Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1589 Gather Victim Identity Information |
GroupVolt Typhoon | Volt Typhoon has gathered victim identify information during pre-compromise reconnaissance. |
| T1589 Gather Victim Identity Information |
GroupAPT32 | APT32 has conducted targeted surveillance against activists and bloggers. |
| T1589 Gather Victim Identity Information |
GroupScattered Spider | Scattered Spider has used information from previous data breaches to identify employee names to be used in social engineering. |
| T1589 Gather Victim Identity Information |
GroupContagious Interview | Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Securonix Contagious Interview DEVPOPPER April 2024Sekoia ClickFake 2025Sentinel One Contagious Interview ClickFix September 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1589 Gather Victim Identity Information |
GroupStar Blizzard | Star Blizzard has identified ways to engage targets by researching potential victims' interests and social or professional contacts. |
| T1589 Gather Victim Identity Information |
GroupLAPSUS$ | LAPSUS$ has gathered detailed information of target employees to enhance their social engineering lures. |
| T1589 Gather Victim Identity Information |
GroupVOID MANTICORE | VOID MANTICORE has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks. |
| T1589 Gather Victim Identity Information |
GroupHEXANE | HEXANE has identified specific potential victims at targeted organizations. |
| T1589 Gather Victim Identity Information |
GroupMagic Hound | Magic Hound has acquired mobile phone numbers of potential targets, possibly for mobile malware or additional phishing operations. |
| T1589 Gather Victim Identity Information |
GroupFIN13 | FIN13 has researched employees to target for social engineering attacks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.