ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1585.001×

19 examples

TechniqueUsed byProcedure example
T1585.001
Social Media Accounts
GroupKimsuky

Kimsuky has created social media accounts to monitor news and security trends as well as potential targets.

T1585.001
Social Media Accounts
GroupEXOTIC LILY

EXOTIC LILY has established social media profiles to mimic employees of targeted companies.

T1585.001
Social Media Accounts
GroupAPT32

APT32 has set up Facebook pages in tandem with fake websites.

T1585.001
Social Media Accounts
GroupSandworm Team

Sandworm Team has established social media accounts to disseminate victim internal-only documents and other sensitive data.

T1585.001
Social Media Accounts
GroupCURIUM

CURIUM has established a network of fictitious social media accounts, including on Facebook and LinkedIn, to establish relationships with victims, often posing as an attractive woman.

T1585.001
Social Media Accounts
GroupScattered Spider

Scattered Spider has created matching fake social media profiles to support new accounts created in victim environments.

T1585.001
Social Media Accounts
GroupContagious Interview

Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts.

T1585.001
Social Media Accounts
GroupLeviathan

Leviathan has created new social media accounts for targeting efforts.

T1585.001
Social Media Accounts
GroupCleaver

Cleaver has created fake LinkedIn profiles that included profile photos, details, and connections.

T1585.001
Social Media Accounts
GroupMedusa Group

Medusa Group has created social media accounts including Telegram and X to publicize their activities.

T1585.001
Social Media Accounts
GroupStar Blizzard

Star Blizzard has established fraudulent profiles on professional networking sites to conduct reconnaissance.

T1585.001
Social Media Accounts
GroupWater Galura

Water Galura operates a news channel on Telegram to make announcements for the Qilin RaaS.

T1585.001
Social Media Accounts
GroupFox Kitten

Fox Kitten has used a Twitter account to communicate with ransomware victims.

T1585.001
Social Media Accounts
GroupLazarus Group

Lazarus Group has created new Twitter accounts to conduct social engineering against potential victims.

T1585.001
Social Media Accounts
GroupMoonstone Sleet

Moonstone Sleet has created social media accounts to interact with victims.

T1585.001
Social Media Accounts
GroupVOID MANTICORE

VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures.

T1585.001
Social Media Accounts
GroupHEXANE

HEXANE has established fraudulent LinkedIn accounts impersonating HR department employees to target potential victims with fake job offers.

T1585.001
Social Media Accounts
GroupMagic Hound

Magic Hound has created fake LinkedIn and other social media accounts to contact targets and convince them--through messages and voice communications--to open malicious links.

T1585.001
Social Media Accounts
GroupTeamPCP

TeamPCP has used its own Telegram channel and X accounts @pcpcats and @xploitrsturtle2 for external communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.