Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.006 Web Services |
GroupAPT17 | APT17 has created profile pages in Microsoft TechNet that were used as C2 infrastructure. |
| T1583.006 Web Services |
GroupKimsuky | Kimsuky has hosted content used for targeting efforts via web services such as Blogspot. Kimsuky has also leveraged Dropbox for hosting payloads and uploading victim system information. |
| T1583.006 Web Services |
GroupAPT32 | APT32 has set up Dropbox, Amazon S3, and Google Drive to host malicious downloads. |
| T1583.006 Web Services |
GroupHAFNIUM | HAFNIUM has acquired web services for use in C2 and exfiltration. |
| T1583.006 Web Services |
GroupMuddyWater | MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools. |
| T1583.006 Web Services |
GroupGamaredon Group | Gamaredon Group has used Cloudflare’s TryClouldflare service to obtain C2 nodes. |
| T1583.006 Web Services |
GroupFIN7 | FIN7 has set up Amazon S3 buckets to host trojanized digital products. |
| T1583.006 Web Services |
GroupMustang Panda | Mustang Panda has set up Dropbox and Google Drive to host malicious downloads. |
| T1583.006 Web Services |
GroupZIRCONIUM | ZIRCONIUM has used GitHub to host malware linked in spearphishing e-mails. |
| T1583.006 Web Services |
GroupContagious Interview | Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities. Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Sekoia ClickFake 2025Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1583.006 Web Services |
GroupTA2541 | TA2541 has hosted malicious files on various platforms including Google Drive, OneDrive, Discord, PasteText, ShareText, and GitHub. |
| T1583.006 Web Services |
GroupPOLONIUM | POLONIUM has created and used legitimate Microsoft OneDrive accounts for their operations. |
| T1583.006 Web Services |
GroupSaint Bear | Saint Bear has leveraged the Discord content delivery network to host malicious content for retrieval during initial access operations. |
| T1583.006 Web Services |
GroupConfucius | Confucius has obtained cloud storage service accounts to host stolen data. |
| T1583.006 Web Services |
GroupTurla | Turla has created web accounts including Dropbox and GitHub for C2 and document exfiltration. |
| T1583.006 Web Services |
GroupAPT29 | APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations. |
| T1583.006 Web Services |
GroupMedusa Group | Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions. |
| T1583.006 Web Services |
GroupTA578 | TA578 has used Google Firebase to host malicious scripts. |
| T1583.006 Web Services |
GroupLazyScripter | LazyScripter has established GitHub accounts to host its toolsets. |
| T1583.006 Web Services |
GroupAPT28 | APT28 has used newly-created Blogspot pages for credential harvesting operations. |
| T1583.006 Web Services |
GroupAPT-C-36 | APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox. |
| T1583.006 Web Services |
GroupLazarus Group | Lazarus Group has hosted malicious downloads on Github. |
| T1583.006 Web Services |
GroupEarth Lusca | Earth Lusca has established GitHub accounts to host their malware. |
| T1583.006 Web Services |
GroupIndigoZebra | IndigoZebra created Dropbox accounts for their operations. |
| T1583.006 Web Services |
GroupVOID MANTICORE | VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure. |
| T1583.006 Web Services |
GroupMagic Hound | Magic Hound has acquired Amazon S3 buckets to use in C2. |
| T1583.006 Web Services |
GroupTeamPCP | TeamPCP has set up Clouflare Tunnels for malware C2. TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via *.getsession[.]org to recipient ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.