moonstone Sleet staged malicious capabilities online for follow-on download by victims or malware. |
| T1608.001 Upload Malware |
GroupHEXANE | HEXANE has staged malware on fraudulent websites set up to impersonate targeted organizations. |
| T1608.001 Upload Malware |
GroupWIRTE | WIRTE has directed victims to malicious payloads staged on file sharing services. |
| T1608.001 Upload Malware |
GroupThreat Group-3390 | Threat Group-3390 has hosted malicious payloads on Dropbox. |
| T1608.001 Upload Malware |
GroupTeamPCP | TeamPCP has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains. |
| T1608.002 Upload Tool |
GroupMedusa Group | Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise. |
| T1608.002 Upload Tool |
GroupThreat Group-3390 | Threat Group-3390 has staged tools, including gsecdump and WCE, on previously compromised websites. |
| T1608.003 Install Digital Certificate |
GroupSea Turtle | Sea Turtle captured legitimate SSL certificates from victim organizations and installed these on Sea Turtle-controlled infrastructure to enable subsequent adversary-in-the-middle operations. |
| T1608.004 Drive-by Target |
GroupMustard Tempest | Mustard Tempest has injected malicious JavaScript into compromised websites to infect victims via drive-by download. |
| T1608.004 Drive-by Target |
GroupDragonfly | Dragonfly has compromised websites to redirect traffic and to host exploit kits. |
| T1608.004 Drive-by Target |
GroupAPT32 | APT32 has stood up websites containing numerous articles and content scraped from the Internet to make them appear legitimate, but some of these pages include malicious JavaScript to profile the potential victim or infect them via a fake software update. |
| T1608.004 Drive-by Target |
GroupFIN7 | FIN7 has compromised a digital product website and modified multiple download links to point to trojanized versions of offered digital products. |
| T1608.004 Drive-by Target |
GroupCURIUM | CURIUM used strategic website compromise to fingerprint then target victims. |
| T1608.004 Drive-by Target |
GroupLuminousMoth | LuminousMoth has redirected compromised machines to an actor-controlled webpage through HTML injection. |
| T1608.004 Drive-by Target |
GroupTransparent Tribe | Transparent Tribe has set up websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.