Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.004 Server |
GroupGALLIUM | GALLIUM has used Taiwan-based servers that appear to be exclusive to GALLIUM. |
| T1583.004 Server |
GroupMustard Tempest | Mustard Tempest has acquired servers to host second-stage payloads that remain active for a period of either days, weeks, or months. |
| T1583.004 Server |
GroupKimsuky | Kimsuky has purchased hosting servers with virtual currency and prepaid cards. |
| T1583.004 Server |
GroupSandworm Team | Sandworm Team has leased servers from resellers instead of leasing infrastructure directly from hosting companies to enable its operations. |
| T1583.004 Server |
GroupCURIUM | CURIUM has created dedicated servers for command and control and exfiltration purposes. |
| T1583.004 Server |
GroupEarth Lusca | Earth Lusca has acquired multiple servers for some of their operations, using each server for a different role. |
| T1583.004 Server |
GroupVOID MANTICORE | VOID MANTICORE has leveraged backend servers within Iran. |
| T1583.004 Server |
GroupTeamPCP | TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982. |
| T1583.004 Server |
GroupShinyHunters | ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.