ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1195.002×

9 examples

TechniqueUsed byProcedure example
T1195.002
Compromise Software Supply Chain
GroupAPT41

APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users.

T1195.002
Compromise Software Supply Chain
GroupDragonfly

Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores.

T1195.002
Compromise Software Supply Chain
GroupFIN7

FIN7 has gained initial access by compromising a victim's software supply chain.

T1195.002
Compromise Software Supply Chain
GroupSandworm Team

Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one.

T1195.002
Compromise Software Supply Chain
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has distributed ransomware by backdooring software installers via a strategic web compromise of the site hosting Italian WinRAR.

T1195.002
Compromise Software Supply Chain
GroupCobalt Group

Cobalt Group has compromised legitimate web browser updates to deliver a backdoor.

T1195.002
Compromise Software Supply Chain
GroupMoonstone Sleet

Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims.

T1195.002
Compromise Software Supply Chain
GroupDaggerfly

Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims.

T1195.002
Compromise Software Supply Chain
GroupThreat Group-3390

Threat Group-3390 has compromised the Able Desktop installer to gain access to victim's environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.