Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.001 Domains |
GroupStorm-1811 | Storm-1811 has created domains for use with RMM tools. |
| T1583.001 Domains |
GroupTeamTNT | TeamTNT has obtained domains to host their payloads. |
| T1583.001 Domains |
GroupFIN7 | FIN7 has registered look-alike domains for use in phishing campaigns. Additionally, FIN7 has registered a malicious domain as `advanced-ip-sccanner[.]com` that redirected to an adversary-controlled Dropbox which contained the malicious executable. |
| T1583.001 Domains |
GroupSandworm Team | Sandworm Team has registered domain names and created URLs that are often designed to mimic or spoof legitimate websites, such as email login pages, online file sharing and storage websites, and password reset pages, while also hosting these items on legitimate, compromised network infrastructure. |
| T1583.001 Domains |
GroupCURIUM | CURIUM created domains to facilitate strategic website compromise and credential capture activities. |
| T1583.001 Domains |
GroupMustang Panda | Mustang Panda has acquired C2 domains prior to operations. CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023McAfee Dianxun March 2021Palo Alto Networks, Unit 42Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015 |
| T1583.001 Domains |
GroupZIRCONIUM | ZIRCONIUM has purchased domains for use in targeted campaigns. |
| T1583.001 Domains |
GroupScattered Spider | Scattered Spider has registered domains to spoof legitimate corporate login portals. |
| T1583.001 Domains |
GroupContagious Interview | Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2. ESET Contagious Interview BeaverTail InvisibleFerret February 2025PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Sekoia ClickFake 2025Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1583.001 Domains |
GroupTA2541 | TA2541 has registered domains often containing the keywords “kimjoy,” “h0pe,” and “grace,” using domain registrars including Netdorm and No-IP DDNS, and hosting providers including xTom GmbH and Danilenko, Artyom. |
| T1583.001 Domains |
GroupOilRig | OilRig has set up fake VPN portals, conference sign ups, and job application websites to target victims. |
| T1583.001 Domains |
GroupSea Turtle | Sea Turtle registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers. |
| T1583.001 Domains |
GroupFerocious Kitten | Ferocious Kitten has acquired domains imitating legitimate sites. |
| T1583.001 Domains |
GroupAPT1 | APT1 has registered hundreds of domains for use in operations. |
| T1583.001 Domains |
GroupLeviathan | Leviathan has established domains that impersonate legitimate entities to use for targeting efforts. |
| T1583.001 Domains |
GroupWinter Vivern | Winter Vivern registered domains mimicking other entities throughout various campaigns. |
| T1583.001 Domains |
GroupTA505 | TA505 has registered domains to impersonate services such as Dropbox to distribute malware. |
| T1583.001 Domains |
GroupBITTER | BITTER has registered a variety of domains to host malicious payloads and for C2. |
| T1583.001 Domains |
GroupSilent Librarian | Silent Librarian has acquired domains to establish credential harvesting pages, often spoofing the target organization and using free top level domains .TK, .ML, .GA, .CF, and .GQ. |
| T1583.001 Domains |
GroupStar Blizzard | Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations. |
| T1583.001 Domains |
GroupLazyScripter | LazyScripter has used dynamic DNS providers to create legitimate-looking subdomains for C2. |
| T1583.001 Domains |
GroupAPT28 | APT28 registered domains imitating NATO, OSCE security websites, Caucasus information resources, and other organizations. |
| T1583.001 Domains |
GroupAPT42 | APT42 has registered domains, several of which masqueraded as news outlets and login services, for use in operations. |
| T1583.001 Domains |
GroupAPT-C-36 | APT-C-36 has acquired domains to host malicious payloads. |
| T1583.001 Domains |
GroupWinnti Group | Winnti Group has registered domains for C2 that mimicked sites of their intended targets. |
| T1583.001 Domains |
GroupLazarus Group | Lazarus Group has acquired domains related to their campaigns to act as distribution points and C2 channels. |
| T1583.001 Domains |
GroupEarth Lusca | Earth Lusca has registered domains, intended to look like legitimate target domains, that have been used in watering hole attacks. |
| T1583.001 Domains |
GroupTransparent Tribe | Transparent Tribe has registered domains to mimic file sharing, government, defense, and research websites for use in targeted campaigns. |
| T1583.001 Domains |
GroupIndigoZebra | IndigoZebra has established domains, some of which were designed to look like official government domains, for their operations. |
| T1583.001 Domains |
GroupMoonstone Sleet | Moonstone Sleet registered domains to develop effective personas for fake companies used in phishing activity. |
| T1583.001 Domains |
GroupVOID MANTICORE | VOID MANTICORE has registered domains for messaging purposes. VOID MANTICORE has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion. VOID MANTICORE has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex. VOID MANTICORE has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations. |
| T1583.001 Domains |
GroupHEXANE | HEXANE has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization. |
| T1583.001 Domains |
GroupWIRTE | WIRTE has registered domains designed to mimic legitimate sites for use in phishing campaigns. |
| T1583.001 Domains |
GroupMagic Hound | Magic Hound has registered fraudulent domains such as "mail-newyorker.com" and "news12.com.recover-session-service.site" to target specific victims with phishing attacks. |
| T1583.001 Domains |
GroupThreat Group-3390 | Threat Group-3390 has registered domains for C2. |
| T1583.001 Domains |
MalwareRaspberry Robin | Raspberry Robin uses newly-registered domains containing only a few characters for command and controll purposes, such as " |
| T1583.001 Domains |
MalwareDarkGate | DarkGate command and control includes hard-coded domains in the malware chosen to masquerade as legitimate services such as Akamai CDN or Amazon Web Services. |
| T1583.001 Domains |
MalwareXLoader | XLoader can utilize hardcoded command and control domain configurations created by the XLoader authors. These are designed to mimic domain registrars and hosting service providers such as Hostinger and Namecheap. |
| T1583.001 Domains |
GroupTeamPCP | TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data. |
| T1583.001 Domains |
GroupShinyHunters | ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data. Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com. |
| T1583.002 DNS Server |
GroupSea Turtle | Sea Turtle built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials. |
| T1583.002 DNS Server |
GroupAxiom | Axiom has acquired dynamic DNS services for use in the targeting of intended victims. |
| T1583.002 DNS Server |
GroupHEXANE | HEXANE has set up custom DNS servers to send commands to compromised hosts via TXT records. |
| T1583.003 Virtual Private Server |
CampaignKV Botnet Activity | KV Botnet Activity used acquired Virtual Private Servers as control systems for devices infected with KV Botnet malware. |
| T1583.003 Virtual Private Server |
CampaignJ-magic Campaign | During the J-magic Campaign, threat actors acquired VPS for use in C2. |
| T1583.003 Virtual Private Server |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used Virtual Private Server (VPS) infrastructure. |
| T1583.003 Virtual Private Server |
CampaignSPACEHOP Activity | SPACEHOP Activity has used acquired Virtual Private Servers as control systems for devices within the ORB network. |
| T1583.003 Virtual Private Server |
CampaignArcaneDoor | ArcaneDoor included the use of dedicated, adversary-controlled virtual private servers for command and control. |
| T1583.003 Virtual Private Server |
CampaignFLORAHOX Activity | FLORAHOX Activity has used acquired Virtual Private Servers as control systems for the ORB network. |
| T1583.003 Virtual Private Server |
GroupBlackByte | BlackByte staged encryption keys on virtual private servers operated by the adversary. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.