ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1566.001
Spearphishing Attachment
MalwareSaint Bot

Saint Bot has been distributed as malicious attachments within spearphishing emails.

T1566.001
Spearphishing Attachment
MalwareChaes

Chaes has been delivered by sending victims a phishing email containing a malicious .docx file.

T1566.001
Spearphishing Attachment
MalwareLODEINFO

LODEINFO has been distributed to targeted victims via malicious email attachments.

T1566.001
Spearphishing Attachment
MalwareMetamorfo

Metamorfo has been delivered to victims via emails with malicious HTML attachments.

T1566.001
Spearphishing Attachment
MalwareBandook

Bandook is delivered via a malicious Word document inside a zip file.

T1566.001
Spearphishing Attachment
MalwareKONNI

KONNI has been delivered via spearphishing campaigns through a malicious Word document.

T1566.001
Spearphishing Attachment
MalwareKerrdown

Kerrdown has been distributed through malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareRTM

RTM has been delivered via spearphishing attachments disguised as PDF documents.

T1566.001
Spearphishing Attachment
MalwareStrelaStealer

StrelaStealer has been distributed as a spearphishing attachment.

T1566.001
Spearphishing Attachment
MalwareZxxZ

ZxxZ has been distributed via spearphishing emails, usually containing a malicious RTF or Excel attachment.

T1566.001
Spearphishing Attachment
MalwareXLoader

XLoader has been delivered as a phishing attachment, including PDFs with embedded links, Word and Excel files, and various archive files (ZIP, RAR, ACE, and ISOs) containing EXE payloads.

T1566.001
Spearphishing Attachment
MalwareREvil

REvil has been distributed via malicious e-mail attachments including MS Word Documents.

T1566.001
Spearphishing Attachment
MalwareValak

Valak has been delivered via spearphishing e-mails with password protected ZIP files.

T1566.001
Spearphishing Attachment
MalwareTaidoor

Taidoor has been delivered through spearphishing emails.

T1566.001
Spearphishing Attachment
MalwareDanBot

DanBot has been distributed within a malicious Excel attachment via spearphishing emails.

T1566.001
Spearphishing Attachment
MalwareRamsay

Ramsay has been distributed through spearphishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareOutSteel

OutSteel has been distributed as a malicious attachment within a spearphishing email.

T1566.001
Spearphishing Attachment
MalwareLAMEHUG

LAMEHUG has been distributed through spearphishing emails with various AI-themed malicious attachments.

T1566.001
Spearphishing Attachment
MalwareLokibot

Lokibot is delivered via a malicious XLS attachment contained within a spearhpishing email.

T1566.001
Spearphishing Attachment
MalwarePoetRAT

PoetRAT was distributed via malicious Word documents.

T1566.001
Spearphishing Attachment
MalwareKOCTOPUS

KOCTOPUS has been distributed via spearphishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareOctopus

Octopus has been delivered via spearsphishing emails.

T1566.001
Spearphishing Attachment
MalwareQilin

Qilin has been delivered to victims through malicious email attachments.

T1566.001
Spearphishing Attachment
MalwareAgent Tesla

The primary delivered mechanism for Agent Tesla is through email phishing messages.

T1566.001
Spearphishing Attachment
MalwareAstaroth

Astaroth has been delivered via malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareQakBot

QakBot has spread through emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareHancitor

Hancitor has been delivered via phishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareJSS Loader

JSS Loader has been delivered by phishing emails containing malicious Microsoft Excel attachments.

T1566.001
Spearphishing Attachment
MalwareWarzoneRAT

WarzoneRAT has been distributed as a malicious attachment within an email.

T1566.001
Spearphishing Attachment
ToolAsyncRAT

AsyncRAT has been delivered via malicious email attachments.

T1566.001
Spearphishing Attachment
ToolRemcos

Remcos has been spread through emails containing malicious documents.

T1566.001
Spearphishing Attachment
MalwareKali365

Kali365 has delivered phishing emails with malicious PDF, Word, Excel, and PowerPoint attachments that direct victims to actor-controlled landing pages.

T1566.001
Spearphishing Attachment
MalwareBADFLICK

BADFLICK has been distributed via spearphishing campaigns containing malicious Microsoft Word documents.

T1566.002
Spearphishing Link
MalwareTrickBot

TrickBot has been delivered via malicious links in phishing e-mails.

T1566.002
Spearphishing Link
MalwareBumblebee

Bumblebee has been spread through e-mail campaigns with malicious links.

T1566.002
Spearphishing Link
MalwareHavoc

Havoc has been distributed through ClickFix phishing campaigns.

T1566.002
Spearphishing Link
MalwarePony

Pony has been delivered via spearphishing emails which contained malicious links.

T1566.002
Spearphishing Link
MalwareROAMINGHOUSE

ROAMINGHOUSE has been distributed through phishing emails containing malicious OneDrive links.

T1566.002
Spearphishing Link
MalwareNETWIRE

NETWIRE has been spread via e-mail campaigns utilizing malicious links.

T1566.002
Spearphishing Link
MalwareEmotet

Emotet has been delivered by phishing emails containing links.

T1566.002
Spearphishing Link
MalwareSquirrelwaffle

Squirrelwaffle has been distributed through phishing emails containing a malicious URL.

T1566.002
Spearphishing Link
MalwareSnip3

Snip3 has been delivered to victims through e-mail links to malicious files.

T1566.002
Spearphishing Link
MalwareGuLoader

GuLoader has been spread in phishing campaigns using malicious web links.

T1566.002
Spearphishing Link
MalwareMispadu

Mispadu has been spread via malicious links embedded in emails.

T1566.002
Spearphishing Link
MalwareSocGholish

SocGholish has been spread via emails containing malicious links.

T1566.002
Spearphishing Link
MalwareSpicyOmelette

SpicyOmelette has been distributed via emails containing a malicious link that appears to be a PDF document.

T1566.002
Spearphishing Link
MalwareJavali

Javali has been delivered via malicious links embedded in e-mails.

T1566.002
Spearphishing Link
MalwareLumma Stealer

Lumma Stealer has been delivered through phishing emails containing malicious links.

T1566.002
Spearphishing Link
MalwareDarkGate

DarkGate is distributed in phishing emails containing links to distribute malicious VBS or MSI files. DarkGate uses applications such as Microsoft Teams for distributing links to payloads.

T1566.002
Spearphishing Link
MalwareLatrodectus

Latrodectus has been distributed to victims through emails containing malicious links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.