ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1584.004
Server
GroupDaggerfly

Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion.

T1584.005
Botnet
CampaignQuad7 Activity

Quad7 Activity has compromised various branded SOHO routers to form a botnet that has been leveraged in password spraying activity.

T1584.005
Botnet
GroupVolt Typhoon

Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations.

T1584.005
Botnet
GroupHAFNIUM

HAFNIUM has used compromised devices in covert networks to obfuscate communications.

T1584.005
Botnet
GroupSandworm Team

Sandworm Team has used a large-scale botnet to target Small Office/Home Office (SOHO) network devices.

T1584.005
Botnet
GroupAxiom

Axiom has used large groups of compromised machines for use as proxy nodes.

T1584.005
Botnet
GroupAPT-C-36

APT-C-36 has used a botnet management interface to control large numbers of compromised hosts.

T1584.006
Web Services
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors abused compromised AWS buckets to store files.

T1584.006
Web Services
GroupCURIUM

CURIUM has compromised legitimate websites to enable strategic website compromise attacks.

T1584.006
Web Services
GroupWinter Vivern

Winter Vivern has used compromised WordPress sites to host malicious payloads for download.

T1584.006
Web Services
GroupTurla

Turla has frequently used compromised WordPress sites for C2 infrastructure.

T1584.006
Web Services
GroupEarth Lusca

Earth Lusca has compromised Google Drive repositories.

T1584.006
Web Services
MalwareGootloader

Gootloader can insert malicious scripts to compromise vulnerable content management systems (CMS).

T1584.008
Network Devices
CampaignKV Botnet Activity

KV Botnet Activity focuses on compromise of small office-home office (SOHO) network devices to build the subsequent botnet.

T1584.008
Network Devices
CampaignCutting Edge

During Cutting Edge, threat actors used compromised and out-of-support Cyberoam VPN appliances for C2.

T1584.008
Network Devices
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries used compromised Cisco routers for network communications.

T1584.008
Network Devices
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation used compromised small office/home office (SOHO) devices to interact with vulnerable Versa Director servers.

T1584.008
Network Devices
CampaignQuad7 Activity

Quad7 Activity has compromised network devices, such as IP cameras, Network Attached Storage (NAS) devices, and SOHO routers, to leverage for follow-on activity.

T1584.008
Network Devices
CampaignFLORAHOX Activity

FLORAHOX Activity has compromised network routers and IoT devices for the ORB network.

T1584.008
Network Devices
GroupVolt Typhoon

Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic.

T1584.008
Network Devices
GroupZIRCONIUM

ZIRCONIUM has compromised network devices such as small office and home office (SOHO) routers and IoT devices for ORB (operational relay box) Proxy networks.

T1584.008
Network Devices
GroupLeviathan

Leviathan has used compromised networking devices, such as small office/home office (SOHO) devices, as operational command and control infrastructure.

T1584.008
Network Devices
GroupAPT28

APT28 compromised Ubiquiti network devices to act as collection devices for credentials compromised via phishing webpages.

T1585
Establish Accounts
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors created Salesforce trial accounts to register their malicious applications.

T1585
Establish Accounts
GroupAPT17

APT17 has created and cultivated profile pages in Microsoft TechNet. To make profile pages appear more legitimate, APT17 has created biographical sections and posted in forum threads.

T1585
Establish Accounts
GroupKimsuky

Kimsuky has leveraged stolen PII to create accounts.

T1585
Establish Accounts
GroupContagious Interview

Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads.

T1585
Establish Accounts
GroupEmber Bear

Ember Bear has created accounts on dark web forums to obtain various tools and malware.

T1585
Establish Accounts
GroupFox Kitten

Fox Kitten has created KeyBase accounts to communicate with ransomware victims.

T1585.001
Social Media Accounts
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group created fake LinkedIn accounts for their targeting efforts.

T1585.001
Social Media Accounts
CampaignOperation Ghost

For Operation Ghost, APT29 registered Twitter accounts to host C2 nodes.

T1585.001
Social Media Accounts
GroupKimsuky

Kimsuky has created social media accounts to monitor news and security trends as well as potential targets.

T1585.001
Social Media Accounts
GroupEXOTIC LILY

EXOTIC LILY has established social media profiles to mimic employees of targeted companies.

T1585.001
Social Media Accounts
GroupAPT32

APT32 has set up Facebook pages in tandem with fake websites.

T1585.001
Social Media Accounts
GroupSandworm Team

Sandworm Team has established social media accounts to disseminate victim internal-only documents and other sensitive data.

T1585.001
Social Media Accounts
GroupCURIUM

CURIUM has established a network of fictitious social media accounts, including on Facebook and LinkedIn, to establish relationships with victims, often posing as an attractive woman.

T1585.001
Social Media Accounts
GroupScattered Spider

Scattered Spider has created matching fake social media profiles to support new accounts created in victim environments.

T1585.001
Social Media Accounts
GroupContagious Interview

Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts.

T1585.001
Social Media Accounts
GroupLeviathan

Leviathan has created new social media accounts for targeting efforts.

T1585.001
Social Media Accounts
GroupCleaver

Cleaver has created fake LinkedIn profiles that included profile photos, details, and connections.

T1585.001
Social Media Accounts
GroupMedusa Group

Medusa Group has created social media accounts including Telegram and X to publicize their activities.

T1585.001
Social Media Accounts
GroupStar Blizzard

Star Blizzard has established fraudulent profiles on professional networking sites to conduct reconnaissance.

T1585.001
Social Media Accounts
GroupWater Galura

Water Galura operates a news channel on Telegram to make announcements for the Qilin RaaS.

T1585.001
Social Media Accounts
GroupFox Kitten

Fox Kitten has used a Twitter account to communicate with ransomware victims.

T1585.001
Social Media Accounts
GroupLazarus Group

Lazarus Group has created new Twitter accounts to conduct social engineering against potential victims.

T1585.001
Social Media Accounts
GroupMoonstone Sleet

Moonstone Sleet has created social media accounts to interact with victims.

T1585.001
Social Media Accounts
GroupVOID MANTICORE

VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures.

T1585.001
Social Media Accounts
GroupHEXANE

HEXANE has established fraudulent LinkedIn accounts impersonating HR department employees to target potential victims with fake job offers.

T1585.001
Social Media Accounts
GroupMagic Hound

Magic Hound has created fake LinkedIn and other social media accounts to contact targets and convince them--through messages and voice communications--to open malicious links.

T1585.001
Social Media Accounts
GroupTeamPCP

TeamPCP has used its own Telegram channel and X accounts @pcpcats and @xploitrsturtle2 for external communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.