ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1583.001×

15 examples

TechniqueUsed byProcedure example
T1583.001
Domains
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort.

T1583.001
Domains
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors registered C2 domains to spoof legitimate Microsoft domains.

T1583.001
Domains
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda registered adversary-controlled domains during RedDelta Modified PlugX Infection Chain Operations that were re-registrations of expired domains.

T1583.001
Domains
CampaignOperation Honeybee

During Operation Honeybee, threat actors registered domains for C2.

T1583.001
Domains
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors established domains as part of their operational infrastructure.

T1583.001
Domains
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities.

T1583.001
Domains
CampaignOperation Spalax

For Operation Spalax, the threat actors registered hundreds of domains using Duck DNS and DNS Exit.

T1583.001
Domains
CampaignC0021

For C0021, the threat actors registered domains for use in C2.

T1583.001
Domains
CampaignOperation Ghost

For Operation Ghost, APT29 registered domains for use in C2 including some crafted to appear as existing legitimate domains.

T1583.001
Domains
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers.

T1583.001
Domains
CampaignFunnyDream

For FunnyDream, the threat actors registered a variety of domains.

T1583.001
Domains
CampaignC0010

For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer.

T1583.001
Domains
CampaignC0011

For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India.

T1583.001
Domains
CampaignC0026

For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware.

T1583.001
Domains
CampaignCostaRicto

For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.