ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1204.001
Malicious Link
MalwareSquirrelwaffle

Squirrelwaffle has relied on victims to click on a malicious link send via phishing campaigns.

T1204.001
Malicious Link
MalwareSnip3

Snip3 has been executed through luring victims into clicking malicious links.

T1204.001
Malicious Link
MalwareGuLoader

GuLoader has relied upon users clicking on links to malicious documents.

T1204.001
Malicious Link
MalwareObliqueRAT

ObliqueRAT has gained execution on targeted systems through luring users to click on links to malicious URLs.

T1204.001
Malicious Link
MalwareSocGholish

SocGholish has lured victims into interacting with malicious links on compromised websites for execution.

T1204.001
Malicious Link
MalwareSpicyOmelette

SpicyOmelette has been executed through malicious links within spearphishing emails.

T1204.001
Malicious Link
MalwareJavali

Javali has achieved execution through victims clicking links to malicious websites.

T1204.001
Malicious Link
MalwareTSCookie

TSCookie has been executed via malicious links embedded in e-mails spoofing the Ministries of Education, Culture, Sports, Science and Technology of Japan.

T1204.001
Malicious Link
MalwareLatrodectus

Latrodectus has been executed through malicious links distributed in email campaigns.

T1204.001
Malicious Link
MalwareSaint Bot

Saint Bot has relied on users to click on a malicious link delivered via a spearphishing.

T1204.001
Malicious Link
MalwareSMOKEDHAM

SMOKEDHAM has relied upon users clicking on a malicious link delivered through phishing.

T1204.001
Malicious Link
MalwareKerrdown

Kerrdown has gained execution through victims opening malicious links.

T1204.001
Malicious Link
MalwareGrandoreiro

Grandoreiro has used malicious links to gain execution on victim machines.

T1204.001
Malicious Link
MalwareBazar

Bazar can gain execution after a user clicks on a malicious link to decoy landing pages hosted on Google Docs.

T1204.001
Malicious Link
MalwarePLEAD

PLEAD has been executed via malicious links in e-mails.

T1204.001
Malicious Link
MalwareOutSteel

OutSteel has relied on a user to click a malicious link within a spearphishing email.

T1204.001
Malicious Link
MalwareBackConfig

BackConfig has compromised victims via links to URLs hosting malicious content.

T1204.001
Malicious Link
MalwareMelcoz

Melcoz has gained execution through victims opening malicious links.

T1204.001
Malicious Link
MalwareKOCTOPUS

KOCTOPUS has relied on victims clicking on a malicious link delivered via email.

T1204.001
Malicious Link
MalwareQilin

Qilin has been executed by luring victims into clicking links in spearphishing emails.

T1204.001
Malicious Link
MalwareAppleJeus

AppleJeus's spearphishing links required user interaction to navigate to the malicious website.

T1204.001
Malicious Link
MalwareQakBot

QakBot has gained execution through users opening malicious links.

T1204.001
Malicious Link
MalwareHancitor

Hancitor has relied upon users clicking on a malicious link delivered through phishing.

T1204.001
Malicious Link
MalwareKali365

Kali365 has directed victims to actor-controlled phishing pages through malicious links, initiating device code authorization flows or adversary-in-the-middle session capture.

T1204.002
Malicious File
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors.

T1204.002
Malicious File
CampaignFrankenstein

During Frankenstein, the threat actors relied on a victim to enable macros within a malicious Microsoft Word document likely sent via email.

T1204.002
Malicious File
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda distributed malicious LNK objects for user execution during RedDelta Modified PlugX Infection Chain Operations.

T1204.002
Malicious File
CampaignOperation Sharpshooter

During Operation Sharpshooter, the threat actors relied on victims executing malicious Microsoft Word or PDF files.

T1204.002
Malicious File
CampaignOperation Honeybee

During Operation Honeybee, threat actors relied on a victim to enable macros within a malicious Word document.

T1204.002
Malicious File
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors relied on potential victims to open a malicious Microsoft Word document sent via email.

T1204.002
Malicious File
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them.

T1204.002
Malicious File
CampaignOperation Spalax

During Operation Spalax, the threat actors relied on a victim to open a PDF document and click on an embedded malicious link to download malware.

T1204.002
Malicious File
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution delivered Pikabot installers as password-protected ZIP files containing heavily obfuscated JavaScript, or IMG files containing an LNK mimicking a Word document and a malicious DLL.

T1204.002
Malicious File
CampaignC0015

During C0015, the threat actors relied on users to enable macros within a malicious Microsoft Word document.

T1204.002
Malicious File
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace lured victims into executing malicious payloads by opening email attachments.

T1204.002
Malicious File
CampaignC0011

During C0011, Transparent Tribe relied on a student target to open a malicious document delivered via email.

T1204.002
Malicious File
GroupAPT38

APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files.

T1204.002
Malicious File
GroupIndrik Spider

Indrik Spider has attempted to get users to click on a malicious zipped file.

T1204.002
Malicious File
GroupElderwood

Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open attachments.

T1204.002
Malicious File
GroupSideCopy

SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns.

T1204.002
Malicious File
GroupKimsuky

Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background.

T1204.002
Malicious File
GroupEXOTIC LILY

EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO.

T1204.002
Malicious File
Groupadmin@338

admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupPatchwork

Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware.

T1204.002
Malicious File
GroupDragonfly

Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments.

T1204.002
Malicious File
GroupGorgon Group

Gorgon Group attempted to get users to launch malicious Microsoft Office attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupmenuPass

menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns.

T1204.002
Malicious File
GroupAPT32

APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment.

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1204.002
Malicious File
GroupNaikon

Naikon has convinced victims to open malicious attachments to execute malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.