ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1068×

22 examples

TechniqueUsed byProcedure example
T1068
Exploitation for Privilege Escalation
GroupBlackByte

BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupVolt Typhoon

Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services.

T1068
Exploitation for Privilege Escalation
GroupAPT32

APT32 has used CVE-2016-7255 to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupHAFNIUM

HAFNIUM has targeted unpatched applications to elevate access in targeted organizations.

T1068
Exploitation for Privilege Escalation
GroupFIN6

FIN6 has used tools to exploit Windows vulnerabilities in order to escalate privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.

T1068
Exploitation for Privilege Escalation
GroupZIRCONIUM

ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupScattered Spider

Scattered Spider has deployed a malicious kernel driver through exploitation of CVE-2015-2291 in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).

T1068
Exploitation for Privilege Escalation
GroupUNC3886

UNC3886 has exploited zero-day vulnerability CVE-2023-20867 to enable execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs.

T1068
Exploitation for Privilege Escalation
GroupOilRig

OilRig has exploited the Windows Kernel Elevation of Privilege vulnerability, CVE-2024-30088.

T1068
Exploitation for Privilege Escalation
GroupMoustachedBouncer

MoustachedBouncer has exploited CVE-2021-1732 to execute malware components with elevated rights.

T1068
Exploitation for Privilege Escalation
GroupTurla

Turla has exploited vulnerabilities in the VBoxDrv.sys driver to obtain kernel mode privileges.

T1068
Exploitation for Privilege Escalation
GroupBITTER

BITTER has exploited CVE-2021-1732 for privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupAPT29

APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host.

T1068
Exploitation for Privilege Escalation
GroupWhitefly

Whitefly has used an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers.

T1068
Exploitation for Privilege Escalation
GroupAPT28

APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupTonto Team

Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupLAPSUS$

LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupCobalt Group

Cobalt Group has used exploits to increase their levels of rights and privileges.

T1068
Exploitation for Privilege Escalation
GroupPLATINUM

PLATINUM has leveraged a zero-day vulnerability to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupThreat Group-3390

Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupAPT33

APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system.

T1068
Exploitation for Privilege Escalation
GroupFIN8

FIN8 has exploited the CVE-2016-0167 local vulnerability.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.