Real-world descriptions of how a group, tool or campaign used a technique.
31 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1189 Drive-by Compromise |
GroupAPT38 | APT38 has conducted watering holes schemes to gain initial access to victims. |
| T1189 Drive-by Compromise |
GroupElderwood | Elderwood has delivered zero-day exploits and malware to victims by injecting malicious code into specific public Web pages visited by targets within a particular sector. |
| T1189 Drive-by Compromise |
GroupMustard Tempest | Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure. |
| T1189 Drive-by Compromise |
GroupPatchwork | Patchwork has used watering holes to deliver files with exploits to initial victims. |
| T1189 Drive-by Compromise |
GroupDragonfly | Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit. |
| T1189 Drive-by Compromise |
GroupAPT32 | APT32 has infected victims by tricking them into visiting compromised watering hole websites. |
| T1189 Drive-by Compromise |
GroupLeafminer | Leafminer has infected victims using watering holes. |
| T1189 Drive-by Compromise |
GroupMachete | Machete has distributed Machete through a fake blog website. |
| T1189 Drive-by Compromise |
GroupAndariel | Andariel has used watering hole attacks, often with zero-day exploits, to gain initial access to victims within a specific IP range. |
| T1189 Drive-by Compromise |
GroupCURIUM | CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader. |
| T1189 Drive-by Compromise |
GroupAPT37 | APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly. |
| T1189 Drive-by Compromise |
GroupWindigo | Windigo has distributed Windows malware via drive-by downloads. |
| T1189 Drive-by Compromise |
GroupLeviathan | Leviathan has infected victims using watering holes. |
| T1189 Drive-by Compromise |
GroupWinter Vivern | Winter Vivern created dedicated web pages mimicking legitimate government websites to deliver malicious fake anti-virus software. |
| T1189 Drive-by Compromise |
GroupTurla | Turla has infected victims using watering holes. |
| T1189 Drive-by Compromise |
GroupDark Caracal | Dark Caracal leveraged a watering hole to serve up malicious code. |
| T1189 Drive-by Compromise |
GroupBRONZE BUTLER | BRONZE BUTLER compromised three Japanese websites using a Flash exploit to perform watering hole attacks. |
| T1189 Drive-by Compromise |
GroupDarkhotel | Darkhotel used embedded iframes on hotel login portals to redirect selected victims to download malware. |
| T1189 Drive-by Compromise |
GroupAxiom | Axiom has used watering hole attacks to gain access. |
| T1189 Drive-by Compromise |
GroupWindshift | Windshift has used compromised websites to register custom URL schemes on a remote system. |
| T1189 Drive-by Compromise |
GroupAPT28 | APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages. |
| T1189 Drive-by Compromise |
GroupRTM | RTM has distributed its malware via the RIG and SUNDOWN exploit kits, as well as online advertising network |
| T1189 Drive-by Compromise |
GroupLazarus Group | Lazarus Group delivered RATANKBA and other malicious code to victims via a compromised legitimate website. |
| T1189 Drive-by Compromise |
GroupEarth Lusca | Earth Lusca has performed watering hole attacks. |
| T1189 Drive-by Compromise |
GroupTransparent Tribe | Transparent Tribe has used websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools. |
| T1189 Drive-by Compromise |
GroupPROMETHIUM | PROMETHIUM has used watering hole attacks to deliver malicious versions of legitimate installers. |
| T1189 Drive-by Compromise |
GroupDaggerfly | Daggerfly has used strategic website compromise for initial access against victims. |
| T1189 Drive-by Compromise |
GroupPLATINUM | PLATINUM has sometimes used drive-by attacks against vulnerable browser plugins. |
| T1189 Drive-by Compromise |
GroupMagic Hound | Magic Hound has conducted watering-hole attacks through media and magazine websites. |
| T1189 Drive-by Compromise |
GroupThreat Group-3390 | Threat Group-3390 has extensively used strategic web compromises to target victims. |
| T1189 Drive-by Compromise |
GroupAPT19 | APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.