ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1566.001×

78 examples

TechniqueUsed byProcedure example
T1566.001
Spearphishing Attachment
GroupLazyScripter

LazyScripter has used spam emails weaponized with archive or document files as its initial infection vector.

T1566.001
Spearphishing Attachment
GroupWindshift

Windshift has sent spearphishing emails with attachment to harvest credentials and deliver malware.

T1566.001
Spearphishing Attachment
GroupAPT28

APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments.

T1566.001
Spearphishing Attachment
GroupMalteiro

Malteiro has sent spearphishing emails containing malicious .zip files.

T1566.001
Spearphishing Attachment
GroupRTM

RTM has used spearphishing attachments to distribute its malware.

T1566.001
Spearphishing Attachment
GroupAPT12

APT12 has sent emails with malicious Microsoft Office documents and PDFs attached.

T1566.001
Spearphishing Attachment
GroupAPT-C-36

APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway.

T1566.001
Spearphishing Attachment
GroupTonto Team

Tonto Team has delivered payloads via spearphishing attachments.

T1566.001
Spearphishing Attachment
GroupLazarus Group

Lazarus Group has targeted victims with spearphishing emails containing malicious Microsoft Word documents.

T1566.001
Spearphishing Attachment
GroupFIN4

FIN4 has used spearphishing emails containing attachments (which are often stolen, legitimate documents sent from compromised accounts) with embedded malicious macros.

T1566.001
Spearphishing Attachment
GroupSilence

Silence has sent emails with malicious DOCX, CHM, LNK and ZIP attachments.

T1566.001
Spearphishing Attachment
GroupCobalt Group

Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables.

T1566.001
Spearphishing Attachment
GroupWizard Spider

Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar.

T1566.001
Spearphishing Attachment
GroupMolerats

Molerats has sent phishing emails with malicious Microsoft Word and PDF attachments.

T1566.001
Spearphishing Attachment
GroupTransparent Tribe

Transparent Tribe has sent spearphishing e-mails with attachments to deliver malicious payloads.

T1566.001
Spearphishing Attachment
GroupIndigoZebra

IndigoZebra sent spearphishing emails containing malicious password-protected RAR attachments.

T1566.001
Spearphishing Attachment
GroupMoonstone Sleet

Moonstone Sleet delivered various payloads to victims as spearphishing attachments.

T1566.001
Spearphishing Attachment
GroupInception

Inception has used weaponized documents attached to spearphishing emails for reconnaissance and initial compromise.

T1566.001
Spearphishing Attachment
GroupAPT30

APT30 has used spearphishing emails with malicious DOC attachments.

T1566.001
Spearphishing Attachment
GroupRancor

Rancor has attached a malicious document to an email to gain initial access.

T1566.001
Spearphishing Attachment
GroupWIRTE

WIRTE has sent emails to intended victims with malicious MS Word and Excel attachments.

T1566.001
Spearphishing Attachment
GroupPLATINUM

PLATINUM has sent spearphishing emails with attachments to victims as its primary initial access vector.

T1566.001
Spearphishing Attachment
GroupAjax Security Team

Ajax Security Team has used personalized spearphishing attachments.

T1566.001
Spearphishing Attachment
GroupThreat Group-3390

Threat Group-3390 has used e-mail to deliver malicious attachments to victims.

T1566.001
Spearphishing Attachment
GroupAPT33

APT33 has sent spearphishing e-mails with archive attachments.

T1566.001
Spearphishing Attachment
GroupFIN8

FIN8 has distributed targeted emails containing Word documents with embedded malicious macros.

T1566.001
Spearphishing Attachment
GroupAPT19

APT19 sent spearphishing emails with malicious attachments in RTF and XLSM formats to deliver initial exploits.

T1566.001
Spearphishing Attachment
GroupNomadic Octopus

Nomadic Octopus has targeted victims with spearphishing emails containing malicious attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.