Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1133 External Remote Services |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a modified Dropbear SSH client as the backdoor to target systems. |
| T1133 External Remote Services |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used VPN access to persist in the victim environment. |
| T1133 External Remote Services |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used compromised identities to access networks via SSH, VPNs, and other remote access tools. |
| T1133 External Remote Services |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors enabled WinRM over HTTP/HTTPS as a backup persistence mechanism using the following command: `cscript //nologo "C:\Windows\System32\winrm.vbs" set winrm/config/service@{EnableCompatibilityHttpsListener="true"}`. |
| T1133 External Remote Services |
CampaignArcaneDoor | ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices. |
| T1133 External Remote Services |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, threat actors leveraged the FortiGate VPN interface that was exposed to the internet to gain access to the victim environment. |
| T1133 External Remote Services |
CampaignNight Dragon | During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems. |
| T1133 External Remote Services |
CampaignOperation Wocao | During Operation Wocao, threat actors used stolen credentials to connect to the victim's network via VPN. |
| T1133 External Remote Services |
CampaignC0027 | During C0027, Scattered Spider used Citrix and VPNs to persist in compromised environments. |
| T1133 External Remote Services |
CampaignCostaRicto | During CostaRicto, the threat actors set up remote tunneling using an SSH tool to maintain access to a compromised environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.