46
Groups Using This
1
Tactics
7
Platforms
19
Prevalence Rank
Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers. Depending on the flaw being exploited, this may also involve Exploitation for Stealth or Exploitation for Client Execution. If an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the Cloud Instance Metadata API), exploit container host access via Escape to Host, or take advantage of weak identity and access management policies. Adversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses. For websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.

View MITRE record โ†—

Platforms
ContainersESXiIaaSLinuxmacOSNetwork DevicesWindows
Groups Using T1190 (46)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0007
APT28
๐Ÿ‡ท๐Ÿ‡บ Russia93 techniques29 software
G0096
APT41
๐Ÿ‡จ๐Ÿ‡ณ China82 techniques32 software
G1017
Volt Typhoon
๐Ÿ‡จ๐Ÿ‡ณ China81 techniques17 software
G0034
Sandworm Team
๐Ÿ‡ท๐Ÿ‡บ Russia79 techniques27 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0069
MuddyWater
๐Ÿ‡ฎ๐Ÿ‡ท Iran68 techniques21 software
G0046
FIN7
67 techniques19 software
G0016
APT29
๐Ÿ‡ท๐Ÿ‡บ Russia66 techniques49 software
G1055
VOID MANTICORE
๐Ÿ‡ฎ๐Ÿ‡ท Iran63 techniques0 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G1051
Medusa Group
57 techniques5 software
G0035
Dragonfly
๐Ÿ‡ท๐Ÿ‡บ Russia56 techniques10 software
G0087
APT39
๐Ÿ‡ฎ๐Ÿ‡ท Iran53 techniques11 software
G1016
FIN13
53 techniques4 software
G0065
Leviathan
๐Ÿ‡จ๐Ÿ‡ณ China50 techniques17 software
G1048
UNC3886
๐Ÿ‡จ๐Ÿ‡ณ China49 techniques8 software
G1043
BlackByte
48 techniques8 software
G1003
Ember Bear
๐Ÿ‡ท๐Ÿ‡บ Russia47 techniques11 software
G1057
ShinyHunters
46 techniques1 software
G0045
menuPass
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques25 software
G0004
Ke3chang
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques11 software
G1006
Earth Lusca
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques9 software
G0125
HAFNIUM
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G1054
MirrorFace
๐Ÿ‡จ๐Ÿ‡ณ China43 techniques16 software
G1053
Storm-0501
42 techniques8 software
G0117
Fox Kitten
๐Ÿ‡ฎ๐Ÿ‡ท Iran41 techniques5 software
G1056
TeamPCP
36 techniques3 software
G0106
Rocke
๐Ÿ‡จ๐Ÿ‡ณ China36 techniques0 software
G0093
GALLIUM
๐Ÿ‡ท๐Ÿ‡บ Russia31 techniques16 software
G1023
APT5
๐Ÿ‡จ๐Ÿ‡ณ China29 techniques13 software
G1035
Winter Vivern
๐Ÿ‡ท๐Ÿ‡บ Russia27 techniques0 software
G1041
Sea Turtle
27 techniques1 software
G1040
Play
26 techniques9 software
G1022
ToddyCat
25 techniques9 software
G1032
INC Ransom
25 techniques8 software
G1030
Agrius
๐Ÿ‡ฎ๐Ÿ‡ท Iran22 techniques9 software
G0108
Blue Mockingbird
22 techniques2 software
G1021
Cinnamon Tempest
๐Ÿ‡จ๐Ÿ‡ณ China19 techniques8 software
G0001
Axiom
๐Ÿ‡จ๐Ÿ‡ณ China16 techniques8 software
G0135
BackdoorDiplomacy
15 techniques5 software
G1045
Salt Typhoon
๐Ÿ‡จ๐Ÿ‡ณ China14 techniques1 software
G0098
BlackTech
๐Ÿ‡จ๐Ÿ‡ณ China14 techniques6 software
G1009
Moses Staff
๐Ÿ‡ฎ๐Ÿ‡ท Iran12 techniques4 software
G0115
GOLD SOUTHFIELD
9 techniques2 software
G0123
Volatile Cedar
๐Ÿ‡ฑ๐Ÿ‡ง Lebanon5 techniques2 software
โ†‘