ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1199×

12 examples

TechniqueUsed byProcedure example
T1199
Trusted Relationship
GroupmenuPass

menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest.

T1199
Trusted Relationship
GroupHAFNIUM

HAFNIUM has used stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to access downstream customer environments.

T1199
Trusted Relationship
GroupSandworm Team

Sandworm Team has used dedicated network connections from one victim organization to gain unauthorized access to a separate organization. Additionally, Sandworm Team has accessed Internet service providers and telecommunication entities that provide mobile connectivity.

T1199
Trusted Relationship
GroupSea Turtle

Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers.

T1199
Trusted Relationship
GroupPOLONIUM

POLONIUM has used compromised credentials from an IT company to target downstream customers including a law firm and aviation company.

T1199
Trusted Relationship
GroupRedCurl

RedCurl has gained access to a contractor to pivot to the victim’s infrastructure.

T1199
Trusted Relationship
GroupAPT29

APT29 has compromised IT, cloud services, and managed services providers to gain broad access to multiple customers for subsequent operations.

T1199
Trusted Relationship
GroupAPT28

Once APT28 gained access to the DCCC network, the group then proceeded to use that access to compromise the DNC network.

T1199
Trusted Relationship
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has breached Managed Service Providers (MSP's) to deliver malware to MSP customers.

T1199
Trusted Relationship
GroupLAPSUS$

LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations.

T1199
Trusted Relationship
GroupVOID MANTICORE

VOID MANTICORE has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access.

T1199
Trusted Relationship
GroupThreat Group-3390

Threat Group-3390 has compromised third party service providers to gain access to victim's environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.