ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1588.001×

18 examples

TechniqueUsed byProcedure example
T1588.001
Malware
GroupMuddyWater

MuddyWater has used publicly available malware for operations, likely to blend in with other cybercriminals.

T1588.001
Malware
GroupAndariel

Andariel has used a variety of publicly-available remote access Trojans (RATs) for its operations.

T1588.001
Malware
GroupScattered Spider

Scattered Spider has obtained malware to use at multiple stages of operations including information stealers, remote access tools, and ransomware.

T1588.001
Malware
GroupUNC3886

UNC3886 has used the publicly available rootkits REPTILE and MEDUSA.

T1588.001
Malware
GroupTA2541

TA2541 has used multiple strains of malware available for purchase on criminal forums or in open-source repositories.

T1588.001
Malware
GroupAquatic Panda

Aquatic Panda has acquired and used njRAT in its operations.

T1588.001
Malware
GroupAPT1

APT1 used publicly available malware for privilege escalation.

T1588.001
Malware
GroupTurla

Turla has used malware obtained after compromising other threat actors, such as OilRig.

T1588.001
Malware
GroupTA505

TA505 has used malware such as Azorult and Cobalt Strike in their operations.

T1588.001
Malware
GroupBackdoorDiplomacy

BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.

T1588.001
Malware
GroupEmber Bear

Ember Bear has acquired malware and related tools from dark web forums.

T1588.001
Malware
GroupLazyScripter

LazyScripter has used a variety of open-source remote access Trojans for its operations.

T1588.001
Malware
GroupLuminousMoth

LuminousMoth has obtained and used malware such as Cobalt Strike.

T1588.001
Malware
GroupMetador

Metador has used unique malware in their operations, including metaMain and Mafalda.

T1588.001
Malware
GroupAPT-C-36

APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos.

T1588.001
Malware
GroupEarth Lusca

Earth Lusca has acquired and used a variety of malware, including Cobalt Strike.

T1588.001
Malware
GroupLAPSUS$

LAPSUS$ acquired and used the Redline password stealer in their operations.

T1588.001
Malware
GroupVOID MANTICORE

VOID MANTICORE has developed or obtained trojanized applications used for persistent surveillance of targeted individuals.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.