Real-world descriptions of how a group, tool or campaign used a technique.
86 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.002 Malicious File |
GroupStar Blizzard | Star Blizzard has lured targets into opening malicious .pdf files to deliver malware. |
| T1204.002 Malicious File |
GroupDarkhotel | Darkhotel has sent spearphishing emails in an attempt to lure users into clicking on a malicious attachments. |
| T1204.002 Malicious File |
GroupLazyScripter | LazyScripter has lured users to open malicious email attachments. |
| T1204.002 Malicious File |
GroupWindshift | Windshift has used e-mail attachments to lure victims into executing malicious code. |
| T1204.002 Malicious File |
GroupWhitefly | Whitefly has used malicious .exe or .dll files disguised as documents or images. |
| T1204.002 Malicious File |
GroupAPT28 | APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts. |
| T1204.002 Malicious File |
GroupMalteiro | Malteiro has relied on users to execute .zip file attachments containing malicious URLs. |
| T1204.002 Malicious File |
GroupRTM | RTM has attempted to lure victims into opening e-mail attachments to execute malicious code. |
| T1204.002 Malicious File |
GroupAPT12 | APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing. |
| T1204.002 Malicious File |
GroupAPT-C-36 | APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware. |
| T1204.002 Malicious File |
GroupTonto Team | Tonto Team has relied on user interaction to open their malicious RTF documents. |
| T1204.002 Malicious File |
GroupLazarus Group | Lazarus Group has attempted to get users to launch a malicious Microsoft Word attachment delivered via a spearphishing email. |
| T1204.002 Malicious File |
GroupEarth Lusca | Earth Lusca required users to click on a malicious file for the loader to activate. |
| T1204.002 Malicious File |
GroupFIN4 | FIN4 has lured victims to launch malicious attachments delivered via spearphishing emails (often sent from compromised accounts). |
| T1204.002 Malicious File |
GroupSilence | Silence attempts to get users to launch malicious attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupCobalt Group | Cobalt Group has sent emails containing malicious attachments that require users to execute a file or macro to infect the victim machine. |
| T1204.002 Malicious File |
GroupWizard Spider | Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar. |
| T1204.002 Malicious File |
GroupMolerats | Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives. |
| T1204.002 Malicious File |
GroupTransparent Tribe | Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems. |
| T1204.002 Malicious File |
GroupIndigoZebra | IndigoZebra sent spearphishing emails containing malicious attachments that urged recipients to review modifications in the file which would trigger the attack. |
| T1204.002 Malicious File |
GroupMoonstone Sleet | Moonstone Sleet relied on users interacting with malicious files, such as a trojanized PuTTY installer, for initial execution. |
| T1204.002 Malicious File |
GroupInception | Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware. |
| T1204.002 Malicious File |
GroupVOID MANTICORE | VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file. VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance. |
| T1204.002 Malicious File |
GroupPROMETHIUM | PROMETHIUM has attempted to get users to execute compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities. |
| T1204.002 Malicious File |
GroupAPT30 | APT30 has relied on users to execute malicious file attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupHEXANE | HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware. |
| T1204.002 Malicious File |
GroupRancor | Rancor attempted to get users to click on an embedded macro within a Microsoft Office Excel document to launch their malware. |
| T1204.002 Malicious File |
GroupWIRTE | WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads. |
| T1204.002 Malicious File |
GroupPLATINUM | PLATINUM has attempted to get users to open malicious files by sending spearphishing emails with attachments to victims. |
| T1204.002 Malicious File |
GroupMagic Hound | Magic Hound has attempted to lure victims into opening malicious email attachments. |
| T1204.002 Malicious File |
GroupAjax Security Team | Ajax Security Team has lured victims into executing malicious files. |
| T1204.002 Malicious File |
GroupThreat Group-3390 | Threat Group-3390 has lured victims into opening malicious files containing malware. |
| T1204.002 Malicious File |
GroupAPT33 | APT33 has used malicious e-mail attachments to lure victims into executing malware. |
| T1204.002 Malicious File |
GroupFIN8 | FIN8 has used malicious e-mail attachments to lure victims into executing malware. |
| T1204.002 Malicious File |
GroupAPT19 | APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupNomadic Octopus | Nomadic Octopus as attempted to lure victims into clicking on malicious attachments within spearphishing emails. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.