Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

Threat-Informed Defense

Browse campaigns through a defensive analytic lens.

Use time-bounded intrusion-activity profiles for chronology, evidence, behavior mapping, and resilience lessons.

C0001

Frankenstein (C0001)

A defensive guide to the Enterprise ATT&CK campaign record C0001, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a highly targeted 2019 campaign whose operators assembled multiple unrelated open-source components.

Open profile →
C0002

Night Dragon (C0002)

A defensive guide to the Enterprise ATT&CK campaign record C0002, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an espionage campaign reported against oil, energy, and petrochemical companies and related individuals.

Open profile →
C0004

CostaRicto (C0004)

A defensive guide to the Enterprise ATT&CK campaign record C0004, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a suspected hacker-for-hire espionage campaign reported across multiple industries and regions.

Open profile →
C0005

Operation Spalax (C0005)

A defensive guide to the Enterprise ATT&CK campaign record C0005, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a campaign reported against Colombian government and private-sector organizations, especially energy and metallurgical entities.

Open profile →
C0006

Operation Honeybee (C0006)

A defensive guide to the Enterprise ATT&CK campaign record C0006, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2017–2018 campaign against humanitarian-aid and inter-Korean affairs organizations across several countries.

Open profile →
C0007

FunnyDream (C0007)

A defensive guide to the Enterprise ATT&CK campaign record C0007, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a suspected Chinese espionage campaign reported against government and foreign organizations in Southeast Asia.

Open profile →
C0010

C0010 (C0010)

A defensive guide to the Enterprise ATT&CK campaign record C0010, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed cyber-espionage campaign reported against Israeli shipping, government, aviation, energy, and healthcare organizations.

Open profile →
C0011

C0011 (C0011)

A defensive guide to the Enterprise ATT&CK campaign record C0011, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed suspected espionage campaign reported against university and college students in India.

Open profile →
C0012

Operation CuckooBees (C0012)

A defensive guide to the Enterprise ATT&CK campaign record C0012, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a cyber-espionage campaign against technology and manufacturing companies reported since at least 2019.

Open profile →
C0013

Operation Sharpshooter (C0013)

A defensive guide to the Enterprise ATT&CK campaign record C0013, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a global espionage campaign reported against nuclear, defense, government, energy, and financial organizations.

Open profile →
C0014

Operation Wocao (C0014)

A defensive guide to the Enterprise ATT&CK campaign record C0014, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a global cyber-espionage campaign reported against governments, managed-service providers, and many industries.

Open profile →
C0015

C0015 (C0015)

A defensive guide to the Enterprise ATT&CK campaign record C0015, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed five-day ransomware intrusion involving Bazar, Cobalt Strike, Conti, and other tools.

Open profile →
C0016

Operation Dust Storm (C0016)

A defensive guide to the Enterprise ATT&CK campaign record C0016, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a long-running espionage campaign reported across industries in East Asia, Southeast Asia, Europe, and the United States.

Open profile →
C0017

C0017 (C0017)

A defensive guide to the Enterprise ATT&CK campaign record C0017, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed APT41 campaign that compromised multiple United States state-government networks in 2021–2022.

Open profile →
C0018

C0018 (C0018)

A defensive guide to the Enterprise ATT&CK campaign record C0018, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed month-long intrusion that culminated in AvosLocker ransomware deployment.

Open profile →
C0020

Maroochy Water Breach (C0020)

A defensive guide to the Enterprise ATT&CK campaign record C0020, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2000 incident in which a wastewater control system was abused to disrupt operations and release sewage.

Open profile →
C0021

C0021 (C0021)

A defensive guide to the Enterprise ATT&CK campaign record C0021, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed November 2018 spearphishing campaign against public, nonprofit, educational, and private-sector organizations.

Open profile →
C0022

Operation Dream Job (C0022)

A defensive guide to the Enterprise ATT&CK campaign record C0022, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an espionage operation using employment-themed lures against defense, aerospace, government, and other sectors.

Open profile →
C0023

Operation Ghost (C0023)

A defensive guide to the Enterprise ATT&CK campaign record C0023, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an APT29 campaign beginning in 2013 against foreign ministries and a European embassy in Washington, D.C..

Open profile →
C0024

SolarWinds Compromise (C0024)

A defensive guide to the Enterprise ATT&CK campaign record C0024, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing the 2020 APT29 supply-chain operation involving the SolarWinds Orion software build process and follow-on access.

Open profile →
C0025

2016 Ukraine Electric Power Attack (C0025)

A defensive guide to the Enterprise ATT&CK campaign record C0025, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2016 campaign that disrupted Ukrainian electric-power distribution using Industroyer.

Open profile →
C0026

C0026 (C0026)

A defensive guide to the Enterprise ATT&CK campaign record C0026, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed 2022 campaign that selectively delivered malware to prior ANDROMEDA victims in Ukraine.

Open profile →
C0027

C0027 (C0027)

A defensive guide to the Enterprise ATT&CK campaign record C0027, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed financially motivated 2022 campaign linked to Scattered Spider and focused on telecommunications and business-process outsourcing companies.

Open profile →
C0028

2015 Ukraine Electric Power Attack (C0028)

A defensive guide to the Enterprise ATT&CK campaign record C0028, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2015 campaign that disrupted Ukrainian electric-power substations using BlackEnergy and KillDisk.

Open profile →
C0029

Cutting Edge (C0029)

A defensive guide to the Enterprise ATT&CK campaign record C0029, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a China-nexus espionage campaign that exploited Ivanti Connect Secure zero-day vulnerabilities beginning in late 2023.

Open profile →
C0030

Triton Safety Instrumented System Attack (C0030)

A defensive guide to the Enterprise ATT&CK campaign record C0030, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a campaign against a petrochemical organization that targeted Triconex safety controllers with the Triton framework.

Open profile →
C0031

Unitronics Defacement Campaign (C0031)

A defensive guide to the Enterprise ATT&CK campaign record C0031, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing global intrusions that defaced Unitronics Vision Series PLC human-machine interfaces across multiple sectors.

Open profile →
C0032

C0032 (C0032)

A defensive guide to the Enterprise ATT&CK campaign record C0032, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed 2019 campaign associated in public reporting with the Triton adversaries and focused on footholds in IT environments.

Open profile →
C0033

C0033 (C0033)

A defensive guide to the Enterprise ATT&CK campaign record C0033, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed PROMETHIUM campaign that used StrongPity against Android users.

Open profile →
C0034

2022 Ukraine Electric Power Attack (C0034)

A defensive guide to the Enterprise ATT&CK campaign record C0034, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2022 campaign against a Ukrainian electric utility that combined malware and living-off-the-land behavior to issue unauthorized SCADA commands.

Open profile →
C0035

KV Botnet Activity (C0035)

A defensive guide to the Enterprise ATT&CK campaign record C0035, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing activity involving compromised end-of-life SOHO equipment used to obscure access to critical-infrastructure victims.

Open profile →
C0036

Pikabot Distribution February 2024 (C0036)

A defensive guide to the Enterprise ATT&CK campaign record C0036, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a February 2024 malicious-email campaign distributing a substantially revised Pikabot variant.

Open profile →
C0037

Water Curupira Pikabot Distribution (C0037)

A defensive guide to the Enterprise ATT&CK campaign record C0037, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing 2023 Pikabot distribution activity linked to Black Basta ransomware deployment through malicious email attachments.

Open profile →
C0038

HomeLand Justice (C0038)

A defensive guide to the Enterprise ATT&CK campaign record C0038, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a disruptive 2022 campaign by Iranian state-affiliated actors against Albanian government networks.

Open profile →
C0039

Versa Director Zero Day Exploitation (C0039)

A defensive guide to the Enterprise ATT&CK campaign record C0039, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing 2024 zero-day exploitation of Versa Director servers at service providers for credential capture and follow-on access.

Open profile →
C0040

APT41 DUST (C0040)

A defensive guide to the Enterprise ATT&CK campaign record C0040, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing APT41 information-gathering activity from 2023 through July 2024 against organizations in Europe, Asia, and the Middle East.

Open profile →

Framework metadata remains source-controlled by MITRE.

Bare Metal Cyber profiles add original educational and defensive context. Verify current object status, relationships, and underlying references on the official ATT&CK site before using a profile for operational or attribution decisions.

MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.