Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1584.004 Server |
GroupIndrik Spider | Indrik Spider has served fake updates via legitimate websites that have been compromised. |
| T1584.004 Server |
GroupVolt Typhoon | Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2. |
| T1584.004 Server |
GroupDragonfly | Dragonfly has compromised legitimate websites to host C2 and malware modules. |
| T1584.004 Server |
GroupSandworm Team | Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns. |
| T1584.004 Server |
GroupLeviathan | Leviathan has used compromised legitimate websites as command and control nodes for operations. |
| T1584.004 Server |
GroupTurla | Turla has used compromised servers as infrastructure. |
| T1584.004 Server |
GroupLazarus Group | Lazarus Group has compromised servers to stage malicious tools. |
| T1584.004 Server |
GroupEarth Lusca | Earth Lusca has used compromised web servers as part of their operational infrastructure. |
| T1584.004 Server |
GroupAPT16 | APT16 has compromised otherwise legitimate sites as staging servers for second-stage payloads. |
| T1584.004 Server |
GroupDaggerfly | Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.