ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1584.004×

10 examples

TechniqueUsed byProcedure example
T1584.004
Server
GroupIndrik Spider

Indrik Spider has served fake updates via legitimate websites that have been compromised.

T1584.004
Server
GroupVolt Typhoon

Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2.

T1584.004
Server
GroupDragonfly

Dragonfly has compromised legitimate websites to host C2 and malware modules.

T1584.004
Server
GroupSandworm Team

Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns.

T1584.004
Server
GroupLeviathan

Leviathan has used compromised legitimate websites as command and control nodes for operations.

T1584.004
Server
GroupTurla

Turla has used compromised servers as infrastructure.

T1584.004
Server
GroupLazarus Group

Lazarus Group has compromised servers to stage malicious tools.

T1584.004
Server
GroupEarth Lusca

Earth Lusca has used compromised web servers as part of their operational infrastructure.

T1584.004
Server
GroupAPT16

APT16 has compromised otherwise legitimate sites as staging servers for second-stage payloads.

T1584.004
Server
GroupDaggerfly

Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.