Real-world descriptions of how a group, tool or campaign used a technique.
61 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.001 Spearphishing Attachment |
MalwareTrickBot | TrickBot has used an email with an Excel sheet containing a malicious macro to deploy the malware |
| T1566.001 Spearphishing Attachment |
MalwareBLINDINGCAN | BLINDINGCAN has been delivered by phishing emails containing malicious Microsoft Office documents. |
| T1566.001 Spearphishing Attachment |
MalwareBumblebee | Bumblebee has gained execution through luring users into opening malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareKOPILUWAK | KOPILUWAK has been delivered to victims as a malicious email attachment. |
| T1566.001 Spearphishing Attachment |
MalwareThreatNeedle | ThreatNeedle has been distributed via a malicious Word document within a spearphishing email. |
| T1566.001 Spearphishing Attachment |
MalwarePony | Pony has been delivered via spearphishing attachments. |
| T1566.001 Spearphishing Attachment |
MalwareOceanSalt | OceanSalt has been delivered via spearphishing emails with Microsoft Office attachments. |
| T1566.001 Spearphishing Attachment |
MalwareAppleSeed | AppleSeed has been distributed to victims through malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareNETWIRE | NETWIRE has been spread via e-mail campaigns utilizing malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareEnvyScout | EnvyScout has been distributed via spearphishing as an email attachment. |
| T1566.001 Spearphishing Attachment |
MalwareEmotet | Emotet has been delivered by phishing emails containing attachments. |
| T1566.001 Spearphishing Attachment |
MalwareWoody RAT | Woody RAT has been delivered via malicious Word documents and archive files. |
| T1566.001 Spearphishing Attachment |
MalwareSquirrelwaffle | Squirrelwaffle has been distributed via malicious Microsoft Office documents within spam emails. |
| T1566.001 Spearphishing Attachment |
MalwareSnip3 | Snip3 has been delivered to victims through malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareRifdoor | Rifdoor has been distributed in e-mails with malicious Excel or Word documents. |
| T1566.001 Spearphishing Attachment |
MalwareRustyWater | RustyWater has sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primary payload for the next stage. |
| T1566.001 Spearphishing Attachment |
MalwareIcedID | IcedID has been delivered via phishing e-mails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareFlagpro | Flagpro has been distributed via spearphishing as an email attachment. |
| T1566.001 Spearphishing Attachment |
MalwareDarkTortilla | DarkTortilla has been distributed via spearphishing emails containing archive attachments, with file types such as .iso, .zip, .img, .dmg, and .tar, as well as through malicious documents. |
| T1566.001 Spearphishing Attachment |
MalwareROKRAT | ROKRAT has been delivered via spearphishing emails that contain a malicious Hangul Office or Microsoft Word document. |
| T1566.001 Spearphishing Attachment |
MalwareDarkWatchman | DarkWatchman has been delivered via spearphishing emails that contain a malicious zip file. |
| T1566.001 Spearphishing Attachment |
MalwareJavali | Javali has been delivered as malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareBisonal | Bisonal has been delivered as malicious email attachments. |
| T1566.001 Spearphishing Attachment |
MalwareLumma Stealer | Lumma Stealer has been delivered through phishing emails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareClambling | Clambling has been delivered to victim's machines through malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareDarkGate | DarkGate can be distributed through emails with malicious attachments from a spoofed email address. |
| T1566.001 Spearphishing Attachment |
MalwareSVCReady | SVCReady has been distributed via spearphishing campaigns containing malicious Mircrosoft Word documents. |
| T1566.001 Spearphishing Attachment |
MalwareLatrodectus | Latrodectus has been distributed through reply-chain phishing emails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareSaint Bot | Saint Bot has been distributed as malicious attachments within spearphishing emails. |
| T1566.001 Spearphishing Attachment |
MalwareChaes | Chaes has been delivered by sending victims a phishing email containing a malicious .docx file. |
| T1566.001 Spearphishing Attachment |
MalwareLODEINFO | LODEINFO has been distributed to targeted victims via malicious email attachments. |
| T1566.001 Spearphishing Attachment |
MalwareMetamorfo | Metamorfo has been delivered to victims via emails with malicious HTML attachments. |
| T1566.001 Spearphishing Attachment |
MalwareBandook | Bandook is delivered via a malicious Word document inside a zip file. |
| T1566.001 Spearphishing Attachment |
MalwareKONNI | KONNI has been delivered via spearphishing campaigns through a malicious Word document. |
| T1566.001 Spearphishing Attachment |
MalwareKerrdown | Kerrdown has been distributed through malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareRTM | RTM has been delivered via spearphishing attachments disguised as PDF documents. |
| T1566.001 Spearphishing Attachment |
MalwareStrelaStealer | StrelaStealer has been distributed as a spearphishing attachment. |
| T1566.001 Spearphishing Attachment |
MalwareZxxZ | ZxxZ has been distributed via spearphishing emails, usually containing a malicious RTF or Excel attachment. |
| T1566.001 Spearphishing Attachment |
MalwareXLoader | XLoader has been delivered as a phishing attachment, including PDFs with embedded links, Word and Excel files, and various archive files (ZIP, RAR, ACE, and ISOs) containing EXE payloads. |
| T1566.001 Spearphishing Attachment |
MalwareREvil | REvil has been distributed via malicious e-mail attachments including MS Word Documents. |
| T1566.001 Spearphishing Attachment |
MalwareValak | Valak has been delivered via spearphishing e-mails with password protected ZIP files. |
| T1566.001 Spearphishing Attachment |
MalwareTaidoor | Taidoor has been delivered through spearphishing emails. |
| T1566.001 Spearphishing Attachment |
MalwareDanBot | DanBot has been distributed within a malicious Excel attachment via spearphishing emails. |
| T1566.001 Spearphishing Attachment |
MalwareRamsay | Ramsay has been distributed through spearphishing emails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareOutSteel | OutSteel has been distributed as a malicious attachment within a spearphishing email. |
| T1566.001 Spearphishing Attachment |
MalwareLAMEHUG | LAMEHUG has been distributed through spearphishing emails with various AI-themed malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareLokibot | Lokibot is delivered via a malicious XLS attachment contained within a spearhpishing email. |
| T1566.001 Spearphishing Attachment |
MalwarePoetRAT | PoetRAT was distributed via malicious Word documents. |
| T1566.001 Spearphishing Attachment |
MalwareKOCTOPUS | KOCTOPUS has been distributed via spearphishing emails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareOctopus | Octopus has been delivered via spearsphishing emails. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.