ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1587.001×

16 examples

TechniqueUsed byProcedure example
T1587.001
Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations.

T1587.001
Malware
CampaignRedPenguin

During RedPenguin, UNC3886 deployed custom malware based on the publicly-available TINYSHELL backdoor.

T1587.001
Malware
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used the Rising Sun modular backdoor.

T1587.001
Malware
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles developed, prior to the attack, malware capabilities that would require access to specific and specialized hardware and software.

T1587.001
Malware
CampaignOperation Ghost

For Operation Ghost, APT29 used new strains of malware including FatDuke, MiniDuke, RegDuke, and PolyglotDuke.

T1587.001
Malware
CampaignJuicy Mix

For Juicy Mix, OilRig improved on Solar by developing the Mango backdoor.

T1587.001
Malware
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP.

T1587.001
Malware
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used custom malware, as well as customized variants of publicly available tools.

T1587.001
Malware
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors created malicious applications within Salesforce trial accounts, typically Python scripts with similar function to the Salesforce Data Loader.

T1587.001
Malware
CampaignOuter Space

For Outer Space, OilRig created new implants including the Solar backdoor.

T1587.001
Malware
CampaignArcaneDoor

ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner.

T1587.001
Malware
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries observed that their malware was initially detected by the victims EDR solutions, so they modified the payload and attempted to execute the new version within the same day.

T1587.001
Malware
CampaignC0010

For C0010, UNC3890 actors used unique malware, including SUGARUSH and SUGARDUMP.

T1587.001
Malware
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation involved the development of a new web shell variant, VersaMem.

T1587.001
Malware
CampaignOperation Wocao

During Operation Wocao, threat actors developed their own custom webshells to upload to compromised servers.

T1587.001
Malware
CampaignCostaRicto

For CostaRicto, the threat actors used custom malware, including PS1, CostaBricks, and SombRAT.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.