ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1583.004×

9 examples

TechniqueUsed byProcedure example
T1583.004
Server
GroupGALLIUM

GALLIUM has used Taiwan-based servers that appear to be exclusive to GALLIUM.

T1583.004
Server
GroupMustard Tempest

Mustard Tempest has acquired servers to host second-stage payloads that remain active for a period of either days, weeks, or months.

T1583.004
Server
GroupKimsuky

Kimsuky has purchased hosting servers with virtual currency and prepaid cards.

T1583.004
Server
GroupSandworm Team

Sandworm Team has leased servers from resellers instead of leasing infrastructure directly from hosting companies to enable its operations.

T1583.004
Server
GroupCURIUM

CURIUM has created dedicated servers for command and control and exfiltration purposes.

T1583.004
Server
GroupEarth Lusca

Earth Lusca has acquired multiple servers for some of their operations, using each server for a different role.

T1583.004
Server
GroupVOID MANTICORE

VOID MANTICORE has leveraged backend servers within Iran.

T1583.004
Server
GroupTeamPCP

TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982.

T1583.004
Server
GroupShinyHunters

ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.