ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1583.003
Virtual Private Server
GroupDragonfly

Dragonfly has acquired VPS infrastructure for use in malicious campaigns.

T1583.003
Virtual Private Server
GroupHAFNIUM

HAFNIUM has operated from leased virtual private servers (VPS) in the United States.

T1583.003
Virtual Private Server
GroupGamaredon Group

Gamaredon Group has used VPS hosting providers for infrastructure outside of Russia.

T1583.003
Virtual Private Server
GroupCURIUM

CURIUM created virtual private server instances to facilitate use of malicious domains and other items.

T1583.003
Virtual Private Server
GroupContagious Interview

Contagious Interview has acquired virtual private servers from services such as Stark Industries Solutions and RouterHosting. Contagious Interview has also utilized hosting providers to include Tier[.]Net, Majestic Hosting, Leaseweb Singapore, and Kaopu Cloud.

T1583.003
Virtual Private Server
GroupSea Turtle

Sea Turtle created adversary-in-the-middle servers to impersonate legitimate services and enable credential capture.

T1583.003
Virtual Private Server
GroupWinter Vivern

Winter Vivern used adversary-owned and -controlled servers to host web vulnerability scanning applications.

T1583.003
Virtual Private Server
GroupAxiom

Axiom has used VPS hosting providers in targeting of intended victims.

T1583.003
Virtual Private Server
GroupEmber Bear

Ember Bear has used virtual private servers (VPSs) to host tools, perform reconnaissance, exploit victim infrastructure, and as a destination for data exfiltration.

T1583.003
Virtual Private Server
GroupAPT28

APT28 hosted phishing domains on free services for brief periods of time during campaigns.

T1583.003
Virtual Private Server
GroupAPT42

APT42 has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment.

T1583.003
Virtual Private Server
GroupAPT-C-36

APT-C-36 has incorporated virtual private servers (VPS) into its operational infrastructure.

T1583.003
Virtual Private Server
GroupLAPSUS$

LAPSUS$ has used VPS hosting providers for infrastructure.

T1583.003
Virtual Private Server
GroupMoonstone Sleet

Moonstone Sleet registered virtual private servers to host payloads for download.

T1583.003
Virtual Private Server
GroupVOID MANTICORE

VOID MANTICORE has utilized VPS solutions for C2.

T1583.004
Server
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group acquired servers to host their malicious tools.

T1583.004
Server
CampaignOperation Honeybee

For Operation Honeybee, at least one identified persona was used to register for a free account for a control server.

T1583.004
Server
CampaignNight Dragon

During Night Dragon, threat actors purchased hosted services to use for C2.

T1583.004
Server
CampaignOperation Wocao

For Operation Wocao, the threat actors purchased servers with Bitcoin to use during the operation.

T1583.004
Server
GroupGALLIUM

GALLIUM has used Taiwan-based servers that appear to be exclusive to GALLIUM.

T1583.004
Server
GroupMustard Tempest

Mustard Tempest has acquired servers to host second-stage payloads that remain active for a period of either days, weeks, or months.

T1583.004
Server
GroupKimsuky

Kimsuky has purchased hosting servers with virtual currency and prepaid cards.

T1583.004
Server
GroupSandworm Team

Sandworm Team has leased servers from resellers instead of leasing infrastructure directly from hosting companies to enable its operations.

T1583.004
Server
GroupCURIUM

CURIUM has created dedicated servers for command and control and exfiltration purposes.

T1583.004
Server
GroupEarth Lusca

Earth Lusca has acquired multiple servers for some of their operations, using each server for a different role.

T1583.004
Server
GroupVOID MANTICORE

VOID MANTICORE has leveraged backend servers within Iran.

T1583.004
Server
GroupTeamPCP

TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982.

T1583.004
Server
GroupShinyHunters

ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files.

T1583.005
Botnet
GroupHAFNIUM

HAFNIUM has incorporated leased devices into covert networks to obfuscate communications.

T1583.005
Botnet
GroupKe3chang

Ke3chang has utilized an ORB (operational relay box) network for reconnaissance and vulnerability exploitation.

T1583.005
Botnet
GroupAPT5

APT5 has acquired a network of compromised systems – specifically an ORB (operational relay box) network – for follow on activities.

T1583.006
Web Services
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used file hosting services like DropBox and OneDrive.

T1583.006
Web Services
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used Dropbox to host lure documents and their first-stage downloader.

T1583.006
Web Services
CampaignArcaneDoor

ArcaneDoor included the use of OpenConnect VPN Server instances for conducting actions on victim devices.

T1583.006
Web Services
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries configured the FortiGate devices to send notifications to an attacker-controlled Slack channel. During the 2025 Poland Wiper Attacks, the adversaries had also staged tools and files on services such as Dropbox and Pastebin.

T1583.006
Web Services
GroupAPT17

APT17 has created profile pages in Microsoft TechNet that were used as C2 infrastructure.

T1583.006
Web Services
GroupKimsuky

Kimsuky has hosted content used for targeting efforts via web services such as Blogspot. Kimsuky has also leveraged Dropbox for hosting payloads and uploading victim system information.

T1583.006
Web Services
GroupAPT32

APT32 has set up Dropbox, Amazon S3, and Google Drive to host malicious downloads.

T1583.006
Web Services
GroupHAFNIUM

HAFNIUM has acquired web services for use in C2 and exfiltration.

T1583.006
Web Services
GroupMuddyWater

MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools.

T1583.006
Web Services
GroupGamaredon Group

Gamaredon Group has used Cloudflare’s TryClouldflare service to obtain C2 nodes.

T1583.006
Web Services
GroupFIN7

FIN7 has set up Amazon S3 buckets to host trojanized digital products.

T1583.006
Web Services
GroupMustang Panda

Mustang Panda has set up Dropbox and Google Drive to host malicious downloads.

T1583.006
Web Services
GroupZIRCONIUM

ZIRCONIUM has used GitHub to host malware linked in spearphishing e-mails.

T1583.006
Web Services
GroupContagious Interview

Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities.

T1583.006
Web Services
GroupTA2541

TA2541 has hosted malicious files on various platforms including Google Drive, OneDrive, Discord, PasteText, ShareText, and GitHub.

T1583.006
Web Services
GroupPOLONIUM

POLONIUM has created and used legitimate Microsoft OneDrive accounts for their operations.

T1583.006
Web Services
GroupSaint Bear

Saint Bear has leveraged the Discord content delivery network to host malicious content for retrieval during initial access operations.

T1583.006
Web Services
GroupConfucius

Confucius has obtained cloud storage service accounts to host stolen data.

T1583.006
Web Services
GroupTurla

Turla has created web accounts including Dropbox and GitHub for C2 and document exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.