ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1189×

31 examples

TechniqueUsed byProcedure example
T1189
Drive-by Compromise
GroupAPT38

APT38 has conducted watering holes schemes to gain initial access to victims.

T1189
Drive-by Compromise
GroupElderwood

Elderwood has delivered zero-day exploits and malware to victims by injecting malicious code into specific public Web pages visited by targets within a particular sector.

T1189
Drive-by Compromise
GroupMustard Tempest

Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure.

T1189
Drive-by Compromise
GroupPatchwork

Patchwork has used watering holes to deliver files with exploits to initial victims.

T1189
Drive-by Compromise
GroupDragonfly

Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit.

T1189
Drive-by Compromise
GroupAPT32

APT32 has infected victims by tricking them into visiting compromised watering hole websites.

T1189
Drive-by Compromise
GroupLeafminer

Leafminer has infected victims using watering holes.

T1189
Drive-by Compromise
GroupMachete

Machete has distributed Machete through a fake blog website.

T1189
Drive-by Compromise
GroupAndariel

Andariel has used watering hole attacks, often with zero-day exploits, to gain initial access to victims within a specific IP range.

T1189
Drive-by Compromise
GroupCURIUM

CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader.

T1189
Drive-by Compromise
GroupAPT37

APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly.

T1189
Drive-by Compromise
GroupWindigo

Windigo has distributed Windows malware via drive-by downloads.

T1189
Drive-by Compromise
GroupLeviathan

Leviathan has infected victims using watering holes.

T1189
Drive-by Compromise
GroupWinter Vivern

Winter Vivern created dedicated web pages mimicking legitimate government websites to deliver malicious fake anti-virus software.

T1189
Drive-by Compromise
GroupTurla

Turla has infected victims using watering holes.

T1189
Drive-by Compromise
GroupDark Caracal

Dark Caracal leveraged a watering hole to serve up malicious code.

T1189
Drive-by Compromise
GroupBRONZE BUTLER

BRONZE BUTLER compromised three Japanese websites using a Flash exploit to perform watering hole attacks.

T1189
Drive-by Compromise
GroupDarkhotel

Darkhotel used embedded iframes on hotel login portals to redirect selected victims to download malware.

T1189
Drive-by Compromise
GroupAxiom

Axiom has used watering hole attacks to gain access.

T1189
Drive-by Compromise
GroupWindshift

Windshift has used compromised websites to register custom URL schemes on a remote system.

T1189
Drive-by Compromise
GroupAPT28

APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages.

T1189
Drive-by Compromise
GroupRTM

RTM has distributed its malware via the RIG and SUNDOWN exploit kits, as well as online advertising network Yandex.Direct.

T1189
Drive-by Compromise
GroupLazarus Group

Lazarus Group delivered RATANKBA and other malicious code to victims via a compromised legitimate website.

T1189
Drive-by Compromise
GroupEarth Lusca

Earth Lusca has performed watering hole attacks.

T1189
Drive-by Compromise
GroupTransparent Tribe

Transparent Tribe has used websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools.

T1189
Drive-by Compromise
GroupPROMETHIUM

PROMETHIUM has used watering hole attacks to deliver malicious versions of legitimate installers.

T1189
Drive-by Compromise
GroupDaggerfly

Daggerfly has used strategic website compromise for initial access against victims.

T1189
Drive-by Compromise
GroupPLATINUM

PLATINUM has sometimes used drive-by attacks against vulnerable browser plugins.

T1189
Drive-by Compromise
GroupMagic Hound

Magic Hound has conducted watering-hole attacks through media and magazine websites.

T1189
Drive-by Compromise
GroupThreat Group-3390

Threat Group-3390 has extensively used strategic web compromises to target victims.

T1189
Drive-by Compromise
GroupAPT19

APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.