Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.004 SSH |
GroupIndrik Spider | Indrik Spider has used SSH for lateral movement. |
| T1021.004 SSH |
GroupGCMAN | GCMAN uses Putty for lateral movement. |
| T1021.004 SSH |
GroupSalt Typhoon | Salt Typhoon has modified the loopback address on compromised switches and used them as the source of SSH connections to additional devices within the target environment, allowing them to bypass access control lists (ACLs). |
| T1021.004 SSH |
GroupmenuPass | menuPass has used Putty Secure Copy Client (PSCP) to transfer data. |
| T1021.004 SSH |
GroupStorm-1811 | Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access. |
| T1021.004 SSH |
GroupTeamTNT | TeamTNT has used SSH to connect back to victim machines. TeamTNT has also used SSH to transfer tools and payloads onto victim hosts and execute them. |
| T1021.004 SSH |
GroupFIN7 | FIN7 has used SSH to move laterally through victim environments. |
| T1021.004 SSH |
GroupRocke | Rocke has spread its coinminer via SSH. |
| T1021.004 SSH |
GroupScattered Spider | Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI. |
| T1021.004 SSH |
GroupAPT39 | APT39 used secure shell (SSH) to move laterally among their targets. |
| T1021.004 SSH |
GroupUNC3886 | UNC3886 has established remote SSH access to targeted ESXi hosts. |
| T1021.004 SSH |
GroupOilRig | OilRig has used Putty to access compromised systems. |
| T1021.004 SSH |
GroupAquatic Panda | Aquatic Panda used SSH with captured user credentials to move laterally in victim environments. |
| T1021.004 SSH |
GroupBlackTech | BlackTech has used Putty for remote access. |
| T1021.004 SSH |
GroupLeviathan | Leviathan used ssh for internal reconnaissance. |
| T1021.004 SSH |
GroupAPT5 | APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers. |
| T1021.004 SSH |
GroupFox Kitten | Fox Kitten has used the PuTTY and Plink tools for lateral movement. |
| T1021.004 SSH |
GroupLazarus Group | Lazarus Group used SSH and the PuTTy PSCP utility to gain access to a restricted segment of a compromised network. |
| T1021.004 SSH |
GroupFIN13 | FIN13 has remotely accessed compromised environments via secure shell (SSH) for lateral movement. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.