During Frankenstein, the threat actors used Empire to gather various local system information.2
campaign
Frankenstein C0001
- First seen
- January 2019
- Last seen
- April 2019
- Created
- 7 September 2022
- Last modified
- 31 July 2026
Frankenstein was described by security researchers as a highly-targeted campaign conducted by moderately sophisticated and highly resourceful threat actors in early 2019. The unidentified actors primarily relied on open source tools, including Empire. The campaign name refers to the actors' ability to piece together several unrelated open-source tool components.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0001
During Frankenstein, the threat actors used Empire to find the public IP address of a compromised system.3
During Frankenstein, the threat actors collected information via Empire, which was automatically sent back to the adversary's C2.4
During Frankenstein, the threat actors ran encoded commands from the command line.5
During Frankenstein, the threat actors used Empire to enumerate hosts and gather username, machine name, and administrative permissions information.6
During Frankenstein, the threat actors named a malicious scheduled task "WinUpdate" for persistence.7
Standing C0001
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
79th percentile · 79% of 56 ATT&CK campaigns have this many Enterprise techniques or fewer.
68th percentile · 68% of 56 ATT&CK campaigns have this many tactics spanned or fewer.
45th percentile · 55% of 56 ATT&CK campaigns have more tools and malware.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
68th percentile · 68% of 56 ATT&CK campaigns have this many detection rules per technique or fewer.
Detection coverage C0001
1036 distinct rules cover the 27 techniques recorded for this campaign. The 1170 technique-to-rule mappings resolve to 1036 distinct rules, because one rule can cover several techniques. 725 Sigma · 311 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org