TACTIC: INITIAL ACCESS

Exploit Public-Facing Application (T1190): real cases

MITRE Definition ↗
Adversaries exploit vulnerabilities in internet-connected software such as web servers or VPN appliances.

Key Facts

Technique ID
T1190
Initial Access
Mapped Cases
11
Primary sources
Related Laws
4
Criminal statutes
  • ATT&CK Technique Identifier: T1190.
  • Tactical Phase: Initial Access.
  • Substantiated in 11 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Indictment ¶ 38, Page 19
"Conspirators compromised the software update mechanism of M.E.Doc, an accounting software used extensively in Ukraine, to distribute the malicious NotPetya binary."
U.S. District Court for the Western District of Pennsylvania View full case dossier →
Primary Source Evidence Excerpt: CISA Advisory AA23-325A
"Affiliates gained access by exploiting Citrix Bleed vulnerability CVE-2023-4966 in NetScaler ADC appliances."
U.S. District Court for the District of New Jersey View full case dossier →
Primary Source Evidence Excerpt: CISA Advisory AA24-038A ¶ 12
"Initial access was achieved by exploiting zero-day vulnerabilities in edge network routers and VPN firewalls including Fortinet and Ivanti appliances."
Federal Law Enforcement Action / FISA Court Authorized Operations View full case dossier →
Primary Source Evidence Excerpt: CISA Advisory AA20-352A ¶ 8
"Adversaries inserted malicious source code (SUNBURST) into legitimate SolarWinds Orion build pipelines, resulting in digitally signed malicious updates."
U.S. District Court for the Southern District of New York View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Vasinskyi exploited zero-day authentication bypass and SQL injection vulnerabilities in internet-facing Kaseya VSA servers."
U.S. District Court for the Northern District of Texas View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 6
"Gonzalez used automated SQL injection scripts against web servers to gain back-end access to internal payment processing networks."
U.S. District Court for the District of Massachusetts View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 12, Page 6
"Tyurin gained entry to JPMorgan Chase's network by exploiting an unpatched web application server lacking two-factor authentication."
U.S. District Court for the Southern District of New York View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 9, Page 4
"Thompson sent crafted HTTP requests exploiting a Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity WAF."
U.S. District Court for the Western District of Washington View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Vision exploited web application vulnerabilities in competitor dark web portals to compromise forum SQL databases and hijack customer accounts."
U.S. District Court for the Northern District of California View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 8
"Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports."
U.S. District Court for the District of New Jersey View full case dossier →
Primary Source Evidence Excerpt: Information ¶ 8, Page 4
"Zhong registered accounts and rapidly executed simultaneous withdrawal requests within fractions of a second, causing the automated withdrawal daemon to pay out double balances."
U.S. District Court for the Southern District of New York View full case dossier →

Commonly Charged Criminal Statutes

18 U.S.C. § 1030(a)(2)

Unauthorized Access to Obtain Protected Information

Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.

18 U.S.C. § 1030(a)(5)(A)

Intentional Damage to a Protected Computer

Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.

18 U.S.C. § 1030(a)(7)

Extortion in Connection with Computers

Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.

18 U.S.C. § 1030(b)

Conspiracy to Commit Computer Fraud

Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.