Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583 Acquire Infrastructure |
GroupIndrik Spider | Indrik Spider has purchased access to victim VPNs to facilitate access to victim environments. |
| T1583 Acquire Infrastructure |
GroupKimsuky | Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure. |
| T1583 Acquire Infrastructure |
GroupSandworm Team | Sandworm Team used various third-party email campaign management services to deliver phishing emails. |
| T1583 Acquire Infrastructure |
GroupContagious Interview | Contagious Interview has used services such as Astrill VPN. |
| T1583 Acquire Infrastructure |
GroupSea Turtle | Sea Turtle accessed victim networks from VPN service provider networks. |
| T1583 Acquire Infrastructure |
GroupStar Blizzard | Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails. |
| T1583 Acquire Infrastructure |
GroupEmber Bear | Ember Bear uses services such as IVPN, SurfShark, and Tor to add anonymization to operations. |
| T1583 Acquire Infrastructure |
GroupAgrius | Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN. |
| T1583 Acquire Infrastructure |
GroupTeamPCP | In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.