ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1583.001
Domains
GroupStorm-1811

Storm-1811 has created domains for use with RMM tools.

T1583.001
Domains
GroupTeamTNT

TeamTNT has obtained domains to host their payloads.

T1583.001
Domains
GroupFIN7

FIN7 has registered look-alike domains for use in phishing campaigns. Additionally, FIN7 has registered a malicious domain as `advanced-ip-sccanner[.]com` that redirected to an adversary-controlled Dropbox which contained the malicious executable.

T1583.001
Domains
GroupSandworm Team

Sandworm Team has registered domain names and created URLs that are often designed to mimic or spoof legitimate websites, such as email login pages, online file sharing and storage websites, and password reset pages, while also hosting these items on legitimate, compromised network infrastructure.

T1583.001
Domains
GroupCURIUM

CURIUM created domains to facilitate strategic website compromise and credential capture activities.

T1583.001
Domains
GroupMustang Panda

Mustang Panda has acquired C2 domains prior to operations.

T1583.001
Domains
GroupZIRCONIUM

ZIRCONIUM has purchased domains for use in targeted campaigns.

T1583.001
Domains
GroupScattered Spider

Scattered Spider has registered domains to spoof legitimate corporate login portals.

T1583.001
Domains
GroupContagious Interview

Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2.

T1583.001
Domains
GroupTA2541

TA2541 has registered domains often containing the keywords “kimjoy,” “h0pe,” and “grace,” using domain registrars including Netdorm and No-IP DDNS, and hosting providers including xTom GmbH and Danilenko, Artyom.

T1583.001
Domains
GroupOilRig

OilRig has set up fake VPN portals, conference sign ups, and job application websites to target victims.

T1583.001
Domains
GroupSea Turtle

Sea Turtle registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers.

T1583.001
Domains
GroupFerocious Kitten

Ferocious Kitten has acquired domains imitating legitimate sites.

T1583.001
Domains
GroupAPT1

APT1 has registered hundreds of domains for use in operations.

T1583.001
Domains
GroupLeviathan

Leviathan has established domains that impersonate legitimate entities to use for targeting efforts.

T1583.001
Domains
GroupWinter Vivern

Winter Vivern registered domains mimicking other entities throughout various campaigns.

T1583.001
Domains
GroupTA505

TA505 has registered domains to impersonate services such as Dropbox to distribute malware.

T1583.001
Domains
GroupBITTER

BITTER has registered a variety of domains to host malicious payloads and for C2.

T1583.001
Domains
GroupSilent Librarian

Silent Librarian has acquired domains to establish credential harvesting pages, often spoofing the target organization and using free top level domains .TK, .ML, .GA, .CF, and .GQ.

T1583.001
Domains
GroupStar Blizzard

Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations.

T1583.001
Domains
GroupLazyScripter

LazyScripter has used dynamic DNS providers to create legitimate-looking subdomains for C2.

T1583.001
Domains
GroupAPT28

APT28 registered domains imitating NATO, OSCE security websites, Caucasus information resources, and other organizations.

T1583.001
Domains
GroupAPT42

APT42 has registered domains, several of which masqueraded as news outlets and login services, for use in operations.

T1583.001
Domains
GroupAPT-C-36

APT-C-36 has acquired domains to host malicious payloads.

T1583.001
Domains
GroupWinnti Group

Winnti Group has registered domains for C2 that mimicked sites of their intended targets.

T1583.001
Domains
GroupLazarus Group

Lazarus Group has acquired domains related to their campaigns to act as distribution points and C2 channels.

T1583.001
Domains
GroupEarth Lusca

Earth Lusca has registered domains, intended to look like legitimate target domains, that have been used in watering hole attacks.

T1583.001
Domains
GroupTransparent Tribe

Transparent Tribe has registered domains to mimic file sharing, government, defense, and research websites for use in targeted campaigns.

T1583.001
Domains
GroupIndigoZebra

IndigoZebra has established domains, some of which were designed to look like official government domains, for their operations.

T1583.001
Domains
GroupMoonstone Sleet

Moonstone Sleet registered domains to develop effective personas for fake companies used in phishing activity.

T1583.001
Domains
GroupVOID MANTICORE

VOID MANTICORE has registered domains for messaging purposes. VOID MANTICORE has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion. VOID MANTICORE has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex. VOID MANTICORE has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations.

T1583.001
Domains
GroupHEXANE

HEXANE has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization.

T1583.001
Domains
GroupWIRTE

WIRTE has registered domains designed to mimic legitimate sites for use in phishing campaigns.

T1583.001
Domains
GroupMagic Hound

Magic Hound has registered fraudulent domains such as "mail-newyorker.com" and "news12.com.recover-session-service.site" to target specific victims with phishing attacks.

T1583.001
Domains
GroupThreat Group-3390

Threat Group-3390 has registered domains for C2.

T1583.001
Domains
MalwareRaspberry Robin

Raspberry Robin uses newly-registered domains containing only a few characters for command and controll purposes, such as "v0[.]cx".

T1583.001
Domains
MalwareDarkGate

DarkGate command and control includes hard-coded domains in the malware chosen to masquerade as legitimate services such as Akamai CDN or Amazon Web Services.

T1583.001
Domains
MalwareXLoader

XLoader can utilize hardcoded command and control domain configurations created by the XLoader authors. These are designed to mimic domain registrars and hosting service providers such as Hostinger and Namecheap.

T1583.001
Domains
GroupTeamPCP

TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data.

T1583.001
Domains
GroupShinyHunters

ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data. Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com.

T1583.002
DNS Server
GroupSea Turtle

Sea Turtle built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials.

T1583.002
DNS Server
GroupAxiom

Axiom has acquired dynamic DNS services for use in the targeting of intended victims.

T1583.002
DNS Server
GroupHEXANE

HEXANE has set up custom DNS servers to send commands to compromised hosts via TXT records.

T1583.003
Virtual Private Server
CampaignKV Botnet Activity

KV Botnet Activity used acquired Virtual Private Servers as control systems for devices infected with KV Botnet malware.

T1583.003
Virtual Private Server
CampaignJ-magic Campaign

During the J-magic Campaign, threat actors acquired VPS for use in C2.

T1583.003
Virtual Private Server
CampaignC0032

During the C0032 campaign, TEMP.Veles used Virtual Private Server (VPS) infrastructure.

T1583.003
Virtual Private Server
CampaignSPACEHOP Activity

SPACEHOP Activity has used acquired Virtual Private Servers as control systems for devices within the ORB network.

T1583.003
Virtual Private Server
CampaignArcaneDoor

ArcaneDoor included the use of dedicated, adversary-controlled virtual private servers for command and control.

T1583.003
Virtual Private Server
CampaignFLORAHOX Activity

FLORAHOX Activity has used acquired Virtual Private Servers as control systems for the ORB network.

T1583.003
Virtual Private Server
GroupBlackByte

BlackByte staged encryption keys on virtual private servers operated by the adversary.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.