TACTIC: INITIAL ACCESS
Exploit Public-Facing Application (T1190): real cases
MITRE Definition ↗ Adversaries exploit vulnerabilities in internet-connected software such as web servers or VPN appliances.
Key Facts
Technique ID
T1190
Initial Access
Mapped Cases
11
Primary sources
Related Laws
4
Criminal statutes
- ATT&CK Technique Identifier: T1190.
- Tactical Phase: Initial Access.
- Substantiated in 11 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)
fugitive 2020-10-15
Primary Source Evidence Excerpt: Indictment ¶ 38, Page 19
"Conspirators compromised the software update mechanism of M.E.Doc, an accounting software used extensively in Ukraine, to distribute the malicious NotPetya binary."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
U.S. v. Khoroshev et al. (LockBit Ransomware Operation)
charged 2024-05-07
Primary Source Evidence Excerpt: CISA Advisory AA23-325A
"Affiliates gained access by exploiting Citrix Bleed vulnerability CVE-2023-4966 in NetScaler ADC appliances."
U.S. District Court for the District of New Jersey
View full case dossier →
Volt Typhoon Critical Infrastructure Pre-Positioning
alleged 2023-05-24
Primary Source Evidence Excerpt: CISA Advisory AA24-038A ¶ 12
"Initial access was achieved by exploiting zero-day vulnerabilities in edge network routers and VPN firewalls including Fortinet and Ivanti appliances."
Federal Law Enforcement Action / FISA Court Authorized Operations
View full case dossier →
SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)
alleged 2020-12-13
Primary Source Evidence Excerpt: CISA Advisory AA20-352A ¶ 8
"Adversaries inserted malicious source code (SUNBURST) into legitimate SolarWinds Orion build pipelines, resulting in digitally signed malicious updates."
U.S. District Court for the Southern District of New York
View full case dossier →
U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)
sentenced 2021-08-11
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Vasinskyi exploited zero-day authentication bypass and SQL injection vulnerabilities in internet-facing Kaseya VSA servers."
U.S. District Court for the Northern District of Texas
View full case dossier →
U.S. v. Albert Gonzalez (TJX & Heartland Payment Systems)
sentenced 2008-08-05
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 6
"Gonzalez used automated SQL injection scripts against web servers to gain back-end access to internal payment processing networks."
U.S. District Court for the District of Massachusetts
View full case dossier →
U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)
sentenced 2015-11-10
Primary Source Evidence Excerpt: Indictment ¶ 12, Page 6
"Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication."
U.S. District Court for the Southern District of New York
View full case dossier →
U.S. v. Paige Thompson (Capital One Cloud Breach)
convicted 2019-07-29
Primary Source Evidence Excerpt: Indictment ¶ 9, Page 4
"Thompson sent crafted HTTP requests exploiting a Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity WAF."
U.S. District Court for the Western District of Washington
View full case dossier →
U.S. v. Max Ray Vision (Iceman / CardersMarket)
sentenced 2007-09-10
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack)
fugitive 2019-01-15
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 8
"Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports."
U.S. District Court for the District of New Jersey
View full case dossier →
U.S. v. James Zhong (Silk Road 50,000 Bitcoin Theft)
sentenced 2022-11-04
Primary Source Evidence Excerpt: Information ¶ 8, Page 4
"Zhong registered accounts and rapidly executed simultaneous withdrawal requests within fractions of a second, causing the automated withdrawal daemon to pay out double balances."
U.S. District Court for the Southern District of New York
View full case dossier →
Commonly Charged Criminal Statutes
18 U.S.C. § 1030(a)(2)
Unauthorized Access to Obtain Protected Information
Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.
18 U.S.C. § 1030(a)(5)(A)
Intentional Damage to a Protected Computer
Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.
18 U.S.C. § 1030(a)(7)
Extortion in Connection with Computers
Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.
18 U.S.C. § 1030(b)
Conspiracy to Commit Computer Fraud
Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.