ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1190×

21 examples

TechniqueUsed byProcedure example
T1190
Exploit Public-Facing Application
CampaignFrostyGoop Incident

FrostyGoop Incident was likely enabled by the adversary exploiting an unknown vulnerability in an external-facing router.

T1190
Exploit Public-Facing Application
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors exploited authentication bypass and remote code execution vulnerabilities (CVE-2025-49706 and CVE-2025-49704) against on-premises SharePoint servers. This activity was characterized by crafted `POST` requests to the ToolPane endpoint `/_layouts/15/ToolPane.aspx`.

T1190
Exploit Public-Facing Application
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect.

T1190
Exploit Public-Facing Application
CampaignCutting Edge

During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887.

T1190
Exploit Public-Facing Application
CampaignC0018

During C0018, the threat actors exploited VMWare Horizon Unified Access Gateways that were vulnerable to several Log4Shell vulnerabilities, including CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832.

T1190
Exploit Public-Facing Application
CampaignShadowRay

During ShadowRay, threat actors exploited CVE-2023-48022 on publicly exposed Ray servers to steal computing power and to expose sensitive data.

T1190
Exploit Public-Facing Application
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to deploy a custom exploit payload targeting an identified SSRF vulnerability to gain initial access to a targeted environment.

T1190
Exploit Public-Facing Application
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used SQL injection to compromise publicly exposed web and database servers.

T1190
Exploit Public-Facing Application
CampaignHomeLand Justice

For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access.

T1190
Exploit Public-Facing Application
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel to regain access to a network.

T1190
Exploit Public-Facing Application
CampaignSPACEHOP Activity

SPACEHOP Activity has enabled the exploitation of CVE-2022-27518 and CVE-2022-27518 for illegitimate access.

T1190
Exploit Public-Facing Application
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors exploited multiple vulnerabilities in externally facing servers.

T1190
Exploit Public-Facing Application
CampaignArcaneDoor

ArcaneDoor abused WebVPN traffic to targeted devices to achieve unauthorized remote code execution.

T1190
Exploit Public-Facing Application
CampaignNight Dragon

During Night Dragon, threat actors used SQL injection exploits against extranet web servers to gain access.

T1190
Exploit Public-Facing Application
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation involved exploitation of a vulnerability in Versa Director servers, since identified as CVE-2024-39717, for initial access and code execution.

T1190
Exploit Public-Facing Application
CampaignOperation Wocao

During Operation Wocao, threat actors gained initial access by exploiting vulnerabilities in JBoss webservers.

T1190
Exploit Public-Facing Application
CampaignLeviathan Australian Intrusions

Leviathan exploited public-facing web applications and appliances for initial access during Leviathan Australian Intrusions.

T1190
Exploit Public-Facing Application
CampaignC0017

During C0017, APT41 exploited CVE-2021-44207 in the USAHerds application and CVE-2021-44228 in Log4j, as well as other .NET deserialization, SQL injection, and directory traversal vulnerabilities to gain initial access.

T1190
Exploit Public-Facing Application
CampaignC0027

During C0027, Scattered Spider exploited CVE-2021-35464 in the ForgeRock Open Access Management (OpenAM) application server to gain initial access.

T1190
Exploit Public-Facing Application
CampaignQuad7 Activity

Quad7 Activity has enabled the exploitation of vulnerabilities for remote code execution capabilities in SOHO routers including CVE-2023-50224 and CVE-2025-9377 in TP-Link devices.

T1190
Exploit Public-Facing Application
CampaignFLORAHOX Activity

FLORAHOX Activity has exploited and infected vulnerable routers to recruit additional network devices into the ORB.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.