Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1588.001 Malware |
GroupMuddyWater | MuddyWater has used publicly available malware for operations, likely to blend in with other cybercriminals. |
| T1588.001 Malware |
GroupAndariel | Andariel has used a variety of publicly-available remote access Trojans (RATs) for its operations. |
| T1588.001 Malware |
GroupScattered Spider | Scattered Spider has obtained malware to use at multiple stages of operations including information stealers, remote access tools, and ransomware. |
| T1588.001 Malware |
GroupUNC3886 | UNC3886 has used the publicly available rootkits REPTILE and MEDUSA. |
| T1588.001 Malware |
GroupTA2541 | TA2541 has used multiple strains of malware available for purchase on criminal forums or in open-source repositories. |
| T1588.001 Malware |
GroupAquatic Panda | Aquatic Panda has acquired and used njRAT in its operations. |
| T1588.001 Malware |
GroupAPT1 | APT1 used publicly available malware for privilege escalation. |
| T1588.001 Malware |
GroupTurla | Turla has used malware obtained after compromising other threat actors, such as OilRig. |
| T1588.001 Malware |
GroupTA505 | TA505 has used malware such as Azorult and Cobalt Strike in their operations. |
| T1588.001 Malware |
GroupBackdoorDiplomacy | BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations. |
| T1588.001 Malware |
GroupEmber Bear | Ember Bear has acquired malware and related tools from dark web forums. |
| T1588.001 Malware |
GroupLazyScripter | LazyScripter has used a variety of open-source remote access Trojans for its operations. |
| T1588.001 Malware |
GroupLuminousMoth | LuminousMoth has obtained and used malware such as Cobalt Strike. |
| T1588.001 Malware |
GroupMetador | Metador has used unique malware in their operations, including metaMain and Mafalda. |
| T1588.001 Malware |
GroupAPT-C-36 | APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos. |
| T1588.001 Malware |
GroupEarth Lusca | Earth Lusca has acquired and used a variety of malware, including Cobalt Strike. |
| T1588.001 Malware |
GroupLAPSUS$ | LAPSUS$ acquired and used the Redline password stealer in their operations. |
| T1588.001 Malware |
GroupVOID MANTICORE | VOID MANTICORE has developed or obtained trojanized applications used for persistent surveillance of targeted individuals. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.