Real-world descriptions of how a group, tool or campaign used a technique.
12 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1199 Trusted Relationship |
GroupmenuPass | menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest. |
| T1199 Trusted Relationship |
GroupHAFNIUM | HAFNIUM has used stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to access downstream customer environments. |
| T1199 Trusted Relationship |
GroupSandworm Team | Sandworm Team has used dedicated network connections from one victim organization to gain unauthorized access to a separate organization. Additionally, Sandworm Team has accessed Internet service providers and telecommunication entities that provide mobile connectivity. |
| T1199 Trusted Relationship |
GroupSea Turtle | Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers. |
| T1199 Trusted Relationship |
GroupPOLONIUM | POLONIUM has used compromised credentials from an IT company to target downstream customers including a law firm and aviation company. |
| T1199 Trusted Relationship |
GroupRedCurl | RedCurl has gained access to a contractor to pivot to the victim’s infrastructure. |
| T1199 Trusted Relationship |
GroupAPT29 | APT29 has compromised IT, cloud services, and managed services providers to gain broad access to multiple customers for subsequent operations. |
| T1199 Trusted Relationship |
GroupAPT28 | Once APT28 gained access to the DCCC network, the group then proceeded to use that access to compromise the DNC network. |
| T1199 Trusted Relationship |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has breached Managed Service Providers (MSP's) to deliver malware to MSP customers. |
| T1199 Trusted Relationship |
GroupLAPSUS$ | LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations. |
| T1199 Trusted Relationship |
GroupVOID MANTICORE | VOID MANTICORE has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access. |
| T1199 Trusted Relationship |
GroupThreat Group-3390 | Threat Group-3390 has compromised third party service providers to gain access to victim's environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.