ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1204.002×

86 examples

TechniqueUsed byProcedure example
T1204.002
Malicious File
GroupStar Blizzard

Star Blizzard has lured targets into opening malicious .pdf files to deliver malware.

T1204.002
Malicious File
GroupDarkhotel

Darkhotel has sent spearphishing emails in an attempt to lure users into clicking on a malicious attachments.

T1204.002
Malicious File
GroupLazyScripter

LazyScripter has lured users to open malicious email attachments.

T1204.002
Malicious File
GroupWindshift

Windshift has used e-mail attachments to lure victims into executing malicious code.

T1204.002
Malicious File
GroupWhitefly

Whitefly has used malicious .exe or .dll files disguised as documents or images.

T1204.002
Malicious File
GroupAPT28

APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts.

T1204.002
Malicious File
GroupMalteiro

Malteiro has relied on users to execute .zip file attachments containing malicious URLs.

T1204.002
Malicious File
GroupRTM

RTM has attempted to lure victims into opening e-mail attachments to execute malicious code.

T1204.002
Malicious File
GroupAPT12

APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing.

T1204.002
Malicious File
GroupAPT-C-36

APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware.

T1204.002
Malicious File
GroupTonto Team

Tonto Team has relied on user interaction to open their malicious RTF documents.

T1204.002
Malicious File
GroupLazarus Group

Lazarus Group has attempted to get users to launch a malicious Microsoft Word attachment delivered via a spearphishing email.

T1204.002
Malicious File
GroupEarth Lusca

Earth Lusca required users to click on a malicious file for the loader to activate.

T1204.002
Malicious File
GroupFIN4

FIN4 has lured victims to launch malicious attachments delivered via spearphishing emails (often sent from compromised accounts).

T1204.002
Malicious File
GroupSilence

Silence attempts to get users to launch malicious attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupCobalt Group

Cobalt Group has sent emails containing malicious attachments that require users to execute a file or macro to infect the victim machine.

T1204.002
Malicious File
GroupWizard Spider

Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar.

T1204.002
Malicious File
GroupMolerats

Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives.

T1204.002
Malicious File
GroupTransparent Tribe

Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems.

T1204.002
Malicious File
GroupIndigoZebra

IndigoZebra sent spearphishing emails containing malicious attachments that urged recipients to review modifications in the file which would trigger the attack.

T1204.002
Malicious File
GroupMoonstone Sleet

Moonstone Sleet relied on users interacting with malicious files, such as a trojanized PuTTY installer, for initial execution.

T1204.002
Malicious File
GroupInception

Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware.

T1204.002
Malicious File
GroupVOID MANTICORE

VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file. VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance.

T1204.002
Malicious File
GroupPROMETHIUM

PROMETHIUM has attempted to get users to execute compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.

T1204.002
Malicious File
GroupAPT30

APT30 has relied on users to execute malicious file attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupHEXANE

HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware.

T1204.002
Malicious File
GroupRancor

Rancor attempted to get users to click on an embedded macro within a Microsoft Office Excel document to launch their malware.

T1204.002
Malicious File
GroupWIRTE

WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads.

T1204.002
Malicious File
GroupPLATINUM

PLATINUM has attempted to get users to open malicious files by sending spearphishing emails with attachments to victims.

T1204.002
Malicious File
GroupMagic Hound

Magic Hound has attempted to lure victims into opening malicious email attachments.

T1204.002
Malicious File
GroupAjax Security Team

Ajax Security Team has lured victims into executing malicious files.

T1204.002
Malicious File
GroupThreat Group-3390

Threat Group-3390 has lured victims into opening malicious files containing malware.

T1204.002
Malicious File
GroupAPT33

APT33 has used malicious e-mail attachments to lure victims into executing malware.

T1204.002
Malicious File
GroupFIN8

FIN8 has used malicious e-mail attachments to lure victims into executing malware.

T1204.002
Malicious File
GroupAPT19

APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupNomadic Octopus

Nomadic Octopus as attempted to lure victims into clicking on malicious attachments within spearphishing emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.