Real-world descriptions of how a group, tool or campaign used a technique.
86 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.002 Malicious File |
GroupAPT38 | APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files. |
| T1204.002 Malicious File |
GroupIndrik Spider | Indrik Spider has attempted to get users to click on a malicious zipped file. |
| T1204.002 Malicious File |
GroupElderwood | Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open attachments. |
| T1204.002 Malicious File |
GroupSideCopy | SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns. |
| T1204.002 Malicious File |
GroupKimsuky | Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background. |
| T1204.002 Malicious File |
GroupEXOTIC LILY | EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO. |
| T1204.002 Malicious File |
Groupadmin@338 | admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupPatchwork | Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware. |
| T1204.002 Malicious File |
GroupDragonfly | Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments. |
| T1204.002 Malicious File |
GroupGorgon Group | Gorgon Group attempted to get users to launch malicious Microsoft Office attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupmenuPass | menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns. |
| T1204.002 Malicious File |
GroupAPT32 | APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment. |
| T1204.002 Malicious File |
GroupMuddyWater | MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1204.002 Malicious File |
GroupNaikon | Naikon has convinced victims to open malicious attachments to execute malware. |
| T1204.002 Malicious File |
GroupFIN6 | FIN6 has used malicious documents to lure victims into allowing execution of PowerShell scripts. |
| T1204.002 Malicious File |
GroupGamaredon Group | Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files. |
| T1204.002 Malicious File |
GroupGallmaker | Gallmaker sent victims a lure document with a warning that asked victims to “enable content” for execution. |
| T1204.002 Malicious File |
GroupStorm-1811 | Storm-1811 has prompted users to execute downloaded software and payloads as the result of social engineering activity. |
| T1204.002 Malicious File |
GroupFIN7 | FIN7 lured victims to double-click on images in the attachments they sent which would then execute the hidden LNK file. Additionally, FIN7 has used malicious Microsoft Word and Excel files and Leo VBS to distribute an updated version of JSS Loader and to distribute the Harpy backdoor. |
| T1204.002 Malicious File |
GroupSandworm Team | Sandworm Team has tricked unwitting recipients into clicking on spearphishing attachments and enabling malicious macros embedded within files. |
| T1204.002 Malicious File |
GroupMachete | Machete has relied on users opening malicious attachments delivered through spearphishing to execute malware. |
| T1204.002 Malicious File |
GroupAndariel | Andariel has attempted to lure victims into enabling malicious macros within email attachments. |
| T1204.002 Malicious File |
GroupCURIUM | CURIUM has lured users into opening malicious files delivered via social media. |
| T1204.002 Malicious File |
GroupSidewinder | Sidewinder has lured targets to click on malicious files to gain execution in the target environment. |
| T1204.002 Malicious File |
GroupMustang Panda | Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019Avira Mustang Panda January 2020CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Proofpoint TA416 Europe March 2022Recorded Future REDDELTA July 2020Sophos Mustang Panda PLUGXSophos PlugX September 2022Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1204.002 Malicious File |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment. |
| T1204.002 Malicious File |
GroupContagious Interview | Contagious Interview has distributed malicious files requiring direct victim interaction to execute through the guise of a code test. |
| T1204.002 Malicious File |
GroupTA2541 | TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads. |
| T1204.002 Malicious File |
GroupAPT37 | APT37 has sent spearphishing attachments attempting to get a user to open them. |
| T1204.002 Malicious File |
GroupOilRig | OilRig has delivered macro-enabled documents that required targets to click the "enable content" button to execute the payload on the system. |
| T1204.002 Malicious File |
GroupHigaisa | Higaisa used malicious e-mail attachments to lure victims into executing LNK files. |
| T1204.002 Malicious File |
GroupTropic Trooper | Tropic Trooper has lured victims into executing malware via malicious e-mail attachments. |
| T1204.002 Malicious File |
GroupTA459 | TA459 has attempted to get victims to open malicious Microsoft Word attachment sent via spearphishing. |
| T1204.002 Malicious File |
GroupAoqin Dragon | Aoqin Dragon has lured victims into opening weaponized documents, fake external drives, and fake antivirus to execute malicious payloads. |
| T1204.002 Malicious File |
GroupFerocious Kitten | Ferocious Kitten has attempted to convince victims to enable malicious content within a spearphishing email by including an odd decoy message. |
| T1204.002 Malicious File |
GroupThe White Company | The White Company has used phishing lure documents that trick users into opening them and infecting their computers. |
| T1204.002 Malicious File |
GroupSaint Bear | Saint Bear relies on user interaction and execution of malicious attachments and similar for initial execution on victim systems. |
| T1204.002 Malicious File |
GroupDarkHydrus | DarkHydrus has sent malware that required users to hit the enable button in Microsoft Excel to allow an .iqy file to be downloaded. |
| T1204.002 Malicious File |
GroupConfucius | Confucius has lured victims to execute malicious attachments included in crafted spearphishing emails related to current topics. |
| T1204.002 Malicious File |
GroupBlackTech | BlackTech has used e-mails with malicious documents to lure victims into installing malware. |
| T1204.002 Malicious File |
GroupLeviathan | Leviathan has sent spearphishing attachments attempting to get a user to click. |
| T1204.002 Malicious File |
GroupTA505 | TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1204.002 Malicious File |
GroupBITTER | BITTER has attempted to lure victims into opening malicious attachments delivered via spearphishing. |
| T1204.002 Malicious File |
GroupRedCurl | RedCurl has used malicious files to infect the victim machines. |
| T1204.002 Malicious File |
GroupMofang | Mofang's malicious spearphishing attachments required a user to open the file after receiving. |
| T1204.002 Malicious File |
GroupAPT29 | APT29 has used various forms of spearphishing attempting to get a user to open attachments, including, but not limited to, malicious Microsoft Word documents, .pdf, and .lnk files. |
| T1204.002 Malicious File |
GroupDark Caracal | Dark Caracal makes their malware look like Flash Player, Office, or PDF documents in order to entice a user to click on it. |
| T1204.002 Malicious File |
GroupMirrorFace | MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution. |
| T1204.002 Malicious File |
GroupBRONZE BUTLER | BRONZE BUTLER has attempted to get users to launch malicious Microsoft Word attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupTA551 | TA551 has prompted users to enable macros within spearphishing attachments to install malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.