Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1657 Financial Theft |
GroupFIN13 | FIN13 has observed the victim's software and infrastructure over several months to understand the technical process of legitimate financial transactions, prior to attempting to conduct fraudulent transactions. |
| T1657 Financial Theft |
GroupTeamPCP | TeamPCP has engaged in cryptocurrency mining and theft. TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware. |
| T1657 Financial Theft |
GroupShinyHunters | ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com. |
| T1659 Content Injection |
GroupMoustachedBouncer | MoustachedBouncer has injected content into DNS, HTTP, and SMB replies to redirect specifically-targeted victims to a fake Windows Update page to download malware. |
| T1665 Hide Infrastructure |
GroupZIRCONIUM | ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to obfuscate the origin of C2 traffic. |
| T1665 Hide Infrastructure |
GroupAPT29 | APT29 uses compromised residential endpoints, typically within the same ISP IP address range, as proxies to hide the true source of C2 traffic. |
| T1667 Email Bombing |
GroupStorm-1811 | Storm-1811 has deployed large volumes of non-malicious email spam to victims in order to prompt follow-on interactions with the threat actor posing as IT support or helpdesk to resolve the problem. |
| T1669 Wi-Fi Networks |
GroupAPT28 | APT28 has exploited open Wi-Fi access points for initial access to target devices using the network. |
| T1673 Virtual Machine Discovery |
GroupUNC3886 | UNC3886 has used scripts to enumerate ESXi hypervisors and their guest VMs. |
| T1674 Input Injection |
GroupFIN7 | FIN7 has used malicious USBs to emulate keystrokes to launch PowerShell to download and execute malware from the adversary's server. |
| T1675 ESXi Administration Command |
GroupUNC3886 | UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host. |
| T1677 Poisoned Pipeline Execution |
GroupTeamPCP | TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM. Aikido TeamPCP Telnyx MAR 2026Aqua Security Blog Trivy Compromise APR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Sysdig TeamPCP MAR 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1678 Delay Execution |
GroupKimsuky | Kimsuky has utilized the Sleep function to ensure execution of scripts. |
| T1678 Delay Execution |
GroupMustang Panda | Mustang Panda has delayed the execution of payloads leveraging ping echo requests `cmd /c ping 8.8.8.8 -n 70&&"%temp%\<legitimate executable>"`. |
| T1679 Selective Exclusion |
GroupVOID MANTICORE | VOID MANTICORE has avoided interacting with specific directories in order to reduce the likelihood of detection. |
| T1680 Local Storage Discovery |
GroupKimsuky | Kimsuky has enumerated drives. |
| T1680 Local Storage Discovery |
GroupVolt Typhoon | Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems. |
| T1680 Local Storage Discovery |
GroupPatchwork | Patchwork enumerated all available drives on the victim's machine. |
| T1680 Local Storage Discovery |
GroupTeamTNT | TeamTNT has searched for disk partition and logical volume information. |
| T1680 Local Storage Discovery |
GroupHigaisa | Higaisa collected the system volume serial number. |
| T1680 Local Storage Discovery |
GroupTropic Trooper | Tropic Trooper has detected a target system’s system volume information. |
| T1680 Local Storage Discovery |
GroupConfucius | Confucius has used a file stealer that can examine system drives, including those other than the C drive. |
| T1680 Local Storage Discovery |
GroupChimera | Chimera has used `fsutil fsinfo drives`, `systeminfo`, and `vssadmin list shadows` for system information including shadow volumes and drive information. |
| T1680 Local Storage Discovery |
GroupToddyCat | ToddyCat has collected information on bootable drives including model, vendor, and serial numbers. |
| T1680 Local Storage Discovery |
GroupLazarus Group | A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server. |
| T1681 Search Threat Vendor Data |
GroupUNC3886 | UNC3886 has replaced indicators mentioned in open-source threat intelligence publications at times under a week after their release. |
| T1681 Search Threat Vendor Data |
GroupContagious Interview | Contagious Interview has registered accounts with Threat Intelligence vendor services to check for reporting associated with their infrastructure and to evaluate new potential infrastructure. |
| T1682 Query Public AI Services |
GroupKimsuky | Kimsuky has used LLMs to identify think tanks, government organizations, and experts to inform targeting for spearphishing campaigns. |
| T1682 Query Public AI Services |
GroupAPT42 | APT42 has leveraged LLMs to search for official emails to build target lists, and conduct reconnaissance on potential business partners. |
| T1683.001 Written Content |
GroupContagious Interview | Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts. |
| T1683.001 Written Content |
GroupAPT-C-36 | APT-C-36 has generated email content impersonating official notifications and documents that direct victims to execute malicious payloads. |
| T1683.001 Written Content |
GroupTeamPCP | TeamPCP has created Dune-themed GitHub repositories using stolen tokens. |
| T1683.002 Audio-Visual Content |
GroupContagious Interview | Contagious Interview has used AI to clone video-conferencing applications to distribute their BeaverTail malware. They have also used AI to create deepfake videos. |
| T1683.002 Audio-Visual Content |
GroupAPT-C-36 | APT-C-36 has used phishing pages appearing like legitimate banking login portals to compromise credentials. |
| T1684 Social Engineering |
GroupShinyHunters | ShinyHunters has used social engineering to demand payment from victims. |
| T1684.001 Impersonation |
GroupKimsuky | Kimsuky has also impersonated legitimate people, such as a foreign advisor, an embassy employee, and a think tank employee. Kimsuky has also purported to be a Japanese diplomat to communicate with the victims. |
| T1684.001 Impersonation |
GroupAPT41 | APT41 impersonated an employee at a video game developer company to send phishing emails. |
| T1684.001 Impersonation |
GroupMuddyWater | MuddyWater has used support@microsoftonlines[.]com to send phishing emails that masqueraded as security updates from Microsoft. MuddyWater has also impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain info@tmcell. |
| T1684.001 Impersonation |
GroupStorm-1811 | Storm-1811 impersonates help desk and IT support personnel for phishing and social engineering purposes during initial access to victim environments. |
| T1684.001 Impersonation |
GroupScattered Spider | Scattered Spider utilized social engineering to compel IT help desk personnel to reset passwords and MFA tokens. Scattered Spider has also used Microsoft Teams to pose as internal IT support or help desk personnel. |
| T1684.001 Impersonation |
GroupContagious Interview | Contagious Interview had impersonated HR hiring personnel through social media, job board notifications, and conducted interviews with victims in order to entice them to download malware disguised as legitimate applications or malicious scripts from code repositories. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Securonix Contagious Interview DEVPOPPER April 2024Sentinel One Contagious Interview ClickFix September 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1684.001 Impersonation |
GroupSaint Bear | Saint Bear has impersonated government and related entities in both phishing activity and developing web sites with malicious links that mimic legitimate resources. |
| T1684.001 Impersonation |
GroupMirrorFace | MirrorFace has sent targeted emails purporting to be from a Japanese political party’s PR department. |
| T1684.001 Impersonation |
GroupStar Blizzard | Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target. |
| T1684.001 Impersonation |
GroupAPT28 | LAMEHUG has sent spearphishing emails impersonating Ukrainian government officials. |
| T1684.001 Impersonation |
GroupAPT42 | APT42 has impersonated legitimate people in phishing emails to gain credentials. |
| T1684.001 Impersonation |
GroupAPT-C-36 | APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General. |
| T1684.001 Impersonation |
GroupLAPSUS$ | LAPSUS$ has called victims' help desk and impersonated legitimate users with previously gathered information in order to gain access to privileged accounts. |
| T1684.001 Impersonation |
GroupVOID MANTICORE | VOID MANTICORE has impersonated individuals familiar to the victim and technical support associated with social messaging services. |
| T1684.001 Impersonation |
GroupWIRTE | WIRTE has used utilized look-alike domains and graphics of trusted security solution providers to entice victims to click on phishing links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.