ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1189×

10 examples

TechniqueUsed byProcedure example
T1189
Drive-by Compromise
MalwareBad Rabbit

Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a .js file.

T1189
Drive-by Compromise
MalwareKARAE

KARAE was distributed through torrent file-sharing websites to South Korean victims, using a YouTube video downloader application as a lure.

T1189
Drive-by Compromise
MalwareSnip3

Snip3 has been delivered to targets via downloads from malicious domains.

T1189
Drive-by Compromise
MalwareIcedID

IcedID has cloned legitimate websites/applications to distribute the malware.

T1189
Drive-by Compromise
MalwarePOORAIM

POORAIM has been delivered through compromised sites acting as watering holes.

T1189
Drive-by Compromise
MalwareSocGholish

SocGholish has been distributed through compromised websites with malicious content often masquerading as browser updates.

T1189
Drive-by Compromise
MalwareBundlore

Bundlore has been spread through malicious advertisements on websites.

T1189
Drive-by Compromise
MalwareGrandoreiro

Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer.

T1189
Drive-by Compromise
MalwareREvil

REvil has infected victim machines through compromised websites and exploit kits.

T1189
Drive-by Compromise
MalwareLoudMiner

LoudMiner is typically bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.