Leviathan performed extensive remote host enumeration to build their own map of victim networks during Leviathan Australian Intrusions.2
campaign
Leviathan Australian Intrusions C0049
- First seen
- April 2022
- Last seen
- September 2022
- Created
- 3 February 2025
- Last modified
- 31 July 2026
Leviathan Australian Intrusions consisted of at least two long-term intrusions against victims in Australia by Leviathan, relying on similar tradecraft such as external service exploitation followed by extensive credential capture and re-use to enable privilege escalation and lateral movement. Leviathan Australian Intrusions were focused on exfiltrating sensitive data including valid credentials for the victim organizations.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0049
Leviathan used remote shares to move laterally through victim networks during Leviathan Australian Intrusions.3
Leviathan used SSH brute force techniques to move laterally within victim environments during Leviathan Australian Intrusions.4
Leviathan exfiltrated collected data over existing command and control channels during Leviathan Australian Intrusions.5
Leviathan captured submitted multfactor authentication codes and other technical artifacts related to remote access sessions during Leviathan Australian Intrusions.6
Leviathan exploited software vulnerabilities in victim environments to escalate privileges during Leviathan Australian Intrusions.7
Standing C0049
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
77th percentile · 77% of 56 ATT&CK campaigns have this many Enterprise techniques or fewer.
86th percentile · 86% of 56 ATT&CK campaigns have this many tactics spanned or fewer.
11th percentile · 89% of 56 ATT&CK campaigns have more tools and malware.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
59th percentile · 59% of 56 ATT&CK campaigns have this many detection rules per technique or fewer.
Detection coverage C0049
816 distinct rules cover the 26 techniques recorded for this campaign. The 895 technique-to-rule mappings resolve to 816 distinct rules, because one rule can cover several techniques. 474 Sigma · 342 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org