ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1566.001×

78 examples

TechniqueUsed byProcedure example
T1566.001
Spearphishing Attachment
GroupAPT38

APT38 has conducted spearphishing campaigns using malicious email attachments.

T1566.001
Spearphishing Attachment
GroupElderwood

Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing malicious attachments.

T1566.001
Spearphishing Attachment
GroupSideCopy

SideCopy has sent spearphishing emails with malicious hta file attachments.

T1566.001
Spearphishing Attachment
GroupKimsuky

Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links.

T1566.001
Spearphishing Attachment
GroupEXOTIC LILY

EXOTIC LILY conducted an e-mail thread-hijacking campaign with malicious ISO attachments.

T1566.001
Spearphishing Attachment
Groupadmin@338

admin@338 has sent emails with malicious Microsoft Office documents attached.

T1566.001
Spearphishing Attachment
GroupPatchwork

Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims.

T1566.001
Spearphishing Attachment
GroupAPT41

APT41 sent spearphishing emails with attachments such as compiled HTML (.chm) files to initially compromise their victims.

T1566.001
Spearphishing Attachment
GroupDragonfly

Dragonfly has sent emails with malicious attachments to gain initial access.

T1566.001
Spearphishing Attachment
GroupGorgon Group

Gorgon Group sent emails to victims with malicious Microsoft Office documents attached.

T1566.001
Spearphishing Attachment
GroupmenuPass

menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents.

T1566.001
Spearphishing Attachment
GroupAPT32

APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet.

T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

T1566.001
Spearphishing Attachment
GroupNaikon

Naikon has used malicious e-mail attachments to deliver malware.

T1566.001
Spearphishing Attachment
GroupFIN6

FIN6 has targeted victims with e-mails containing malicious attachments.

T1566.001
Spearphishing Attachment
GroupGamaredon Group

Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives.

T1566.001
Spearphishing Attachment
GroupGallmaker

Gallmaker sent emails with malicious Microsoft Office documents attached.

T1566.001
Spearphishing Attachment
GroupFIN7

FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached.

T1566.001
Spearphishing Attachment
GroupSandworm Team

Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails.

T1566.001
Spearphishing Attachment
GroupMachete

Machete has delivered spearphishing emails that contain a zipped file with malicious contents.

T1566.001
Spearphishing Attachment
GroupAndariel

Andariel has conducted spearphishing campaigns that included malicious Word or Excel attachments.

T1566.001
Spearphishing Attachment
GroupCURIUM

CURIUM has used phishing with malicious attachments for initial access to victim environments.

T1566.001
Spearphishing Attachment
GroupSidewinder

Sidewinder has sent e-mails with malicious attachments often crafted for specific targets.

T1566.001
Spearphishing Attachment
GroupMustang Panda

Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs.

T1566.001
Spearphishing Attachment
GroupAPT39

APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims.

T1566.001
Spearphishing Attachment
GroupTA2541

TA2541 has sent phishing emails with malicious attachments for initial access including MS Word documents.

T1566.001
Spearphishing Attachment
GroupAPT37

APT37 delivers malware using spearphishing emails with malicious HWP attachments.

T1566.001
Spearphishing Attachment
GroupOilRig

OilRig has sent spearphising emails with malicious attachments to potential victims using compromised and/or spoofed email accounts.

T1566.001
Spearphishing Attachment
GroupHigaisa

Higaisa has sent spearphishing emails containing malicious attachments.

T1566.001
Spearphishing Attachment
GroupTropic Trooper

Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments.

T1566.001
Spearphishing Attachment
GroupTA459

TA459 has targeted victims using spearphishing emails with malicious Microsoft Word attachments.

T1566.001
Spearphishing Attachment
GroupFerocious Kitten

Ferocious Kitten has conducted spearphishing campaigns containing malicious documents to lure victims to open the attachments.

T1566.001
Spearphishing Attachment
GroupThe White Company

The White Company has sent phishing emails with malicious Microsoft Word attachments to victims.

T1566.001
Spearphishing Attachment
GroupSaint Bear

Saint Bear uses a variety of file formats, such as Microsoft Office documents, ZIP archives, PDF documents, and other items as phishing attachments for initial access.

T1566.001
Spearphishing Attachment
GroupAPT1

APT1 has sent spearphishing emails containing malicious attachments.

T1566.001
Spearphishing Attachment
GroupDarkHydrus

DarkHydrus has sent spearphishing emails with password-protected RAR archives containing malicious Excel Web Query files (.iqy). The group has also sent spearphishing emails that contained malicious Microsoft Office documents that use the “attachedTemplate” technique to load a template from a remote server.

T1566.001
Spearphishing Attachment
GroupConfucius

Confucius has crafted and sent victims malicious attachments to gain initial access.

T1566.001
Spearphishing Attachment
GroupBlackTech

BlackTech has used spearphishing e-mails with malicious password-protected archived files (ZIP or RAR) to deliver malware.

T1566.001
Spearphishing Attachment
GroupLeviathan

Leviathan has sent spearphishing emails with malicious attachments, including .rtf, .doc, and .xls files.

T1566.001
Spearphishing Attachment
GroupWinter Vivern

Winter Vivern leverages malicious attachments delivered via email for initial access activity.

T1566.001
Spearphishing Attachment
GroupTA505

TA505 has used spearphishing emails with malicious attachments to initially compromise victims.

T1566.001
Spearphishing Attachment
GroupBITTER

BITTER has sent spearphishing emails with a malicious RTF document or Excel spreadsheet.

T1566.001
Spearphishing Attachment
GroupRedCurl

RedCurl has used phishing emails with malicious files to gain initial access.

T1566.001
Spearphishing Attachment
GroupMofang

Mofang delivered spearphishing emails with malicious documents, PDFs, or Excel files attached.

T1566.001
Spearphishing Attachment
GroupAPT29

APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims.

T1566.001
Spearphishing Attachment
GroupMirrorFace

MirrorFace has sent spearphishing emails with malicious attachments to deliver malware payloads.

T1566.001
Spearphishing Attachment
GroupBRONZE BUTLER

BRONZE BUTLER used spearphishing emails with malicious Microsoft Word attachments to infect victims.

T1566.001
Spearphishing Attachment
GroupTA551

TA551 has sent spearphishing attachments with password protected ZIP files.

T1566.001
Spearphishing Attachment
GroupStar Blizzard

Star Blizzard has sent emails with malicious .pdf files to spread malware.

T1566.001
Spearphishing Attachment
GroupDarkhotel

Darkhotel has sent spearphishing emails with malicious RAR and .LNK attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.