Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.002 Malicious File |
MalwareBisonal | Bisonal has relied on users to execute malicious file attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
MalwareLumma Stealer | Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files. |
| T1204.002 Malicious File |
MalwareClambling | Clambling has gained execution through luring victims into opening malicious files. |
| T1204.002 Malicious File |
MalwareDarkGate | DarkGate initial infection payloads can masquerade as pirated media content requiring user interaction for code execution. DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution. |
| T1204.002 Malicious File |
MalwareMongall | Mongall has relied on a user opening a malicious document for execution. |
| T1204.002 Malicious File |
MalwareSVCReady | SVCReady has relied on users clicking a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareLatrodectus | Latrodectus has lured users into opening malicious email attachments for execution. |
| T1204.002 Malicious File |
MalwareSaint Bot | Saint Bot has relied on users to execute a malicious attachment delivered via spearphishing. |
| T1204.002 Malicious File |
MalwareChaes | Chaes requires the user to click on the malicious Word document to execute the next part of the attack. |
| T1204.002 Malicious File |
MalwareLODEINFO | LODEINFO has been executed via victims opening malicious email attachments. |
| T1204.002 Malicious File |
MalwareTYPEFRAME | A Word document delivering TYPEFRAME prompts the user to enable macro execution. |
| T1204.002 Malicious File |
MalwareBundlore | Bundlore has attempted to get users to execute a malicious .app file that looks like a Flash Player update. |
| T1204.002 Malicious File |
MalwareMetamorfo | Metamorfo requires the user to double-click the executable to run the malicious HTA file or to download a malicious installer. |
| T1204.002 Malicious File |
MalwareBandook | Bandook has used lure documents to convince the user to enable macros. |
| T1204.002 Malicious File |
MalwareKONNI | KONNI has relied on a victim to enable malicious macros within an attachment delivered via email. |
| T1204.002 Malicious File |
MalwareDnsSystem | DnsSystem has lured victims into opening macro-enabled Word documents for execution. |
| T1204.002 Malicious File |
MalwareKGH_SPY | KGH_SPY has been spread through Word documents containing malicious macros. |
| T1204.002 Malicious File |
MalwareKerrdown | Kerrdown has gained execution through victims opening malicious files. |
| T1204.002 Malicious File |
MalwareRedLine Stealer | RedLine Stealer malware has been executed through the download of malicious files. RedLine Stealer has also lured users to install malware with an Install Wizard interface. |
| T1204.002 Malicious File |
MalwareBlack Basta | Black Basta has been downloaded and executed from malicious Excel files. |
| T1204.002 Malicious File |
MalwareSQLRat | SQLRat relies on users clicking on an embedded image to execute the scripts. |
| T1204.002 Malicious File |
MalwareRTM | RTM has relied on users opening malicious email attachments, decompressing the attached archive, and double-clicking the executable within. |
| T1204.002 Malicious File |
MalwareStrelaStealer | StrelaStealer relies on user execution of a malicious file for installation. |
| T1204.002 Malicious File |
MalwareGrandoreiro | Grandoreiro has infected victims via malicious attachments. |
| T1204.002 Malicious File |
MalwareZxxZ | ZxxZ has relied on victims to open a malicious attachment delivered via email. |
| T1204.002 Malicious File |
MalwareSUGARDUMP | Some SUGARDUMP variants required a user to enable a macro within a malicious .xls file for execution. |
| T1204.002 Malicious File |
MalwareLunarMail | LunarMail has been installed through a malicious macro in a Microsoft Word document. |
| T1204.002 Malicious File |
MalwareJCry | JCry has achieved execution by luring users to click on a file that appeared to be an Adobe Flash Player update installer. |
| T1204.002 Malicious File |
MalwareREvil | REvil has been executed via malicious MS Word e-mail attachments. |
| T1204.002 Malicious File |
MalwareValak | Valak has been executed via Microsoft Word documents containing malicious macros. |
| T1204.002 Malicious File |
MalwareTaidoor | Taidoor has relied upon a victim to click on a malicious email attachment. |
| T1204.002 Malicious File |
MalwareNativeZone | NativeZone can display an RTF document to the user to enable execution of Cobalt Strike stage shellcode. |
| T1204.002 Malicious File |
MalwarePLEAD | PLEAD has been executed via malicious e-mail attachments. |
| T1204.002 Malicious File |
MalwareCardinal RAT | Cardinal RAT lures victims into executing malicious macros embedded within Microsoft Excel documents. |
| T1204.002 Malicious File |
MalwareDanBot | DanBot has relied on victims' opening a malicious file for initial execution. |
| T1204.002 Malicious File |
MalwareRamsay | Ramsay has been executed through malicious e-mail attachments. |
| T1204.002 Malicious File |
MalwareAshTag | AshTag has been executed through victims downloading and opening malicious RAR archive files. |
| T1204.002 Malicious File |
MalwareOutSteel | OutSteel has relied on a user to execute a malicious attachment delivered via spearphishing. |
| T1204.002 Malicious File |
MalwareBoomBox | BoomBox has gained execution through user interaction with a malicious file. |
| T1204.002 Malicious File |
MalwareLAMEHUG | LAMEHUG has been executed through victim interaction with malicious email attachments made to look like legitimate AI applications or documents. |
| T1204.002 Malicious File |
MalwareMango | Mango has been executed through a Microsoft Word document with a malicious macro. |
| T1204.002 Malicious File |
MalwareLokibot | Lokibot has tricked recipients into enabling malicious macros by getting victims to click "enable content" in email attachments. |
| T1204.002 Malicious File |
MalwarePoetRAT | PoetRAT has used spearphishing attachments to infect victims. |
| T1204.002 Malicious File |
MalwareHIUPAN | HIUPAN has lured victims into executing malicious files from USBs including the use of files such as USBconfig.exe. |
| T1204.002 Malicious File |
MalwareKOCTOPUS | KOCTOPUS has relied on victims clicking a malicious document for execution. |
| T1204.002 Malicious File |
MalwareHeyoka Backdoor | Heyoka Backdoor has been spread through malicious document lures. |
| T1204.002 Malicious File |
MalwareDisco | Disco has been executed through inducing user interaction with malicious .zip and .msi files. |
| T1204.002 Malicious File |
MalwareOctopus | Octopus has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareQilin | Qilin has been delivered to victims through spearphishing emails with malicious attachments. |
| T1204.002 Malicious File |
MalwareAppleJeus | AppleJeus has required user execution of a malicious MSI installer. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.