Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.001 Malicious Link |
MalwareJavali | Javali has achieved execution through victims clicking links to malicious websites. |
| T1204.001 Malicious Link |
MalwareTSCookie | TSCookie has been executed via malicious links embedded in e-mails spoofing the Ministries of Education, Culture, Sports, Science and Technology of Japan. |
| T1204.001 Malicious Link |
MalwareLatrodectus | Latrodectus has been executed through malicious links distributed in email campaigns. |
| T1204.001 Malicious Link |
MalwareSaint Bot | Saint Bot has relied on users to click on a malicious link delivered via a spearphishing. |
| T1204.001 Malicious Link |
MalwareSMOKEDHAM | SMOKEDHAM has relied upon users clicking on a malicious link delivered through phishing. |
| T1204.001 Malicious Link |
MalwareKerrdown | Kerrdown has gained execution through victims opening malicious links. |
| T1204.001 Malicious Link |
MalwareGrandoreiro | Grandoreiro has used malicious links to gain execution on victim machines. |
| T1204.001 Malicious Link |
MalwareBazar | Bazar can gain execution after a user clicks on a malicious link to decoy landing pages hosted on Google Docs. |
| T1204.001 Malicious Link |
MalwarePLEAD | PLEAD has been executed via malicious links in e-mails. |
| T1204.001 Malicious Link |
MalwareOutSteel | OutSteel has relied on a user to click a malicious link within a spearphishing email. |
| T1204.001 Malicious Link |
MalwareBackConfig | BackConfig has compromised victims via links to URLs hosting malicious content. |
| T1204.001 Malicious Link |
MalwareMelcoz | Melcoz has gained execution through victims opening malicious links. |
| T1204.001 Malicious Link |
MalwareKOCTOPUS | KOCTOPUS has relied on victims clicking on a malicious link delivered via email. |
| T1204.001 Malicious Link |
MalwareQilin | Qilin has been executed by luring victims into clicking links in spearphishing emails. |
| T1204.001 Malicious Link |
MalwareAppleJeus | AppleJeus's spearphishing links required user interaction to navigate to the malicious website. |
| T1204.001 Malicious Link |
MalwareQakBot | QakBot has gained execution through users opening malicious links. |
| T1204.001 Malicious Link |
MalwareHancitor | Hancitor has relied upon users clicking on a malicious link delivered through phishing. |
| T1204.001 Malicious Link |
MalwareKali365 | Kali365 has directed victims to actor-controlled phishing pages through malicious links, initiating device code authorization flows or adversary-in-the-middle session capture. |
| T1204.002 Malicious File |
MalwareTrickBot | TrickBot has attempted to get users to launch malicious documents to deliver its payload. |
| T1204.002 Malicious File |
MalwareBLINDINGCAN | BLINDINGCAN has lured victims into executing malicious macros embedded within Microsoft Office documents. |
| T1204.002 Malicious File |
MalwareNinja | Ninja has gained execution through victims opening malicious executable files embedded in zip archives. |
| T1204.002 Malicious File |
MalwareBumblebee | Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs. |
| T1204.002 Malicious File |
MalwareKOPILUWAK | KOPILUWAK has gained execution through malicious attachments. |
| T1204.002 Malicious File |
MalwareThreatNeedle | ThreatNeedle relies on a victim to click on a malicious document for initial execution. |
| T1204.002 Malicious File |
MalwareHavoc | Havoc has been executed by victims through the use of targeted lures and crafted decoy documents. |
| T1204.002 Malicious File |
MalwareStrongPity | StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities. |
| T1204.002 Malicious File |
MalwarePony | Pony has attempted to lure targets into downloading an attached executable (ZIP, RAR, or CAB archives) or document (PDF or other MS Office format). |
| T1204.002 Malicious File |
MalwareROAMINGHOUSE | During Operation AkaiRyū, MirrorFace used malicious files to drop ROAMINGHOUSE. |
| T1204.002 Malicious File |
MalwareAppleSeed | AppleSeed can achieve execution through users running malicious file attachments distributed via email. |
| T1204.002 Malicious File |
MalwareNETWIRE | NETWIRE has been executed through luring victims into opening malicious documents. |
| T1204.002 Malicious File |
MalwareBad Rabbit | Bad Rabbit has been executed through user installation of an executable disguised as a flash installer. |
| T1204.002 Malicious File |
MalwareEnvyScout | EnvyScout has been executed through malicious files attached to e-mails. |
| T1204.002 Malicious File |
MalwareSTATICPLUGIN | STATICPLUGIN has required user execution to load subsequent malicious payloads. |
| T1204.002 Malicious File |
MalwareEmotet | Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareWoody RAT | Woody RAT has relied on users opening a malicious email attachment for execution. |
| T1204.002 Malicious File |
MalwareSquirrelwaffle | Squirrelwaffle has relied on users enabling malicious macros within Microsoft Excel and Word attachments. |
| T1204.002 Malicious File |
MalwareSnip3 | Snip3 can gain execution through the download of visual basic files. |
| T1204.002 Malicious File |
MalwareRifdoor | Rifdoor has been executed from malicious Excel or Word documents containing macros. |
| T1204.002 Malicious File |
MalwareGuLoader | The GuLoader executable has been retrieved via embedded macros in malicious Word documents. |
| T1204.002 Malicious File |
MalwareInvisiMole | InvisiMole can deliver trojanized versions of software and documents, relying on user execution. |
| T1204.002 Malicious File |
MalwareCLAIMLOADER | CLAIMLOADER has used tailored decoy documents as part of the installation routine to entice users to open attachments. |
| T1204.002 Malicious File |
MalwareMispadu | Mispadu has relied on users to execute malicious files in order to gain execution on victim machines. |
| T1204.002 Malicious File |
MalwareRustyWater | RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. |
| T1204.002 Malicious File |
MalwareIcedID | IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL. |
| T1204.002 Malicious File |
MalwareFlagpro | Flagpro has relied on users clicking a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareDarkTortilla | DarkTortilla has relied on a user to open a malicious document or archived file delivered via email for initial execution. |
| T1204.002 Malicious File |
MalwareBeaverTail | BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications. |
| T1204.002 Malicious File |
MalwareROKRAT | ROKRAT has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareJavali | Javali has achieved execution through victims opening malicious attachments, including MSI files with embedded VBScript. |
| T1204.002 Malicious File |
MalwarePlugX | PlugX has leveraged an initial executable disguised as a legitimate document to trick the target into opening it. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.