ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1583.006
Web Services
GroupAPT29

APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations.

T1583.006
Web Services
GroupMedusa Group

Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions.

T1583.006
Web Services
GroupTA578

TA578 has used Google Firebase to host malicious scripts.

T1583.006
Web Services
GroupLazyScripter

LazyScripter has established GitHub accounts to host its toolsets.

T1583.006
Web Services
GroupAPT28

APT28 has used newly-created Blogspot pages for credential harvesting operations.

T1583.006
Web Services
GroupAPT-C-36

APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox.

T1583.006
Web Services
GroupLazarus Group

Lazarus Group has hosted malicious downloads on Github.

T1583.006
Web Services
GroupEarth Lusca

Earth Lusca has established GitHub accounts to host their malware.

T1583.006
Web Services
GroupIndigoZebra

IndigoZebra created Dropbox accounts for their operations.

T1583.006
Web Services
GroupVOID MANTICORE

VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure.

T1583.006
Web Services
GroupMagic Hound

Magic Hound has acquired Amazon S3 buckets to use in C2.

T1583.006
Web Services
GroupTeamPCP

TeamPCP has set up Clouflare Tunnels for malware C2. TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via  *.getsession[.]org to recipient  ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`.

T1583.007
Serverless
CampaignAPT41 DUST

APT41 DUST used infrastructure hosted behind Cloudflare or utilized Cloudflare Workers for command and control.

T1583.008
Malvertising
GroupMustard Tempest

Mustard Tempest has posted false advertisements including for software packages and browser updates in order to distribute malware.

T1583.008
Malvertising
MalwareRaspberry Robin

Raspberry Robin variants have been delivered via malicious advertising items that, when interacted with, download a malicious archive file containing the initial payload, hosted on services such as Discord.

T1584
Compromise Infrastructure
CampaignIndian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions included the use of compromised infrastructure, such as DVR and IP camera devices, for command and control purposes in ShadowPad activity.

T1584
Compromise Infrastructure
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 compromised third-party infrastructure in physical proximity to targets of interest for follow-on activities.

T1584.001
Domains
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure.

T1584.001
Domains
CampaignC0021

For C0021, the threat actors used legitimate but compromised domains to host malicious payloads.

T1584.001
Domains
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 compromised domains to use for C2.

T1584.001
Domains
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compromised infrastructure to use for C2.

T1584.001
Domains
CampaignC0010

During C0010, UNC3890 actors likely compromised the domain of a legitimate Israeli shipping company.

T1584.001
Domains
GroupSideCopy

SideCopy has compromised domains for some of their infrastructure, including for C2 and staging malware.

T1584.001
Domains
GroupMustard Tempest

Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page.

T1584.001
Domains
GroupKimsuky

Kimsuky has compromised legitimate sites and used them to distribute malware.

T1584.001
Domains
GroupAPT1

APT1 hijacked FQDNs associated with legitimate websites hosted by hop points.

T1584.001
Domains
GroupTransparent Tribe

Transparent Tribe has compromised domains for use in targeted malicious campaigns.

T1584.001
Domains
GroupMagic Hound

Magic Hound has used compromised domains to host links targeted to specific phishing victims.

T1584.001
Domains
MalwareGootloader

Gootloader has used compromised legitimate domains to as a delivery network for malicious payloads.

T1584.002
DNS Server
GroupSea Turtle

Sea Turtle modified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers to provide responses for all DNS lookups.

T1584.002
DNS Server
GroupLAPSUS$

LAPSUS$ has reconfigured a victim's DNS records to actor-controlled domains and websites.

T1584.003
Virtual Private Server
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors abused Virtual Private Servers to store malicious files.

T1584.003
Virtual Private Server
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries used compromised VPS servers for C2.

T1584.003
Virtual Private Server
GroupVolt Typhoon

Volt Typhoon has compromised Virtual Private Servers (VPS) to proxy C2 traffic.

T1584.003
Virtual Private Server
GroupTurla

Turla has used the VPS infrastructure of compromised Iranian threat actors.

T1584.004
Server
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools.

T1584.004
Server
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors compromised a server they used as part of the campaign's infrastructure.

T1584.004
Server
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary operated dedicated penetration testing servers accessible via MCP to support remote command execution, simultaneous tool coordination, and persistent operational state maintenance across campaign sessions.

T1584.004
Server
CampaignJuicy Mix

During Juicy Mix, OilRig compromised an Israeli job portal to use for a C2 server.

T1584.004
Server
CampaignOuter Space

During Outer Space, OilRig compromised an Israeli human resources site to use as a C2 server.

T1584.004
Server
CampaignNight Dragon

During Night Dragon, threat actors compromised web servers to use for C2.

T1584.004
Server
GroupIndrik Spider

Indrik Spider has served fake updates via legitimate websites that have been compromised.

T1584.004
Server
GroupVolt Typhoon

Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2.

T1584.004
Server
GroupDragonfly

Dragonfly has compromised legitimate websites to host C2 and malware modules.

T1584.004
Server
GroupSandworm Team

Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns.

T1584.004
Server
GroupLeviathan

Leviathan has used compromised legitimate websites as command and control nodes for operations.

T1584.004
Server
GroupTurla

Turla has used compromised servers as infrastructure.

T1584.004
Server
GroupLazarus Group

Lazarus Group has compromised servers to stage malicious tools.

T1584.004
Server
GroupEarth Lusca

Earth Lusca has used compromised web servers as part of their operational infrastructure.

T1584.004
Server
GroupAPT16

APT16 has compromised otherwise legitimate sites as staging servers for second-stage payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.