1200KM / simulation
T1189 Drive-by Compromise — Attack Simulation
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including: * A legitimate website is compromised, allowing adversaries to inject malicious code * Script files served to a legitimate website from a publicly writeable cloud storage bucket are modified by an adversary * Malicious ads are paid for and…
Technique description
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including: * A legitimate website is compromised, allowing adversaries to inject malicious code * Script files served to a legitimate website from a publicly writeable cloud storage bucket are modified by an adversary * Malicious ads are paid for and…
No compatible procedure was found in the pinned Atomic index. This is a support gap, not a finding of technical impossibility.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
No compatible documented candidate in the pinned snapshot. This is a support gap, not technical impossibility.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Axiom · G0001
- APT28 · G0007
- Turla · G0010
- Darkhotel · G0012
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Dragonfly · G0035
- Patchwork · G0040
- RTM · G0048
- APT32 · G0050
- PROMETHIUM · G0056
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- Leviathan · G0065
- Elderwood · G0066
- APT37 · G0067
- PLATINUM · G0068
- Dark Caracal · G0070
- APT19 · G0073
- Leafminer · G0077
- APT38 · G0082
- Machete · G0095
- Windshift · G0112
- Windigo · G0124
- Transparent Tribe · G0134
- Andariel · G0138
- Earth Lusca · G1006
- CURIUM · G1012
- Mustard Tempest · G1020
- Daggerfly · G1034
- Winter Vivern · G1035
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.