Real-world descriptions of how a group, tool or campaign used a technique.
15 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.001 Domains |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort. |
| T1583.001 Domains |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors registered C2 domains to spoof legitimate Microsoft domains. |
| T1583.001 Domains |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda registered adversary-controlled domains during RedDelta Modified PlugX Infection Chain Operations that were re-registrations of expired domains. |
| T1583.001 Domains |
CampaignOperation Honeybee | During Operation Honeybee, threat actors registered domains for C2. |
| T1583.001 Domains |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors established domains as part of their operational infrastructure. |
| T1583.001 Domains |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities. |
| T1583.001 Domains |
CampaignOperation Spalax | For Operation Spalax, the threat actors registered hundreds of domains using Duck DNS and DNS Exit. |
| T1583.001 Domains |
CampaignC0021 | For C0021, the threat actors registered domains for use in C2. |
| T1583.001 Domains |
CampaignOperation Ghost | For Operation Ghost, APT29 registered domains for use in C2 including some crafted to appear as existing legitimate domains. |
| T1583.001 Domains |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers. |
| T1583.001 Domains |
CampaignFunnyDream | For FunnyDream, the threat actors registered a variety of domains. |
| T1583.001 Domains |
CampaignC0010 | For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer. |
| T1583.001 Domains |
CampaignC0011 | For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India. |
| T1583.001 Domains |
CampaignC0026 | For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware. |
| T1583.001 Domains |
CampaignCostaRicto | For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.