ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1204.002×

98 examples

TechniqueUsed byProcedure example
T1204.002
Malicious File
MalwareTrickBot

TrickBot has attempted to get users to launch malicious documents to deliver its payload.

T1204.002
Malicious File
MalwareBLINDINGCAN

BLINDINGCAN has lured victims into executing malicious macros embedded within Microsoft Office documents.

T1204.002
Malicious File
MalwareNinja

Ninja has gained execution through victims opening malicious executable files embedded in zip archives.

T1204.002
Malicious File
MalwareBumblebee

Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs.

T1204.002
Malicious File
MalwareKOPILUWAK

KOPILUWAK has gained execution through malicious attachments.

T1204.002
Malicious File
MalwareThreatNeedle

ThreatNeedle relies on a victim to click on a malicious document for initial execution.

T1204.002
Malicious File
MalwareHavoc

Havoc has been executed by victims through the use of targeted lures and crafted decoy documents.

T1204.002
Malicious File
MalwareStrongPity

StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.

T1204.002
Malicious File
MalwarePony

Pony has attempted to lure targets into downloading an attached executable (ZIP, RAR, or CAB archives) or document (PDF or other MS Office format).

T1204.002
Malicious File
MalwareROAMINGHOUSE

During Operation AkaiRyū, MirrorFace used malicious files to drop ROAMINGHOUSE.

T1204.002
Malicious File
MalwareAppleSeed

AppleSeed can achieve execution through users running malicious file attachments distributed via email.

T1204.002
Malicious File
MalwareNETWIRE

NETWIRE has been executed through luring victims into opening malicious documents.

T1204.002
Malicious File
MalwareBad Rabbit

Bad Rabbit has been executed through user installation of an executable disguised as a flash installer.

T1204.002
Malicious File
MalwareEnvyScout

EnvyScout has been executed through malicious files attached to e-mails.

T1204.002
Malicious File
MalwareSTATICPLUGIN

STATICPLUGIN has required user execution to load subsequent malicious payloads.

T1204.002
Malicious File
MalwareEmotet

Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareWoody RAT

Woody RAT has relied on users opening a malicious email attachment for execution.

T1204.002
Malicious File
MalwareSquirrelwaffle

Squirrelwaffle has relied on users enabling malicious macros within Microsoft Excel and Word attachments.

T1204.002
Malicious File
MalwareSnip3

Snip3 can gain execution through the download of visual basic files.

T1204.002
Malicious File
MalwareRifdoor

Rifdoor has been executed from malicious Excel or Word documents containing macros.

T1204.002
Malicious File
MalwareGuLoader

The GuLoader executable has been retrieved via embedded macros in malicious Word documents.

T1204.002
Malicious File
MalwareInvisiMole

InvisiMole can deliver trojanized versions of software and documents, relying on user execution.

T1204.002
Malicious File
MalwareCLAIMLOADER

CLAIMLOADER has used tailored decoy documents as part of the installation routine to entice users to open attachments.

T1204.002
Malicious File
MalwareMispadu

Mispadu has relied on users to execute malicious files in order to gain execution on victim machines.

T1204.002
Malicious File
MalwareRustyWater

RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1204.002
Malicious File
MalwareIcedID

IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL.

T1204.002
Malicious File
MalwareFlagpro

Flagpro has relied on users clicking a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareDarkTortilla

DarkTortilla has relied on a user to open a malicious document or archived file delivered via email for initial execution.

T1204.002
Malicious File
MalwareBeaverTail

BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications.

T1204.002
Malicious File
MalwareROKRAT

ROKRAT has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareJavali

Javali has achieved execution through victims opening malicious attachments, including MSI files with embedded VBScript.

T1204.002
Malicious File
MalwarePlugX

PlugX has leveraged an initial executable disguised as a legitimate document to trick the target into opening it.

T1204.002
Malicious File
MalwareBisonal

Bisonal has relied on users to execute malicious file attachments delivered via spearphishing emails.

T1204.002
Malicious File
MalwareLumma Stealer

Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files.

T1204.002
Malicious File
MalwareClambling

Clambling has gained execution through luring victims into opening malicious files.

T1204.002
Malicious File
MalwareDarkGate

DarkGate initial infection payloads can masquerade as pirated media content requiring user interaction for code execution. DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.

T1204.002
Malicious File
MalwareMongall

Mongall has relied on a user opening a malicious document for execution.

T1204.002
Malicious File
MalwareSVCReady

SVCReady has relied on users clicking a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareLatrodectus

Latrodectus has lured users into opening malicious email attachments for execution.

T1204.002
Malicious File
MalwareSaint Bot

Saint Bot has relied on users to execute a malicious attachment delivered via spearphishing.

T1204.002
Malicious File
MalwareChaes

Chaes requires the user to click on the malicious Word document to execute the next part of the attack.

T1204.002
Malicious File
MalwareLODEINFO

LODEINFO has been executed via victims opening malicious email attachments.

T1204.002
Malicious File
MalwareTYPEFRAME

A Word document delivering TYPEFRAME prompts the user to enable macro execution.

T1204.002
Malicious File
MalwareBundlore

Bundlore has attempted to get users to execute a malicious .app file that looks like a Flash Player update.

T1204.002
Malicious File
MalwareMetamorfo

Metamorfo requires the user to double-click the executable to run the malicious HTA file or to download a malicious installer.

T1204.002
Malicious File
MalwareBandook

Bandook has used lure documents to convince the user to enable macros.

T1204.002
Malicious File
MalwareKONNI

KONNI has relied on a victim to enable malicious macros within an attachment delivered via email.

T1204.002
Malicious File
MalwareDnsSystem

DnsSystem has lured victims into opening macro-enabled Word documents for execution.

T1204.002
Malicious File
MalwareKGH_SPY

KGH_SPY has been spread through Word documents containing malicious macros.

T1204.002
Malicious File
MalwareKerrdown

Kerrdown has gained execution through victims opening malicious files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.