ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1204.002
Malicious File
MalwareBisonal

Bisonal has relied on users to execute malicious file attachments delivered via spearphishing emails.

T1204.002
Malicious File
MalwareLumma Stealer

Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files.

T1204.002
Malicious File
MalwareClambling

Clambling has gained execution through luring victims into opening malicious files.

T1204.002
Malicious File
MalwareDarkGate

DarkGate initial infection payloads can masquerade as pirated media content requiring user interaction for code execution. DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.

T1204.002
Malicious File
MalwareMongall

Mongall has relied on a user opening a malicious document for execution.

T1204.002
Malicious File
MalwareSVCReady

SVCReady has relied on users clicking a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareLatrodectus

Latrodectus has lured users into opening malicious email attachments for execution.

T1204.002
Malicious File
MalwareSaint Bot

Saint Bot has relied on users to execute a malicious attachment delivered via spearphishing.

T1204.002
Malicious File
MalwareChaes

Chaes requires the user to click on the malicious Word document to execute the next part of the attack.

T1204.002
Malicious File
MalwareLODEINFO

LODEINFO has been executed via victims opening malicious email attachments.

T1204.002
Malicious File
MalwareTYPEFRAME

A Word document delivering TYPEFRAME prompts the user to enable macro execution.

T1204.002
Malicious File
MalwareBundlore

Bundlore has attempted to get users to execute a malicious .app file that looks like a Flash Player update.

T1204.002
Malicious File
MalwareMetamorfo

Metamorfo requires the user to double-click the executable to run the malicious HTA file or to download a malicious installer.

T1204.002
Malicious File
MalwareBandook

Bandook has used lure documents to convince the user to enable macros.

T1204.002
Malicious File
MalwareKONNI

KONNI has relied on a victim to enable malicious macros within an attachment delivered via email.

T1204.002
Malicious File
MalwareDnsSystem

DnsSystem has lured victims into opening macro-enabled Word documents for execution.

T1204.002
Malicious File
MalwareKGH_SPY

KGH_SPY has been spread through Word documents containing malicious macros.

T1204.002
Malicious File
MalwareKerrdown

Kerrdown has gained execution through victims opening malicious files.

T1204.002
Malicious File
MalwareRedLine Stealer

RedLine Stealer malware has been executed through the download of malicious files. RedLine Stealer has also lured users to install malware with an Install Wizard interface.

T1204.002
Malicious File
MalwareBlack Basta

Black Basta has been downloaded and executed from malicious Excel files.

T1204.002
Malicious File
MalwareSQLRat

SQLRat relies on users clicking on an embedded image to execute the scripts.

T1204.002
Malicious File
MalwareRTM

RTM has relied on users opening malicious email attachments, decompressing the attached archive, and double-clicking the executable within.

T1204.002
Malicious File
MalwareStrelaStealer

StrelaStealer relies on user execution of a malicious file for installation.

T1204.002
Malicious File
MalwareGrandoreiro

Grandoreiro has infected victims via malicious attachments.

T1204.002
Malicious File
MalwareZxxZ

ZxxZ has relied on victims to open a malicious attachment delivered via email.

T1204.002
Malicious File
MalwareSUGARDUMP

Some SUGARDUMP variants required a user to enable a macro within a malicious .xls file for execution.

T1204.002
Malicious File
MalwareLunarMail

LunarMail has been installed through a malicious macro in a Microsoft Word document.

T1204.002
Malicious File
MalwareJCry

JCry has achieved execution by luring users to click on a file that appeared to be an Adobe Flash Player update installer.

T1204.002
Malicious File
MalwareREvil

REvil has been executed via malicious MS Word e-mail attachments.

T1204.002
Malicious File
MalwareValak

Valak has been executed via Microsoft Word documents containing malicious macros.

T1204.002
Malicious File
MalwareTaidoor

Taidoor has relied upon a victim to click on a malicious email attachment.

T1204.002
Malicious File
MalwareNativeZone

NativeZone can display an RTF document to the user to enable execution of Cobalt Strike stage shellcode.

T1204.002
Malicious File
MalwarePLEAD

PLEAD has been executed via malicious e-mail attachments.

T1204.002
Malicious File
MalwareCardinal RAT

Cardinal RAT lures victims into executing malicious macros embedded within Microsoft Excel documents.

T1204.002
Malicious File
MalwareDanBot

DanBot has relied on victims' opening a malicious file for initial execution.

T1204.002
Malicious File
MalwareRamsay

Ramsay has been executed through malicious e-mail attachments.

T1204.002
Malicious File
MalwareAshTag

AshTag has been executed through victims downloading and opening malicious RAR archive files.

T1204.002
Malicious File
MalwareOutSteel

OutSteel has relied on a user to execute a malicious attachment delivered via spearphishing.

T1204.002
Malicious File
MalwareBoomBox

BoomBox has gained execution through user interaction with a malicious file.

T1204.002
Malicious File
MalwareLAMEHUG

LAMEHUG has been executed through victim interaction with malicious email attachments made to look like legitimate AI applications or documents.

T1204.002
Malicious File
MalwareMango

Mango has been executed through a Microsoft Word document with a malicious macro.

T1204.002
Malicious File
MalwareLokibot

Lokibot has tricked recipients into enabling malicious macros by getting victims to click "enable content" in email attachments.

T1204.002
Malicious File
MalwarePoetRAT

PoetRAT has used spearphishing attachments to infect victims.

T1204.002
Malicious File
MalwareHIUPAN

HIUPAN has lured victims into executing malicious files from USBs including the use of files such as USBconfig.exe.

T1204.002
Malicious File
MalwareKOCTOPUS

KOCTOPUS has relied on victims clicking a malicious document for execution.

T1204.002
Malicious File
MalwareHeyoka Backdoor

Heyoka Backdoor has been spread through malicious document lures.

T1204.002
Malicious File
MalwareDisco

Disco has been executed through inducing user interaction with malicious .zip and .msi files.

T1204.002
Malicious File
MalwareOctopus

Octopus has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareQilin

Qilin has been delivered to victims through spearphishing emails with malicious attachments.

T1204.002
Malicious File
MalwareAppleJeus

AppleJeus has required user execution of a malicious MSI installer.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.