ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1204.001
Malicious Link
MalwareJavali

Javali has achieved execution through victims clicking links to malicious websites.

T1204.001
Malicious Link
MalwareTSCookie

TSCookie has been executed via malicious links embedded in e-mails spoofing the Ministries of Education, Culture, Sports, Science and Technology of Japan.

T1204.001
Malicious Link
MalwareLatrodectus

Latrodectus has been executed through malicious links distributed in email campaigns.

T1204.001
Malicious Link
MalwareSaint Bot

Saint Bot has relied on users to click on a malicious link delivered via a spearphishing.

T1204.001
Malicious Link
MalwareSMOKEDHAM

SMOKEDHAM has relied upon users clicking on a malicious link delivered through phishing.

T1204.001
Malicious Link
MalwareKerrdown

Kerrdown has gained execution through victims opening malicious links.

T1204.001
Malicious Link
MalwareGrandoreiro

Grandoreiro has used malicious links to gain execution on victim machines.

T1204.001
Malicious Link
MalwareBazar

Bazar can gain execution after a user clicks on a malicious link to decoy landing pages hosted on Google Docs.

T1204.001
Malicious Link
MalwarePLEAD

PLEAD has been executed via malicious links in e-mails.

T1204.001
Malicious Link
MalwareOutSteel

OutSteel has relied on a user to click a malicious link within a spearphishing email.

T1204.001
Malicious Link
MalwareBackConfig

BackConfig has compromised victims via links to URLs hosting malicious content.

T1204.001
Malicious Link
MalwareMelcoz

Melcoz has gained execution through victims opening malicious links.

T1204.001
Malicious Link
MalwareKOCTOPUS

KOCTOPUS has relied on victims clicking on a malicious link delivered via email.

T1204.001
Malicious Link
MalwareQilin

Qilin has been executed by luring victims into clicking links in spearphishing emails.

T1204.001
Malicious Link
MalwareAppleJeus

AppleJeus's spearphishing links required user interaction to navigate to the malicious website.

T1204.001
Malicious Link
MalwareQakBot

QakBot has gained execution through users opening malicious links.

T1204.001
Malicious Link
MalwareHancitor

Hancitor has relied upon users clicking on a malicious link delivered through phishing.

T1204.001
Malicious Link
MalwareKali365

Kali365 has directed victims to actor-controlled phishing pages through malicious links, initiating device code authorization flows or adversary-in-the-middle session capture.

T1204.002
Malicious File
MalwareTrickBot

TrickBot has attempted to get users to launch malicious documents to deliver its payload.

T1204.002
Malicious File
MalwareBLINDINGCAN

BLINDINGCAN has lured victims into executing malicious macros embedded within Microsoft Office documents.

T1204.002
Malicious File
MalwareNinja

Ninja has gained execution through victims opening malicious executable files embedded in zip archives.

T1204.002
Malicious File
MalwareBumblebee

Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs.

T1204.002
Malicious File
MalwareKOPILUWAK

KOPILUWAK has gained execution through malicious attachments.

T1204.002
Malicious File
MalwareThreatNeedle

ThreatNeedle relies on a victim to click on a malicious document for initial execution.

T1204.002
Malicious File
MalwareHavoc

Havoc has been executed by victims through the use of targeted lures and crafted decoy documents.

T1204.002
Malicious File
MalwareStrongPity

StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.

T1204.002
Malicious File
MalwarePony

Pony has attempted to lure targets into downloading an attached executable (ZIP, RAR, or CAB archives) or document (PDF or other MS Office format).

T1204.002
Malicious File
MalwareROAMINGHOUSE

During Operation AkaiRyū, MirrorFace used malicious files to drop ROAMINGHOUSE.

T1204.002
Malicious File
MalwareAppleSeed

AppleSeed can achieve execution through users running malicious file attachments distributed via email.

T1204.002
Malicious File
MalwareNETWIRE

NETWIRE has been executed through luring victims into opening malicious documents.

T1204.002
Malicious File
MalwareBad Rabbit

Bad Rabbit has been executed through user installation of an executable disguised as a flash installer.

T1204.002
Malicious File
MalwareEnvyScout

EnvyScout has been executed through malicious files attached to e-mails.

T1204.002
Malicious File
MalwareSTATICPLUGIN

STATICPLUGIN has required user execution to load subsequent malicious payloads.

T1204.002
Malicious File
MalwareEmotet

Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareWoody RAT

Woody RAT has relied on users opening a malicious email attachment for execution.

T1204.002
Malicious File
MalwareSquirrelwaffle

Squirrelwaffle has relied on users enabling malicious macros within Microsoft Excel and Word attachments.

T1204.002
Malicious File
MalwareSnip3

Snip3 can gain execution through the download of visual basic files.

T1204.002
Malicious File
MalwareRifdoor

Rifdoor has been executed from malicious Excel or Word documents containing macros.

T1204.002
Malicious File
MalwareGuLoader

The GuLoader executable has been retrieved via embedded macros in malicious Word documents.

T1204.002
Malicious File
MalwareInvisiMole

InvisiMole can deliver trojanized versions of software and documents, relying on user execution.

T1204.002
Malicious File
MalwareCLAIMLOADER

CLAIMLOADER has used tailored decoy documents as part of the installation routine to entice users to open attachments.

T1204.002
Malicious File
MalwareMispadu

Mispadu has relied on users to execute malicious files in order to gain execution on victim machines.

T1204.002
Malicious File
MalwareRustyWater

RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1204.002
Malicious File
MalwareIcedID

IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL.

T1204.002
Malicious File
MalwareFlagpro

Flagpro has relied on users clicking a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareDarkTortilla

DarkTortilla has relied on a user to open a malicious document or archived file delivered via email for initial execution.

T1204.002
Malicious File
MalwareBeaverTail

BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications.

T1204.002
Malicious File
MalwareROKRAT

ROKRAT has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareJavali

Javali has achieved execution through victims opening malicious attachments, including MSI files with embedded VBScript.

T1204.002
Malicious File
MalwarePlugX

PlugX has leveraged an initial executable disguised as a legitimate document to trick the target into opening it.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.