31
Groups Using This
1
Tactics
4
Platforms
35
Prevalence Rank
Description

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including: * A legitimate website is compromised, allowing adversaries to inject malicious code * Script files served to a legitimate website from a publicly writeable cloud storage bucket are modified by an adversary * Malicious ads are paid for and served through legitimate ad providers (i.e., Malvertising) * Built-in web application interfaces that allow user-controllable content are leveraged for the insertion of malicious scripts or iFrames (e.g., cross-site scripting) Browser push notifications may also be abused by adversaries and leveraged for malicious code injection via User Execution. By clicking "allow" on browser push notifications, users may be granting a website permission to run JavaScript code on their browser. Often the website used by an adversary is one visited by a specific community, such as government, a particular industry, or a particular region, where the goal is to compromise a specific user or set of users based on a shared interest. This kind of targeted campaign is often referred to a strategic web compromise or watering hole attack. There are several known examples of this occurring. Typical drive-by compromise process: 1. A user visits a website that is used to host the adversary controlled content. 2. Scripts automatically execute, typically searching versions of the browser and plugins for a potentially vulnerable version. The user may be required to assist in this process by enabling scripting, notifications, or active website components and ignoring warning dialog boxes. 3. Upon finding a vulnerable version, exploit code is delivered to the browser. 4. If exploitation is successful, the adversary will gain code execution on the user's system unless other protections are in place. In some cases, a second visit to the website after the initial scan is required before exploit code is delivered. Unlike Exploit Public-Facing Application, the focus of this technique is to exploit software on a client endpoint upon visiting a website. This will commonly give an adversary access to systems on the internal network instead of external systems that may be in a DMZ.

View MITRE record โ†—

Platforms
Identity ProviderLinuxmacOSWindows
Groups Using T1189 (31)
G0032
Lazarus Group
๐Ÿ‡ฐ๐Ÿ‡ต North Korea93 techniques26 software
G0007
APT28
๐Ÿ‡ท๐Ÿ‡บ Russia93 techniques29 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0010
Turla
๐Ÿ‡ท๐Ÿ‡บ Russia68 techniques30 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G0082
APT38
๐Ÿ‡ฐ๐Ÿ‡ต North Korea56 techniques6 software
G0035
Dragonfly
๐Ÿ‡ท๐Ÿ‡บ Russia56 techniques10 software
G0065
Leviathan
๐Ÿ‡จ๐Ÿ‡ณ China50 techniques17 software
G1006
Earth Lusca
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques9 software
G0040
Patchwork
๐Ÿ‡จ๐Ÿ‡ณ China41 techniques8 software
G0060
BRONZE BUTLER
๐Ÿ‡จ๐Ÿ‡ณ China40 techniques14 software
G0067
APT37
๐Ÿ‡ท๐Ÿ‡บ Russia29 techniques13 software
G1035
Winter Vivern
๐Ÿ‡ท๐Ÿ‡บ Russia27 techniques0 software
G0012
Darkhotel
๐Ÿ‡ฐ๐Ÿ‡ท South Korea24 techniques0 software
G0073
APT19
๐Ÿ‡จ๐Ÿ‡ณ China21 techniques2 software
G0112
Windshift
19 techniques1 software
G1012
CURIUM
๐Ÿ‡ฎ๐Ÿ‡ท Iran19 techniques1 software
G1034
Daggerfly
๐Ÿ‡จ๐Ÿ‡ณ China17 techniques6 software
G0077
Leafminer
๐Ÿ‡ฎ๐Ÿ‡ท Iran17 techniques4 software
G0001
Axiom
๐Ÿ‡จ๐Ÿ‡ณ China16 techniques8 software
G0134
Transparent Tribe
๐Ÿ‡ต๐Ÿ‡ฐ Pakistan14 techniques5 software
G0070
Dark Caracal
๐Ÿ‡ฑ๐Ÿ‡ง Lebanon12 techniques3 software
G0138
Andariel
๐Ÿ‡ฐ๐Ÿ‡ต North Korea12 techniques2 software
G1020
Mustard Tempest
12 techniques2 software
G0095
Machete
๐Ÿ‡ท๐Ÿ‡บ Russia11 techniques1 software
G0068
PLATINUM
11 techniques3 software
G0056
PROMETHIUM
๐Ÿ‡น๐Ÿ‡ท Turkey11 techniques2 software
G0066
Elderwood
๐Ÿ‡จ๐Ÿ‡ณ China9 techniques9 software
G0048
RTM
๐Ÿ‡ท๐Ÿ‡บ Russia7 techniques1 software
G0124
Windigo
7 techniques1 software
โ†‘