ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1204.002×

98 examples

TechniqueUsed byProcedure example
T1204.002
Malicious File
MalwareRedLine Stealer

RedLine Stealer malware has been executed through the download of malicious files. RedLine Stealer has also lured users to install malware with an Install Wizard interface.

T1204.002
Malicious File
MalwareBlack Basta

Black Basta has been downloaded and executed from malicious Excel files.

T1204.002
Malicious File
MalwareSQLRat

SQLRat relies on users clicking on an embedded image to execute the scripts.

T1204.002
Malicious File
MalwareRTM

RTM has relied on users opening malicious email attachments, decompressing the attached archive, and double-clicking the executable within.

T1204.002
Malicious File
MalwareStrelaStealer

StrelaStealer relies on user execution of a malicious file for installation.

T1204.002
Malicious File
MalwareGrandoreiro

Grandoreiro has infected victims via malicious attachments.

T1204.002
Malicious File
MalwareZxxZ

ZxxZ has relied on victims to open a malicious attachment delivered via email.

T1204.002
Malicious File
MalwareSUGARDUMP

Some SUGARDUMP variants required a user to enable a macro within a malicious .xls file for execution.

T1204.002
Malicious File
MalwareLunarMail

LunarMail has been installed through a malicious macro in a Microsoft Word document.

T1204.002
Malicious File
MalwareJCry

JCry has achieved execution by luring users to click on a file that appeared to be an Adobe Flash Player update installer.

T1204.002
Malicious File
MalwareREvil

REvil has been executed via malicious MS Word e-mail attachments.

T1204.002
Malicious File
MalwareValak

Valak has been executed via Microsoft Word documents containing malicious macros.

T1204.002
Malicious File
MalwareTaidoor

Taidoor has relied upon a victim to click on a malicious email attachment.

T1204.002
Malicious File
MalwareNativeZone

NativeZone can display an RTF document to the user to enable execution of Cobalt Strike stage shellcode.

T1204.002
Malicious File
MalwarePLEAD

PLEAD has been executed via malicious e-mail attachments.

T1204.002
Malicious File
MalwareCardinal RAT

Cardinal RAT lures victims into executing malicious macros embedded within Microsoft Excel documents.

T1204.002
Malicious File
MalwareDanBot

DanBot has relied on victims' opening a malicious file for initial execution.

T1204.002
Malicious File
MalwareRamsay

Ramsay has been executed through malicious e-mail attachments.

T1204.002
Malicious File
MalwareAshTag

AshTag has been executed through victims downloading and opening malicious RAR archive files.

T1204.002
Malicious File
MalwareOutSteel

OutSteel has relied on a user to execute a malicious attachment delivered via spearphishing.

T1204.002
Malicious File
MalwareBoomBox

BoomBox has gained execution through user interaction with a malicious file.

T1204.002
Malicious File
MalwareLAMEHUG

LAMEHUG has been executed through victim interaction with malicious email attachments made to look like legitimate AI applications or documents.

T1204.002
Malicious File
MalwareMango

Mango has been executed through a Microsoft Word document with a malicious macro.

T1204.002
Malicious File
MalwareLokibot

Lokibot has tricked recipients into enabling malicious macros by getting victims to click "enable content" in email attachments.

T1204.002
Malicious File
MalwarePoetRAT

PoetRAT has used spearphishing attachments to infect victims.

T1204.002
Malicious File
MalwareHIUPAN

HIUPAN has lured victims into executing malicious files from USBs including the use of files such as USBconfig.exe.

T1204.002
Malicious File
MalwareKOCTOPUS

KOCTOPUS has relied on victims clicking a malicious document for execution.

T1204.002
Malicious File
MalwareHeyoka Backdoor

Heyoka Backdoor has been spread through malicious document lures.

T1204.002
Malicious File
MalwareDisco

Disco has been executed through inducing user interaction with malicious .zip and .msi files.

T1204.002
Malicious File
MalwareOctopus

Octopus has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareQilin

Qilin has been delivered to victims through spearphishing emails with malicious attachments.

T1204.002
Malicious File
MalwareAppleJeus

AppleJeus has required user execution of a malicious MSI installer.

T1204.002
Malicious File
MalwareSTARWHALE

STARWHALE has relied on victims opening a malicious Excel file for execution.

T1204.002
Malicious File
MalwareAgent Tesla

Agent Tesla has been executed through malicious e-mail attachments

T1204.002
Malicious File
MalwareAstaroth

Astaroth has used malicious files including VBS, LNK, and HTML for execution.

T1204.002
Malicious File
MalwareQakBot

QakBot has gained execution through users opening malicious attachments.

T1204.002
Malicious File
MalwareSYSCON

SYSCON has been executed by luring victims to open malicious e-mail attachments.

T1204.002
Malicious File
MalwareHancitor

Hancitor has used malicious Microsoft Word documents, sent via email, which prompted the victim to enable macros.

T1204.002
Malicious File
MalwareDridex

Dridex has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareOSX/Shlayer

OSX/Shlayer has relied on users mounting and executing a malicious DMG file.

T1204.002
Malicious File
MalwareJSS Loader

JSS Loader has been executed through malicious attachments contained in spearphishing emails.

T1204.002
Malicious File
MalwareWarzoneRAT

WarzoneRAT has relied on a victim to open a malicious attachment within an email for execution.

T1204.002
Malicious File
ToolCSPY Downloader

CSPY Downloader has been delivered via malicious documents with embedded macros.

T1204.002
Malicious File
ToolCARROTBALL

CARROTBALL has been executed through users being lured into opening malicious e-mail attachments.

T1204.002
Malicious File
ToolAsyncRAT

AsyncRAT has been executed through victims opening malicious file attachments.

T1204.002
Malicious File
ToolBrute Ratel C4

Brute Ratel C4 has gained execution through users opening malicious documents.

T1204.002
Malicious File
ToolRemcos

Remcos has been executed by luring victims into opening malicious email attachments including Excel files.

T1204.002
Malicious File
MalwareBADFLICK

BADFLICK has relied upon users clicking on a malicious attachment delivered through spearphishing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.