ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1583.006×

27 examples

TechniqueUsed byProcedure example
T1583.006
Web Services
GroupAPT17

APT17 has created profile pages in Microsoft TechNet that were used as C2 infrastructure.

T1583.006
Web Services
GroupKimsuky

Kimsuky has hosted content used for targeting efforts via web services such as Blogspot. Kimsuky has also leveraged Dropbox for hosting payloads and uploading victim system information.

T1583.006
Web Services
GroupAPT32

APT32 has set up Dropbox, Amazon S3, and Google Drive to host malicious downloads.

T1583.006
Web Services
GroupHAFNIUM

HAFNIUM has acquired web services for use in C2 and exfiltration.

T1583.006
Web Services
GroupMuddyWater

MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools.

T1583.006
Web Services
GroupGamaredon Group

Gamaredon Group has used Cloudflare’s TryClouldflare service to obtain C2 nodes.

T1583.006
Web Services
GroupFIN7

FIN7 has set up Amazon S3 buckets to host trojanized digital products.

T1583.006
Web Services
GroupMustang Panda

Mustang Panda has set up Dropbox and Google Drive to host malicious downloads.

T1583.006
Web Services
GroupZIRCONIUM

ZIRCONIUM has used GitHub to host malware linked in spearphishing e-mails.

T1583.006
Web Services
GroupContagious Interview

Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities.

T1583.006
Web Services
GroupTA2541

TA2541 has hosted malicious files on various platforms including Google Drive, OneDrive, Discord, PasteText, ShareText, and GitHub.

T1583.006
Web Services
GroupPOLONIUM

POLONIUM has created and used legitimate Microsoft OneDrive accounts for their operations.

T1583.006
Web Services
GroupSaint Bear

Saint Bear has leveraged the Discord content delivery network to host malicious content for retrieval during initial access operations.

T1583.006
Web Services
GroupConfucius

Confucius has obtained cloud storage service accounts to host stolen data.

T1583.006
Web Services
GroupTurla

Turla has created web accounts including Dropbox and GitHub for C2 and document exfiltration.

T1583.006
Web Services
GroupAPT29

APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations.

T1583.006
Web Services
GroupMedusa Group

Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions.

T1583.006
Web Services
GroupTA578

TA578 has used Google Firebase to host malicious scripts.

T1583.006
Web Services
GroupLazyScripter

LazyScripter has established GitHub accounts to host its toolsets.

T1583.006
Web Services
GroupAPT28

APT28 has used newly-created Blogspot pages for credential harvesting operations.

T1583.006
Web Services
GroupAPT-C-36

APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox.

T1583.006
Web Services
GroupLazarus Group

Lazarus Group has hosted malicious downloads on Github.

T1583.006
Web Services
GroupEarth Lusca

Earth Lusca has established GitHub accounts to host their malware.

T1583.006
Web Services
GroupIndigoZebra

IndigoZebra created Dropbox accounts for their operations.

T1583.006
Web Services
GroupVOID MANTICORE

VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure.

T1583.006
Web Services
GroupMagic Hound

Magic Hound has acquired Amazon S3 buckets to use in C2.

T1583.006
Web Services
GroupTeamPCP

TeamPCP has set up Clouflare Tunnels for malware C2. TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via  *.getsession[.]org to recipient  ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.