Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1608.004 Drive-by Target |
GroupThreat Group-3390 | Threat Group-3390 has embedded malicious code into websites to screen a potential victim's IP address and then exploit their browser if they are of interest. |
| T1608.005 Link Target |
GroupFIN7 | FIN7 has created a fake link that redirected to an adversary-controlled Dropbox that downloaded the malicious executable. |
| T1608.005 Link Target |
GroupSilent Librarian | Silent Librarian has cloned victim organization login pages and staged them for later use in credential harvesting campaigns. Silent Librarian has also made use of a variety of URL shorteners for these staged websites. |
| T1608.005 Link Target |
GroupLuminousMoth | LuminousMoth has created a link to a Dropbox file that has been used in their spear-phishing operations. |
| T1608.006 SEO Poisoning |
GroupMustard Tempest | Mustard Tempest has poisoned search engine results to return fake software updates in order to distribute malware. |
| T1609 Container Administration Command |
GroupTeamTNT | TeamTNT executed Hildegard through the kubelet API run command and by executing commands on running containers. |
| T1610 Deploy Container |
GroupTeamTNT | TeamTNT has deployed different types of containers into victim environments to facilitate execution. TeamTNT has also transferred cryptocurrency mining software to Kubernetes clusters discovered within local IP address ranges. |
| T1611 Escape to Host |
GroupTeamTNT | TeamTNT has deployed privileged containers that mount the filesystem of victim machine. |
| T1613 Container and Resource Discovery |
GroupTeamTNT | TeamTNT has checked for running containers with |
| T1614 System Location Discovery |
GroupSideCopy | SideCopy has identified the country location of a compromised host. |
| T1614 System Location Discovery |
GroupVolt Typhoon | Volt Typhoon has obtained the victim's system current location. |
| T1614.001 System Language Discovery |
GroupBlackByte | BlackByte identified system language settings to determine follow-on execution. |
| T1614.001 System Language Discovery |
GroupKe3chang | Ke3chang has used implants to collect the system language ID of a compromised machine. |
| T1614.001 System Language Discovery |
GroupStorm-0501 | Storm-0501 has identified system language codes on a compromised host to determine if the victim falls under a non-supported language code that is prohibited for targeting, including victims associated with Russia and other Commonwealth of Independent States (CIS) that may draw attention of law enforcement in countries where the ransomware operator or affiliates may reside/operate from. |
| T1614.001 System Language Discovery |
GroupMirrorFace | MirrorFace has deployed shellcode to check for Japanese Microsoft Office settings. |
| T1614.001 System Language Discovery |
GroupMalteiro | Malteiro will terminate Mispadu's infection process if the language of the victim machine is not Spanish or Portuguese. |
| T1615 Group Policy Discovery |
GroupTurla | Turla surveys a system upon check-in to discover Group Policy details using the |
| T1619 Cloud Storage Object Discovery |
GroupShinyHunters | ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects. |
| T1620 Reflective Code Loading |
GroupKimsuky | Kimsuky has used the Invoke-Mimikatz PowerShell script to reflectively load a Mimikatz credential stealing DLL into memory. Kimsuky has also used reflective loading through .NET assembly using `[System.Reflection.Assembly]::Load`. |
| T1620 Reflective Code Loading |
GroupGamaredon Group | Gamaredon Group has used an obfuscated PowerShell script that used `System.Reflection.Assembly` to gather and send victim information to the C2. |
| T1620 Reflective Code Loading |
GroupFIN7 | FIN7 has loaded a .NET assembly into the currect execution context via `Reflection.Assembly::Load`. |
| T1620 Reflective Code Loading |
GroupLazarus Group | Lazarus Group has changed memory protection permissions then overwritten in memory DLL function code with shellcode, which was later executed via KernelCallbackTable hijacking. Lazarus Group has also used shellcode within macros to decrypt and manually map DLLs into memory at runtime. |
| T1621 Multi-Factor Authentication Request Generation |
GroupScattered Spider | Scattered Spider has used multifactor authentication (MFA) fatigue by sending repeated MFA authentication requests to targets. |
| T1621 Multi-Factor Authentication Request Generation |
GroupAPT29 | APT29 has used repeated MFA requests to gain access to victim accounts. |
| T1621 Multi-Factor Authentication Request Generation |
GroupLAPSUS$ | LAPSUS$ has spammed target users with MFA prompts in the hope that the legitimate user will grant necessary approval. |
| T1622 Debugger Evasion |
GroupMustang Panda | Mustang Panda has embedded debug strings with messages to distract analysts. Mustang Panda has also made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger. |
| T1649 Steal or Forge Authentication Certificates |
GroupAPT29 | APT29 has abused misconfigured AD CS certificate templates to impersonate admin users and create additional authentication certificates. |
| T1650 Acquire Access |
GroupMedusa Group | Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs). |
| T1651 Cloud Administration Command |
GroupAPT29 | APT29 has used Azure Run Command and Azure Admin-on-Behalf-of (AOBO) to execute code on virtual machines. |
| T1651 Cloud Administration Command |
GroupVOID MANTICORE | VOID MANTICORE has abused built-in remote wipe or factory reset commands to wipe devices managed within an organization’s Cloud management solution impacting laptops, servers, and mobile devices. |
| T1652 Device Driver Discovery |
GroupMedusa Group | Medusa Group has queried drivers on the victim device through the command `driverquery`. |
| T1654 Log Enumeration |
GroupVolt Typhoon | Volt Typhoon has used `wevtutil.exe` and the PowerShell command `Get-EventLog security` to enumerate Windows logs to search for successful logons. |
| T1654 Log Enumeration |
GroupMustang Panda | Mustang Panda has used Wevtutil to gather Windows Security Event Logs. |
| T1654 Log Enumeration |
GroupAquatic Panda | Aquatic Panda enumerated logs related to authentication in Linux environments prior to deleting selective entries for defense evasion purposes. |
| T1654 Log Enumeration |
GroupEmber Bear | Ember Bear has enumerated SECURITY and SYSTEM log files during intrusions. |
| T1654 Log Enumeration |
GroupAPT5 | APT5 has used the BLOODMINE utility to parse and extract information from Pulse Secure Connect logs. |
| T1657 Financial Theft |
GroupKimsuky | Kimsuky has stolen and laundered cryptocurrency to self-fund operations including the acquisition of infrastructure. |
| T1657 Financial Theft |
GroupAppleJeus | AppleJeus has targeted the cryptocurrency industry with the goal of stealing digital assets. |
| T1657 Financial Theft |
GroupScattered Spider | Scattered Spider has deployed ransomware on compromised hosts and threatened to leak stolen data for financial gain. |
| T1657 Financial Theft |
GroupContagious Interview | Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1657 Financial Theft |
GroupAkira | Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom. |
| T1657 Financial Theft |
GroupSilverTerrier | SilverTerrier targets organizations in high technology, higher education, and manufacturing for business email compromise (BEC) campaigns with the goal of financial theft. |
| T1657 Financial Theft |
GroupStorm-0501 | Storm-0501 has engaged in double-extortion ransomware, exfiltrating data and directly contacting victims when the primary organization refuses to pay along with posting data on their data leak sites. |
| T1657 Financial Theft |
GroupCinnamon Tempest | Cinnamon Tempest has maintained leak sites for exfiltrated data in attempt to extort victims into paying a ransom. |
| T1657 Financial Theft |
GroupMedusa Group | Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom. |
| T1657 Financial Theft |
GroupWater Galura | Water Galura has extorted victims for ransomware decryption keys and to prevent publication of data exfiltrated to their Tor data leak site. |
| T1657 Financial Theft |
GroupMalteiro | Malteiro targets organizations in a wide variety of sectors via the use of Mispadu banking trojan with the goal of financial theft. |
| T1657 Financial Theft |
GroupINC Ransom | INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it. |
| T1657 Financial Theft |
GroupVOID MANTICORE | VOID MANTICORE has conducted data exfiltration and posted stolen information on data leak sites for the purposes of financial and political extortion. VOID MANTICORE has also sold stolen data to prospective buyers for cryptocurrency. |
| T1657 Financial Theft |
GroupPlay | Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.