Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1068 Exploitation for Privilege Escalation |
GroupBlackByte | BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupVolt Typhoon | Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT32 | APT32 has used CVE-2016-7255 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupHAFNIUM | HAFNIUM has targeted unpatched applications to elevate access in targeted organizations. |
| T1068 Exploitation for Privilege Escalation |
GroupFIN6 | FIN6 has used tools to exploit Windows vulnerabilities in order to escalate privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupZIRCONIUM | ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupScattered Spider | Scattered Spider has deployed a malicious kernel driver through exploitation of CVE-2015-2291 in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys). |
| T1068 Exploitation for Privilege Escalation |
GroupUNC3886 | UNC3886 has exploited zero-day vulnerability CVE-2023-20867 to enable execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs. |
| T1068 Exploitation for Privilege Escalation |
GroupOilRig | OilRig has exploited the Windows Kernel Elevation of Privilege vulnerability, CVE-2024-30088. |
| T1068 Exploitation for Privilege Escalation |
GroupMoustachedBouncer | MoustachedBouncer has exploited CVE-2021-1732 to execute malware components with elevated rights. |
| T1068 Exploitation for Privilege Escalation |
GroupTurla | Turla has exploited vulnerabilities in the VBoxDrv.sys driver to obtain kernel mode privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupBITTER | BITTER has exploited CVE-2021-1732 for privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT29 | APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host. |
| T1068 Exploitation for Privilege Escalation |
GroupWhitefly | Whitefly has used an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT28 | APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupTonto Team | Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupLAPSUS$ | LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupCobalt Group | Cobalt Group has used exploits to increase their levels of rights and privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupPLATINUM | PLATINUM has leveraged a zero-day vulnerability to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupThreat Group-3390 | Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT33 | APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system. |
| T1068 Exploitation for Privilege Escalation |
GroupFIN8 | FIN8 has exploited the CVE-2016-0167 local vulnerability. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.