ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1583×

9 examples

TechniqueUsed byProcedure example
T1583
Acquire Infrastructure
GroupIndrik Spider

Indrik Spider has purchased access to victim VPNs to facilitate access to victim environments.

T1583
Acquire Infrastructure
GroupKimsuky

Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure.

T1583
Acquire Infrastructure
GroupSandworm Team

Sandworm Team used various third-party email campaign management services to deliver phishing emails.

T1583
Acquire Infrastructure
GroupContagious Interview

Contagious Interview has used services such as Astrill VPN.

T1583
Acquire Infrastructure
GroupSea Turtle

Sea Turtle accessed victim networks from VPN service provider networks.

T1583
Acquire Infrastructure
GroupStar Blizzard

Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails.

T1583
Acquire Infrastructure
GroupEmber Bear

Ember Bear uses services such as IVPN, SurfShark, and Tor to add anonymization to operations.

T1583
Acquire Infrastructure
GroupAgrius

Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN.

T1583
Acquire Infrastructure
GroupTeamPCP

In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.