Real-world descriptions of how a group, tool or campaign used a technique.
78 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.001 Spearphishing Attachment |
GroupAPT38 | APT38 has conducted spearphishing campaigns using malicious email attachments. |
| T1566.001 Spearphishing Attachment |
GroupElderwood | Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
GroupSideCopy | SideCopy has sent spearphishing emails with malicious hta file attachments. |
| T1566.001 Spearphishing Attachment |
GroupKimsuky | Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links. |
| T1566.001 Spearphishing Attachment |
GroupEXOTIC LILY | EXOTIC LILY conducted an e-mail thread-hijacking campaign with malicious ISO attachments. |
| T1566.001 Spearphishing Attachment |
Groupadmin@338 | admin@338 has sent emails with malicious Microsoft Office documents attached. |
| T1566.001 Spearphishing Attachment |
GroupPatchwork | Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims. |
| T1566.001 Spearphishing Attachment |
GroupAPT41 | APT41 sent spearphishing emails with attachments such as compiled HTML (.chm) files to initially compromise their victims. |
| T1566.001 Spearphishing Attachment |
GroupDragonfly | Dragonfly has sent emails with malicious attachments to gain initial access. |
| T1566.001 Spearphishing Attachment |
GroupGorgon Group | Gorgon Group sent emails to victims with malicious Microsoft Office documents attached. |
| T1566.001 Spearphishing Attachment |
GroupmenuPass | menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents. |
| T1566.001 Spearphishing Attachment |
GroupAPT32 | APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet. |
| T1566.001 Spearphishing Attachment |
GroupMuddyWater | MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022ESET_MuddyWater_Dec2025FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024SOCRadar_MuddyWaterDindoor_Mar2026Securelist MuddyWater Oct 2018Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1566.001 Spearphishing Attachment |
GroupNaikon | Naikon has used malicious e-mail attachments to deliver malware. |
| T1566.001 Spearphishing Attachment |
GroupFIN6 | FIN6 has targeted victims with e-mails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
GroupGamaredon Group | Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives. |
| T1566.001 Spearphishing Attachment |
GroupGallmaker | Gallmaker sent emails with malicious Microsoft Office documents attached. |
| T1566.001 Spearphishing Attachment |
GroupFIN7 | FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached. |
| T1566.001 Spearphishing Attachment |
GroupSandworm Team | Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails. |
| T1566.001 Spearphishing Attachment |
GroupMachete | Machete has delivered spearphishing emails that contain a zipped file with malicious contents. |
| T1566.001 Spearphishing Attachment |
GroupAndariel | Andariel has conducted spearphishing campaigns that included malicious Word or Excel attachments. |
| T1566.001 Spearphishing Attachment |
GroupCURIUM | CURIUM has used phishing with malicious attachments for initial access to victim environments. |
| T1566.001 Spearphishing Attachment |
GroupSidewinder | Sidewinder has sent e-mails with malicious attachments often crafted for specific targets. |
| T1566.001 Spearphishing Attachment |
GroupMustang Panda | Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs. 2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024 |
| T1566.001 Spearphishing Attachment |
GroupAPT39 | APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims. |
| T1566.001 Spearphishing Attachment |
GroupTA2541 | TA2541 has sent phishing emails with malicious attachments for initial access including MS Word documents. |
| T1566.001 Spearphishing Attachment |
GroupAPT37 | APT37 delivers malware using spearphishing emails with malicious HWP attachments. |
| T1566.001 Spearphishing Attachment |
GroupOilRig | OilRig has sent spearphising emails with malicious attachments to potential victims using compromised and/or spoofed email accounts. |
| T1566.001 Spearphishing Attachment |
GroupHigaisa | Higaisa has sent spearphishing emails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
GroupTropic Trooper | Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments. |
| T1566.001 Spearphishing Attachment |
GroupTA459 | TA459 has targeted victims using spearphishing emails with malicious Microsoft Word attachments. |
| T1566.001 Spearphishing Attachment |
GroupFerocious Kitten | Ferocious Kitten has conducted spearphishing campaigns containing malicious documents to lure victims to open the attachments. |
| T1566.001 Spearphishing Attachment |
GroupThe White Company | The White Company has sent phishing emails with malicious Microsoft Word attachments to victims. |
| T1566.001 Spearphishing Attachment |
GroupSaint Bear | Saint Bear uses a variety of file formats, such as Microsoft Office documents, ZIP archives, PDF documents, and other items as phishing attachments for initial access. |
| T1566.001 Spearphishing Attachment |
GroupAPT1 | APT1 has sent spearphishing emails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
GroupDarkHydrus | DarkHydrus has sent spearphishing emails with password-protected RAR archives containing malicious Excel Web Query files (.iqy). The group has also sent spearphishing emails that contained malicious Microsoft Office documents that use the “attachedTemplate” technique to load a template from a remote server. |
| T1566.001 Spearphishing Attachment |
GroupConfucius | Confucius has crafted and sent victims malicious attachments to gain initial access. |
| T1566.001 Spearphishing Attachment |
GroupBlackTech | BlackTech has used spearphishing e-mails with malicious password-protected archived files (ZIP or RAR) to deliver malware. |
| T1566.001 Spearphishing Attachment |
GroupLeviathan | Leviathan has sent spearphishing emails with malicious attachments, including .rtf, .doc, and .xls files. |
| T1566.001 Spearphishing Attachment |
GroupWinter Vivern | Winter Vivern leverages malicious attachments delivered via email for initial access activity. |
| T1566.001 Spearphishing Attachment |
GroupTA505 | TA505 has used spearphishing emails with malicious attachments to initially compromise victims. |
| T1566.001 Spearphishing Attachment |
GroupBITTER | BITTER has sent spearphishing emails with a malicious RTF document or Excel spreadsheet. |
| T1566.001 Spearphishing Attachment |
GroupRedCurl | RedCurl has used phishing emails with malicious files to gain initial access. |
| T1566.001 Spearphishing Attachment |
GroupMofang | Mofang delivered spearphishing emails with malicious documents, PDFs, or Excel files attached. |
| T1566.001 Spearphishing Attachment |
GroupAPT29 | APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims. |
| T1566.001 Spearphishing Attachment |
GroupMirrorFace | MirrorFace has sent spearphishing emails with malicious attachments to deliver malware payloads. |
| T1566.001 Spearphishing Attachment |
GroupBRONZE BUTLER | BRONZE BUTLER used spearphishing emails with malicious Microsoft Word attachments to infect victims. |
| T1566.001 Spearphishing Attachment |
GroupTA551 | TA551 has sent spearphishing attachments with password protected ZIP files. |
| T1566.001 Spearphishing Attachment |
GroupStar Blizzard | Star Blizzard has sent emails with malicious .pdf files to spread malware. |
| T1566.001 Spearphishing Attachment |
GroupDarkhotel | Darkhotel has sent spearphishing emails with malicious RAR and .LNK attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.