Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1189 Drive-by Compromise |
MalwareBad Rabbit | Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a |
| T1189 Drive-by Compromise |
MalwareKARAE | KARAE was distributed through torrent file-sharing websites to South Korean victims, using a YouTube video downloader application as a lure. |
| T1189 Drive-by Compromise |
MalwareSnip3 | Snip3 has been delivered to targets via downloads from malicious domains. |
| T1189 Drive-by Compromise |
MalwareIcedID | IcedID has cloned legitimate websites/applications to distribute the malware. |
| T1189 Drive-by Compromise |
MalwarePOORAIM | POORAIM has been delivered through compromised sites acting as watering holes. |
| T1189 Drive-by Compromise |
MalwareSocGholish | SocGholish has been distributed through compromised websites with malicious content often masquerading as browser updates. |
| T1189 Drive-by Compromise |
MalwareBundlore | Bundlore has been spread through malicious advertisements on websites. |
| T1189 Drive-by Compromise |
MalwareGrandoreiro | Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer. |
| T1189 Drive-by Compromise |
MalwareREvil | REvil has infected victim machines through compromised websites and exploit kits. |
| T1189 Drive-by Compromise |
MalwareLoudMiner | LoudMiner is typically bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.