Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1584.004 Server |
GroupDaggerfly | Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion. |
| T1584.005 Botnet |
CampaignQuad7 Activity | Quad7 Activity has compromised various branded SOHO routers to form a botnet that has been leveraged in password spraying activity. |
| T1584.005 Botnet |
GroupVolt Typhoon | Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations. |
| T1584.005 Botnet |
GroupHAFNIUM | HAFNIUM has used compromised devices in covert networks to obfuscate communications. |
| T1584.005 Botnet |
GroupSandworm Team | Sandworm Team has used a large-scale botnet to target Small Office/Home Office (SOHO) network devices. |
| T1584.005 Botnet |
GroupAxiom | Axiom has used large groups of compromised machines for use as proxy nodes. |
| T1584.005 Botnet |
GroupAPT-C-36 | APT-C-36 has used a botnet management interface to control large numbers of compromised hosts. |
| T1584.006 Web Services |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors abused compromised AWS buckets to store files. |
| T1584.006 Web Services |
GroupCURIUM | CURIUM has compromised legitimate websites to enable strategic website compromise attacks. |
| T1584.006 Web Services |
GroupWinter Vivern | Winter Vivern has used compromised WordPress sites to host malicious payloads for download. |
| T1584.006 Web Services |
GroupTurla | Turla has frequently used compromised WordPress sites for C2 infrastructure. |
| T1584.006 Web Services |
GroupEarth Lusca | Earth Lusca has compromised Google Drive repositories. |
| T1584.006 Web Services |
MalwareGootloader | Gootloader can insert malicious scripts to compromise vulnerable content management systems (CMS). |
| T1584.008 Network Devices |
CampaignKV Botnet Activity | KV Botnet Activity focuses on compromise of small office-home office (SOHO) network devices to build the subsequent botnet. |
| T1584.008 Network Devices |
CampaignCutting Edge | During Cutting Edge, threat actors used compromised and out-of-support Cyberoam VPN appliances for C2. |
| T1584.008 Network Devices |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries used compromised Cisco routers for network communications. |
| T1584.008 Network Devices |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used compromised small office/home office (SOHO) devices to interact with vulnerable Versa Director servers. |
| T1584.008 Network Devices |
CampaignQuad7 Activity | Quad7 Activity has compromised network devices, such as IP cameras, Network Attached Storage (NAS) devices, and SOHO routers, to leverage for follow-on activity. |
| T1584.008 Network Devices |
CampaignFLORAHOX Activity | FLORAHOX Activity has compromised network routers and IoT devices for the ORB network. |
| T1584.008 Network Devices |
GroupVolt Typhoon | Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic. |
| T1584.008 Network Devices |
GroupZIRCONIUM | ZIRCONIUM has compromised network devices such as small office and home office (SOHO) routers and IoT devices for ORB (operational relay box) Proxy networks. |
| T1584.008 Network Devices |
GroupLeviathan | Leviathan has used compromised networking devices, such as small office/home office (SOHO) devices, as operational command and control infrastructure. |
| T1584.008 Network Devices |
GroupAPT28 | APT28 compromised Ubiquiti network devices to act as collection devices for credentials compromised via phishing webpages. |
| T1585 Establish Accounts |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors created Salesforce trial accounts to register their malicious applications. |
| T1585 Establish Accounts |
GroupAPT17 | APT17 has created and cultivated profile pages in Microsoft TechNet. To make profile pages appear more legitimate, APT17 has created biographical sections and posted in forum threads. |
| T1585 Establish Accounts |
GroupKimsuky | Kimsuky has leveraged stolen PII to create accounts. |
| T1585 Establish Accounts |
GroupContagious Interview | Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1585 Establish Accounts |
GroupEmber Bear | Ember Bear has created accounts on dark web forums to obtain various tools and malware. |
| T1585 Establish Accounts |
GroupFox Kitten | Fox Kitten has created KeyBase accounts to communicate with ransomware victims. |
| T1585.001 Social Media Accounts |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group created fake LinkedIn accounts for their targeting efforts. |
| T1585.001 Social Media Accounts |
CampaignOperation Ghost | For Operation Ghost, APT29 registered Twitter accounts to host C2 nodes. |
| T1585.001 Social Media Accounts |
GroupKimsuky | Kimsuky has created social media accounts to monitor news and security trends as well as potential targets. |
| T1585.001 Social Media Accounts |
GroupEXOTIC LILY | EXOTIC LILY has established social media profiles to mimic employees of targeted companies. |
| T1585.001 Social Media Accounts |
GroupAPT32 | APT32 has set up Facebook pages in tandem with fake websites. |
| T1585.001 Social Media Accounts |
GroupSandworm Team | Sandworm Team has established social media accounts to disseminate victim internal-only documents and other sensitive data. |
| T1585.001 Social Media Accounts |
GroupCURIUM | CURIUM has established a network of fictitious social media accounts, including on Facebook and LinkedIn, to establish relationships with victims, often posing as an attractive woman. |
| T1585.001 Social Media Accounts |
GroupScattered Spider | Scattered Spider has created matching fake social media profiles to support new accounts created in victim environments. |
| T1585.001 Social Media Accounts |
GroupContagious Interview | Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts. ESET Contagious Interview BeaverTail InvisibleFerret February 2025PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1585.001 Social Media Accounts |
GroupLeviathan | Leviathan has created new social media accounts for targeting efforts. |
| T1585.001 Social Media Accounts |
GroupCleaver | Cleaver has created fake LinkedIn profiles that included profile photos, details, and connections. |
| T1585.001 Social Media Accounts |
GroupMedusa Group | Medusa Group has created social media accounts including Telegram and X to publicize their activities. |
| T1585.001 Social Media Accounts |
GroupStar Blizzard | Star Blizzard has established fraudulent profiles on professional networking sites to conduct reconnaissance. |
| T1585.001 Social Media Accounts |
GroupWater Galura | Water Galura operates a news channel on Telegram to make announcements for the Qilin RaaS. |
| T1585.001 Social Media Accounts |
GroupFox Kitten | Fox Kitten has used a Twitter account to communicate with ransomware victims. |
| T1585.001 Social Media Accounts |
GroupLazarus Group | Lazarus Group has created new Twitter accounts to conduct social engineering against potential victims. |
| T1585.001 Social Media Accounts |
GroupMoonstone Sleet | Moonstone Sleet has created social media accounts to interact with victims. |
| T1585.001 Social Media Accounts |
GroupVOID MANTICORE | VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures. |
| T1585.001 Social Media Accounts |
GroupHEXANE | HEXANE has established fraudulent LinkedIn accounts impersonating HR department employees to target potential victims with fake job offers. |
| T1585.001 Social Media Accounts |
GroupMagic Hound | Magic Hound has created fake LinkedIn and other social media accounts to contact targets and convince them--through messages and voice communications--to open malicious links. |
| T1585.001 Social Media Accounts |
GroupTeamPCP | TeamPCP has used its own Telegram channel and X accounts @pcpcats and @xploitrsturtle2 for external communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.