ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1133×

10 examples

TechniqueUsed byProcedure example
T1133
External Remote Services
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a modified Dropbear SSH client as the backdoor to target systems.

T1133
External Remote Services
CampaignC0032

During the C0032 campaign, TEMP.Veles used VPN access to persist in the victim environment.

T1133
External Remote Services
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 used compromised identities to access networks via SSH, VPNs, and other remote access tools.

T1133
External Remote Services
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors enabled WinRM over HTTP/HTTPS as a backup persistence mechanism using the following command: `cscript //nologo "C:\Windows\System32\winrm.vbs" set winrm/config/service@{EnableCompatibilityHttpsListener="true"}`.

T1133
External Remote Services
CampaignArcaneDoor

ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices.

T1133
External Remote Services
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, threat actors leveraged the FortiGate VPN interface that was exposed to the internet to gain access to the victim environment.

T1133
External Remote Services
CampaignNight Dragon

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.

T1133
External Remote Services
CampaignOperation Wocao

During Operation Wocao, threat actors used stolen credentials to connect to the victim's network via VPN.

T1133
External Remote Services
CampaignC0027

During C0027, Scattered Spider used Citrix and VPNs to persist in compromised environments.

T1133
External Remote Services
CampaignCostaRicto

During CostaRicto, the threat actors set up remote tunneling using an SSH tool to maintain access to a compromised environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.