Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1587.001 Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations. |
| T1587.001 Malware |
CampaignRedPenguin | During RedPenguin, UNC3886 deployed custom malware based on the publicly-available TINYSHELL backdoor. |
| T1587.001 Malware |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors used the Rising Sun modular backdoor. |
| T1587.001 Malware |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles developed, prior to the attack, malware capabilities that would require access to specific and specialized hardware and software. |
| T1587.001 Malware |
CampaignOperation Ghost | For Operation Ghost, APT29 used new strains of malware including FatDuke, MiniDuke, RegDuke, and PolyglotDuke. |
| T1587.001 Malware |
CampaignJuicy Mix | For Juicy Mix, OilRig improved on Solar by developing the Mango backdoor. |
| T1587.001 Malware |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP. |
| T1587.001 Malware |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used custom malware, as well as customized variants of publicly available tools. |
| T1587.001 Malware |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors created malicious applications within Salesforce trial accounts, typically Python scripts with similar function to the Salesforce Data Loader. |
| T1587.001 Malware |
CampaignOuter Space | For Outer Space, OilRig created new implants including the Solar backdoor. |
| T1587.001 Malware |
CampaignArcaneDoor | ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner. |
| T1587.001 Malware |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries observed that their malware was initially detected by the victims EDR solutions, so they modified the payload and attempted to execute the new version within the same day. |
| T1587.001 Malware |
CampaignC0010 | For C0010, UNC3890 actors used unique malware, including SUGARUSH and SUGARDUMP. |
| T1587.001 Malware |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation involved the development of a new web shell variant, VersaMem. |
| T1587.001 Malware |
CampaignOperation Wocao | During Operation Wocao, threat actors developed their own custom webshells to upload to compromised servers. |
| T1587.001 Malware |
CampaignCostaRicto | For CostaRicto, the threat actors used custom malware, including PS1, CostaBricks, and SombRAT. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.