Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1657 Financial Theft |
GroupKimsuky | Kimsuky has stolen and laundered cryptocurrency to self-fund operations including the acquisition of infrastructure. |
| T1657 Financial Theft |
GroupAppleJeus | AppleJeus has targeted the cryptocurrency industry with the goal of stealing digital assets. |
| T1657 Financial Theft |
GroupScattered Spider | Scattered Spider has deployed ransomware on compromised hosts and threatened to leak stolen data for financial gain. |
| T1657 Financial Theft |
GroupContagious Interview | Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1657 Financial Theft |
GroupAkira | Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom. |
| T1657 Financial Theft |
GroupSilverTerrier | SilverTerrier targets organizations in high technology, higher education, and manufacturing for business email compromise (BEC) campaigns with the goal of financial theft. |
| T1657 Financial Theft |
GroupStorm-0501 | Storm-0501 has engaged in double-extortion ransomware, exfiltrating data and directly contacting victims when the primary organization refuses to pay along with posting data on their data leak sites. |
| T1657 Financial Theft |
GroupCinnamon Tempest | Cinnamon Tempest has maintained leak sites for exfiltrated data in attempt to extort victims into paying a ransom. |
| T1657 Financial Theft |
GroupMedusa Group | Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom. |
| T1657 Financial Theft |
GroupWater Galura | Water Galura has extorted victims for ransomware decryption keys and to prevent publication of data exfiltrated to their Tor data leak site. |
| T1657 Financial Theft |
GroupMalteiro | Malteiro targets organizations in a wide variety of sectors via the use of Mispadu banking trojan with the goal of financial theft. |
| T1657 Financial Theft |
GroupINC Ransom | INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it. |
| T1657 Financial Theft |
GroupVOID MANTICORE | VOID MANTICORE has conducted data exfiltration and posted stolen information on data leak sites for the purposes of financial and political extortion. VOID MANTICORE has also sold stolen data to prospective buyers for cryptocurrency. |
| T1657 Financial Theft |
GroupPlay | Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks. |
| T1657 Financial Theft |
GroupFIN13 | FIN13 has observed the victim's software and infrastructure over several months to understand the technical process of legitimate financial transactions, prior to attempting to conduct fraudulent transactions. |
| T1657 Financial Theft |
GroupTeamPCP | TeamPCP has engaged in cryptocurrency mining and theft. TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware. |
| T1657 Financial Theft |
GroupShinyHunters | ShinyHunters has called or sent text messages or emails to employees of victim organizations to demand payment in Bitcoin within 72 hours. Email addresses used in extortion activities include shinycorp@tuta[.]com, shinygroup@tuta[.]com, shinycorp@tutanota[.]com, and shinygroup@onionmail[.]com. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.