Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.001 Malicious Link |
MalwareSquirrelwaffle | Squirrelwaffle has relied on victims to click on a malicious link send via phishing campaigns. |
| T1204.001 Malicious Link |
MalwareSnip3 | Snip3 has been executed through luring victims into clicking malicious links. |
| T1204.001 Malicious Link |
MalwareGuLoader | GuLoader has relied upon users clicking on links to malicious documents. |
| T1204.001 Malicious Link |
MalwareObliqueRAT | ObliqueRAT has gained execution on targeted systems through luring users to click on links to malicious URLs. |
| T1204.001 Malicious Link |
MalwareSocGholish | SocGholish has lured victims into interacting with malicious links on compromised websites for execution. |
| T1204.001 Malicious Link |
MalwareSpicyOmelette | SpicyOmelette has been executed through malicious links within spearphishing emails. |
| T1204.001 Malicious Link |
MalwareJavali | Javali has achieved execution through victims clicking links to malicious websites. |
| T1204.001 Malicious Link |
MalwareTSCookie | TSCookie has been executed via malicious links embedded in e-mails spoofing the Ministries of Education, Culture, Sports, Science and Technology of Japan. |
| T1204.001 Malicious Link |
MalwareLatrodectus | Latrodectus has been executed through malicious links distributed in email campaigns. |
| T1204.001 Malicious Link |
MalwareSaint Bot | Saint Bot has relied on users to click on a malicious link delivered via a spearphishing. |
| T1204.001 Malicious Link |
MalwareSMOKEDHAM | SMOKEDHAM has relied upon users clicking on a malicious link delivered through phishing. |
| T1204.001 Malicious Link |
MalwareKerrdown | Kerrdown has gained execution through victims opening malicious links. |
| T1204.001 Malicious Link |
MalwareGrandoreiro | Grandoreiro has used malicious links to gain execution on victim machines. |
| T1204.001 Malicious Link |
MalwareBazar | Bazar can gain execution after a user clicks on a malicious link to decoy landing pages hosted on Google Docs. |
| T1204.001 Malicious Link |
MalwarePLEAD | PLEAD has been executed via malicious links in e-mails. |
| T1204.001 Malicious Link |
MalwareOutSteel | OutSteel has relied on a user to click a malicious link within a spearphishing email. |
| T1204.001 Malicious Link |
MalwareBackConfig | BackConfig has compromised victims via links to URLs hosting malicious content. |
| T1204.001 Malicious Link |
MalwareMelcoz | Melcoz has gained execution through victims opening malicious links. |
| T1204.001 Malicious Link |
MalwareKOCTOPUS | KOCTOPUS has relied on victims clicking on a malicious link delivered via email. |
| T1204.001 Malicious Link |
MalwareQilin | Qilin has been executed by luring victims into clicking links in spearphishing emails. |
| T1204.001 Malicious Link |
MalwareAppleJeus | AppleJeus's spearphishing links required user interaction to navigate to the malicious website. |
| T1204.001 Malicious Link |
MalwareQakBot | QakBot has gained execution through users opening malicious links. |
| T1204.001 Malicious Link |
MalwareHancitor | Hancitor has relied upon users clicking on a malicious link delivered through phishing. |
| T1204.001 Malicious Link |
MalwareKali365 | Kali365 has directed victims to actor-controlled phishing pages through malicious links, initiating device code authorization flows or adversary-in-the-middle session capture. |
| T1204.002 Malicious File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors. |
| T1204.002 Malicious File |
CampaignFrankenstein | During Frankenstein, the threat actors relied on a victim to enable macros within a malicious Microsoft Word document likely sent via email. |
| T1204.002 Malicious File |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda distributed malicious LNK objects for user execution during RedDelta Modified PlugX Infection Chain Operations. |
| T1204.002 Malicious File |
CampaignOperation Sharpshooter | During Operation Sharpshooter, the threat actors relied on victims executing malicious Microsoft Word or PDF files. |
| T1204.002 Malicious File |
CampaignOperation Honeybee | During Operation Honeybee, threat actors relied on a victim to enable macros within a malicious Word document. |
| T1204.002 Malicious File |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors relied on potential victims to open a malicious Microsoft Word document sent via email. |
| T1204.002 Malicious File |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them. |
| T1204.002 Malicious File |
CampaignOperation Spalax | During Operation Spalax, the threat actors relied on a victim to open a PDF document and click on an embedded malicious link to download malware. |
| T1204.002 Malicious File |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution delivered Pikabot installers as password-protected ZIP files containing heavily obfuscated JavaScript, or IMG files containing an LNK mimicking a Word document and a malicious DLL. |
| T1204.002 Malicious File |
CampaignC0015 | During C0015, the threat actors relied on users to enable macros within a malicious Microsoft Word document. |
| T1204.002 Malicious File |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace lured victims into executing malicious payloads by opening email attachments. |
| T1204.002 Malicious File |
CampaignC0011 | During C0011, Transparent Tribe relied on a student target to open a malicious document delivered via email. |
| T1204.002 Malicious File |
GroupAPT38 | APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files. |
| T1204.002 Malicious File |
GroupIndrik Spider | Indrik Spider has attempted to get users to click on a malicious zipped file. |
| T1204.002 Malicious File |
GroupElderwood | Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open attachments. |
| T1204.002 Malicious File |
GroupSideCopy | SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns. |
| T1204.002 Malicious File |
GroupKimsuky | Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background. |
| T1204.002 Malicious File |
GroupEXOTIC LILY | EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO. |
| T1204.002 Malicious File |
Groupadmin@338 | admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupPatchwork | Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware. |
| T1204.002 Malicious File |
GroupDragonfly | Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments. |
| T1204.002 Malicious File |
GroupGorgon Group | Gorgon Group attempted to get users to launch malicious Microsoft Office attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupmenuPass | menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns. |
| T1204.002 Malicious File |
GroupAPT32 | APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment. |
| T1204.002 Malicious File |
GroupMuddyWater | MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1204.002 Malicious File |
GroupNaikon | Naikon has convinced victims to open malicious attachments to execute malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.