Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1684.001 Impersonation |
GroupKimsuky | Kimsuky has also impersonated legitimate people, such as a foreign advisor, an embassy employee, and a think tank employee. Kimsuky has also purported to be a Japanese diplomat to communicate with the victims. |
| T1684.001 Impersonation |
GroupAPT41 | APT41 impersonated an employee at a video game developer company to send phishing emails. |
| T1684.001 Impersonation |
GroupMuddyWater | MuddyWater has used support@microsoftonlines[.]com to send phishing emails that masqueraded as security updates from Microsoft. MuddyWater has also impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain info@tmcell. |
| T1684.001 Impersonation |
GroupStorm-1811 | Storm-1811 impersonates help desk and IT support personnel for phishing and social engineering purposes during initial access to victim environments. |
| T1684.001 Impersonation |
GroupScattered Spider | Scattered Spider utilized social engineering to compel IT help desk personnel to reset passwords and MFA tokens. Scattered Spider has also used Microsoft Teams to pose as internal IT support or help desk personnel. |
| T1684.001 Impersonation |
GroupContagious Interview | Contagious Interview had impersonated HR hiring personnel through social media, job board notifications, and conducted interviews with victims in order to entice them to download malware disguised as legitimate applications or malicious scripts from code repositories. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Securonix Contagious Interview DEVPOPPER April 2024Sentinel One Contagious Interview ClickFix September 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1684.001 Impersonation |
GroupSaint Bear | Saint Bear has impersonated government and related entities in both phishing activity and developing web sites with malicious links that mimic legitimate resources. |
| T1684.001 Impersonation |
GroupMirrorFace | MirrorFace has sent targeted emails purporting to be from a Japanese political party’s PR department. |
| T1684.001 Impersonation |
GroupStar Blizzard | Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target. |
| T1684.001 Impersonation |
GroupAPT28 | LAMEHUG has sent spearphishing emails impersonating Ukrainian government officials. |
| T1684.001 Impersonation |
GroupAPT42 | APT42 has impersonated legitimate people in phishing emails to gain credentials. |
| T1684.001 Impersonation |
GroupAPT-C-36 | APT-C-36 has impersonated banks including Banco Davivienda, Bancolombia, and BBVA as well as government institutions such as Colombia’s National Directorate of Taxes and Customs, Ministry of Foreign Affairs, and Office of the Attorney General. |
| T1684.001 Impersonation |
GroupLAPSUS$ | LAPSUS$ has called victims' help desk and impersonated legitimate users with previously gathered information in order to gain access to privileged accounts. |
| T1684.001 Impersonation |
GroupVOID MANTICORE | VOID MANTICORE has impersonated individuals familiar to the victim and technical support associated with social messaging services. |
| T1684.001 Impersonation |
GroupWIRTE | WIRTE has used utilized look-alike domains and graphics of trusted security solution providers to entice victims to click on phishing links. |
| T1684.001 Impersonation |
GroupTeamPCP | TeamPCP impersonated legitimate maintainers to push imposter commits to the Aquasecurity Trivy scanner GitHub repository. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.