Real-world descriptions of how a group, tool or campaign used a technique.
82 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1588.002 Tool |
GroupAPT38 | APT38 has obtained and used open-source tools such as Mimikatz. |
| T1588.002 Tool |
GroupGALLIUM | GALLIUM has used a variety of widely-available tools, which in some cases they modified to add functionality and/or subvert antimalware solutions. |
| T1588.002 Tool |
GroupKimsuky | Kimsuky has obtained and used tools such as Nirsoft WebBrowserPassVIew, Mimikatz, and PsExec. |
| T1588.002 Tool |
GroupVolt Typhoon | Volt Typhoon has used legitimate network and forensic tools and customized versions of open-source tools for C2. |
| T1588.002 Tool |
GroupPatchwork | Patchwork has obtained and used open-source tools such as QuasarRAT. |
| T1588.002 Tool |
GroupAPT41 | APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor. |
| T1588.002 Tool |
GroupSalt Typhoon | Salt Typhoon has used publicly available tooling to exploit vulnerabilities. |
| T1588.002 Tool |
GroupDragonfly | Dragonfly has obtained and used tools such as Mimikatz, CrackMapExec, and PsExec. |
| T1588.002 Tool |
GroupGorgon Group | Gorgon Group has obtained and used tools such as QuasarRAT and Remcos. |
| T1588.002 Tool |
GroupmenuPass | menuPass has used and modified open-source tools like Impacket, Mimikatz, and pwdump. |
| T1588.002 Tool |
GroupAPT32 | APT32 has obtained and used tools such as Mimikatz and Cobalt Strike, and a variety of other open-source tools from GitHub. |
| T1588.002 Tool |
GroupMuddyWater | MuddyWater has used legitimate tools ConnectWise, RemoteUtilities, and SimpleHelp to gain access to the target environment. |
| T1588.002 Tool |
GroupFIN6 | FIN6 has obtained and used tools such as Mimikatz, Cobalt Strike, and AdFind. |
| T1588.002 Tool |
GroupGamaredon Group | Gamaredon Group has used various legitimate tools, such as `mshta.exe` and Reg, and services during operations. |
| T1588.002 Tool |
GroupStorm-1811 | Storm-1811 acquired various legitimate and malicious tools, such as RMM software and commodity malware packages, for operations. |
| T1588.002 Tool |
GroupLeafminer | Leafminer has obtained and used tools such as LaZagne, Mimikatz, PsExec, and MailSniper. |
| T1588.002 Tool |
GroupFIN7 | FIN7 has utilized a variety of tools such as Cobalt Strike, PowerSploit, and the remote management tool, Atera for targeting efforts. |
| T1588.002 Tool |
GroupSandworm Team | Sandworm Team has acquired open-source tools for their operations, including Invoke-PSImage, which was used to establish an encrypted channel from a compromised host to Sandworm Team's C2 server in preparation for the 2018 Winter Olympics attack, as well as Impacket and RemoteExec, which were used in their 2022 Prestige operations. Additionally, Sandworm Team has used Empire, Cobalt Strike and PoshC2. |
| T1588.002 Tool |
GroupMustang Panda | Mustang Panda has obtained and leveraged publicly-available tools for intrusion activities. |
| T1588.002 Tool |
GroupScattered Spider | Scattered Spider has obtained tools for use throughout the attack lifecycle to include remote access software, protocol tunneling and proxy tools, exploitation frameworks, and reconnaissance tools. |
| T1588.002 Tool |
GroupAPT39 | APT39 has modified and used customized versions of publicly-available tools like PLINK and Mimikatz. |
| T1588.002 Tool |
GroupContagious Interview | Contagious Interview has used remote management and monitoring software such as “AnyDesk”. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024SecurityScorecard Contagious Interview October 2024 |
| T1588.002 Tool |
GroupTA2541 | TA2541 has used commodity remote access tools. |
| T1588.002 Tool |
GroupMoses Staff | Moses Staff has used the commercial tool DiskCryptor. |
| T1588.002 Tool |
GroupOilRig | OilRig has made use of the publicly available tools including Plink and Mimikatz. |
| T1588.002 Tool |
GroupCarbanak | Carbanak has obtained and used open-source tools such as PsExec and Mimikatz. |
| T1588.002 Tool |
GroupSea Turtle | Sea Turtle has used tools such as Adminer during intrusions. |
| T1588.002 Tool |
GroupPOLONIUM | POLONIUM has obtained and used tools such as AirVPN and plink in their operations. |
| T1588.002 Tool |
GroupAquatic Panda | Aquatic Panda has acquired and used Cobalt Strike in its operations. |
| T1588.002 Tool |
GroupAoqin Dragon | Aoqin Dragon obtained the Heyoka open source exfiltration tool and subsequently modified it for their operations. |
| T1588.002 Tool |
GroupFerocious Kitten | Ferocious Kitten has obtained open source tools for its operations, including JsonCPP and Psiphon. |
| T1588.002 Tool |
GroupKe3chang | |
| T1588.002 Tool |
GroupAPT1 | APT1 has used various open-source tools for privilege escalation purposes. |
| T1588.002 Tool |
GroupDarkHydrus | DarkHydrus has obtained and used tools such as Mimikatz, Empire, and Cobalt Strike. |
| T1588.002 Tool |
GroupBlackTech | BlackTech has obtained and used tools such as Putty, SNScan, and PsExec for its operations. |
| T1588.002 Tool |
GroupBlue Mockingbird | Blue Mockingbird has obtained and used tools such as Mimikatz. |
| T1588.002 Tool |
GroupTurla | Turla has obtained and customized publicly-available tools like Mimikatz. |
| T1588.002 Tool |
GroupTA505 | TA505 has used a variety of tools in their operations, including AdFind, BloodHound, Mimikatz, and PowerSploit. |
| T1588.002 Tool |
GroupBITTER | BITTER has obtained tools such as PuTTY for use in their operations. |
| T1588.002 Tool |
GroupDarkVishnya | DarkVishnya has obtained and used tools such as Impacket, Winexe, and PsExec. |
| T1588.002 Tool |
GroupFIN5 | FIN5 has obtained and used a customized version of PsExec, as well as use other tools such as pwdump, SDelete, and Windows Credential Editor. |
| T1588.002 Tool |
GroupLotus Blossom | Lotus Blossom has used publicly-available tools such as a Python-based cookie stealer for Chrome browsers, Impacket, and the Venom proxy tool. |
| T1588.002 Tool |
GroupAPT29 | APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike. |
| T1588.002 Tool |
GroupCinnamon Tempest | Cinnamon Tempest has used open-source tools including customized versions of the Iox proxy tool, NPS tunneling tool, Meterpreter, and a keylogger that uploads data to Alibaba cloud storage. |
| T1588.002 Tool |
GroupChimera | Chimera has obtained and used tools such as BloodHound, Cobalt Strike, Mimikatz, and PsExec. |
| T1588.002 Tool |
GroupMirrorFace | MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike. |
| T1588.002 Tool |
GroupCleaver | Cleaver has obtained and used open-source tools such as PsExec, Windows Credential Editor, and Mimikatz. |
| T1588.002 Tool |
GroupSilent Librarian | Silent Librarian has obtained free and publicly available tools including SingleFile and HTTrack to copy login pages of targeted organizations. |
| T1588.002 Tool |
GroupMedusa Group | Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning. Medusa Group has utilized tools such as Advanced IP Scanner and SoftPerfect Network scanner for user, system and network discovery. Medusa Group has also acquired tools for command and control and defense evasion which include tunneling tools Ligolo and Cloudflared. |
| T1588.002 Tool |
GroupBRONZE BUTLER | BRONZE BUTLER has obtained and used open-source tools such as Mimikatz, gsecdump, and Windows Credential Editor. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.