Real-world descriptions of how a group, tool or campaign used a technique.
98 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.002 Malicious File |
MalwareRedLine Stealer | RedLine Stealer malware has been executed through the download of malicious files. RedLine Stealer has also lured users to install malware with an Install Wizard interface. |
| T1204.002 Malicious File |
MalwareBlack Basta | Black Basta has been downloaded and executed from malicious Excel files. |
| T1204.002 Malicious File |
MalwareSQLRat | SQLRat relies on users clicking on an embedded image to execute the scripts. |
| T1204.002 Malicious File |
MalwareRTM | RTM has relied on users opening malicious email attachments, decompressing the attached archive, and double-clicking the executable within. |
| T1204.002 Malicious File |
MalwareStrelaStealer | StrelaStealer relies on user execution of a malicious file for installation. |
| T1204.002 Malicious File |
MalwareGrandoreiro | Grandoreiro has infected victims via malicious attachments. |
| T1204.002 Malicious File |
MalwareZxxZ | ZxxZ has relied on victims to open a malicious attachment delivered via email. |
| T1204.002 Malicious File |
MalwareSUGARDUMP | Some SUGARDUMP variants required a user to enable a macro within a malicious .xls file for execution. |
| T1204.002 Malicious File |
MalwareLunarMail | LunarMail has been installed through a malicious macro in a Microsoft Word document. |
| T1204.002 Malicious File |
MalwareJCry | JCry has achieved execution by luring users to click on a file that appeared to be an Adobe Flash Player update installer. |
| T1204.002 Malicious File |
MalwareREvil | REvil has been executed via malicious MS Word e-mail attachments. |
| T1204.002 Malicious File |
MalwareValak | Valak has been executed via Microsoft Word documents containing malicious macros. |
| T1204.002 Malicious File |
MalwareTaidoor | Taidoor has relied upon a victim to click on a malicious email attachment. |
| T1204.002 Malicious File |
MalwareNativeZone | NativeZone can display an RTF document to the user to enable execution of Cobalt Strike stage shellcode. |
| T1204.002 Malicious File |
MalwarePLEAD | PLEAD has been executed via malicious e-mail attachments. |
| T1204.002 Malicious File |
MalwareCardinal RAT | Cardinal RAT lures victims into executing malicious macros embedded within Microsoft Excel documents. |
| T1204.002 Malicious File |
MalwareDanBot | DanBot has relied on victims' opening a malicious file for initial execution. |
| T1204.002 Malicious File |
MalwareRamsay | Ramsay has been executed through malicious e-mail attachments. |
| T1204.002 Malicious File |
MalwareAshTag | AshTag has been executed through victims downloading and opening malicious RAR archive files. |
| T1204.002 Malicious File |
MalwareOutSteel | OutSteel has relied on a user to execute a malicious attachment delivered via spearphishing. |
| T1204.002 Malicious File |
MalwareBoomBox | BoomBox has gained execution through user interaction with a malicious file. |
| T1204.002 Malicious File |
MalwareLAMEHUG | LAMEHUG has been executed through victim interaction with malicious email attachments made to look like legitimate AI applications or documents. |
| T1204.002 Malicious File |
MalwareMango | Mango has been executed through a Microsoft Word document with a malicious macro. |
| T1204.002 Malicious File |
MalwareLokibot | Lokibot has tricked recipients into enabling malicious macros by getting victims to click "enable content" in email attachments. |
| T1204.002 Malicious File |
MalwarePoetRAT | PoetRAT has used spearphishing attachments to infect victims. |
| T1204.002 Malicious File |
MalwareHIUPAN | HIUPAN has lured victims into executing malicious files from USBs including the use of files such as USBconfig.exe. |
| T1204.002 Malicious File |
MalwareKOCTOPUS | KOCTOPUS has relied on victims clicking a malicious document for execution. |
| T1204.002 Malicious File |
MalwareHeyoka Backdoor | Heyoka Backdoor has been spread through malicious document lures. |
| T1204.002 Malicious File |
MalwareDisco | Disco has been executed through inducing user interaction with malicious .zip and .msi files. |
| T1204.002 Malicious File |
MalwareOctopus | Octopus has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareQilin | Qilin has been delivered to victims through spearphishing emails with malicious attachments. |
| T1204.002 Malicious File |
MalwareAppleJeus | AppleJeus has required user execution of a malicious MSI installer. |
| T1204.002 Malicious File |
MalwareSTARWHALE | STARWHALE has relied on victims opening a malicious Excel file for execution. |
| T1204.002 Malicious File |
MalwareAgent Tesla | Agent Tesla has been executed through malicious e-mail attachments |
| T1204.002 Malicious File |
MalwareAstaroth | Astaroth has used malicious files including VBS, LNK, and HTML for execution. |
| T1204.002 Malicious File |
MalwareQakBot | QakBot has gained execution through users opening malicious attachments. |
| T1204.002 Malicious File |
MalwareSYSCON | SYSCON has been executed by luring victims to open malicious e-mail attachments. |
| T1204.002 Malicious File |
MalwareHancitor | Hancitor has used malicious Microsoft Word documents, sent via email, which prompted the victim to enable macros. |
| T1204.002 Malicious File |
MalwareDridex | Dridex has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareOSX/Shlayer | OSX/Shlayer has relied on users mounting and executing a malicious DMG file. |
| T1204.002 Malicious File |
MalwareJSS Loader | JSS Loader has been executed through malicious attachments contained in spearphishing emails. |
| T1204.002 Malicious File |
MalwareWarzoneRAT | WarzoneRAT has relied on a victim to open a malicious attachment within an email for execution. |
| T1204.002 Malicious File |
ToolCSPY Downloader | CSPY Downloader has been delivered via malicious documents with embedded macros. |
| T1204.002 Malicious File |
ToolCARROTBALL | CARROTBALL has been executed through users being lured into opening malicious e-mail attachments. |
| T1204.002 Malicious File |
ToolAsyncRAT | AsyncRAT has been executed through victims opening malicious file attachments. |
| T1204.002 Malicious File |
ToolBrute Ratel C4 | Brute Ratel C4 has gained execution through users opening malicious documents. |
| T1204.002 Malicious File |
ToolRemcos | Remcos has been executed by luring victims into opening malicious email attachments including Excel files. |
| T1204.002 Malicious File |
MalwareBADFLICK | BADFLICK has relied upon users clicking on a malicious attachment delivered through spearphishing. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.