ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1566.001×

61 examples

TechniqueUsed byProcedure example
T1566.001
Spearphishing Attachment
MalwareQilin

Qilin has been delivered to victims through malicious email attachments.

T1566.001
Spearphishing Attachment
MalwareAgent Tesla

The primary delivered mechanism for Agent Tesla is through email phishing messages.

T1566.001
Spearphishing Attachment
MalwareAstaroth

Astaroth has been delivered via malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareQakBot

QakBot has spread through emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareHancitor

Hancitor has been delivered via phishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareJSS Loader

JSS Loader has been delivered by phishing emails containing malicious Microsoft Excel attachments.

T1566.001
Spearphishing Attachment
MalwareWarzoneRAT

WarzoneRAT has been distributed as a malicious attachment within an email.

T1566.001
Spearphishing Attachment
ToolAsyncRAT

AsyncRAT has been delivered via malicious email attachments.

T1566.001
Spearphishing Attachment
ToolRemcos

Remcos has been spread through emails containing malicious documents.

T1566.001
Spearphishing Attachment
MalwareKali365

Kali365 has delivered phishing emails with malicious PDF, Word, Excel, and PowerPoint attachments that direct victims to actor-controlled landing pages.

T1566.001
Spearphishing Attachment
MalwareBADFLICK

BADFLICK has been distributed via spearphishing campaigns containing malicious Microsoft Word documents.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.