ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1204.002
Malicious File
GroupSilence

Silence attempts to get users to launch malicious attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupCobalt Group

Cobalt Group has sent emails containing malicious attachments that require users to execute a file or macro to infect the victim machine.

T1204.002
Malicious File
GroupWizard Spider

Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar.

T1204.002
Malicious File
GroupMolerats

Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives.

T1204.002
Malicious File
GroupTransparent Tribe

Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems.

T1204.002
Malicious File
GroupIndigoZebra

IndigoZebra sent spearphishing emails containing malicious attachments that urged recipients to review modifications in the file which would trigger the attack.

T1204.002
Malicious File
GroupMoonstone Sleet

Moonstone Sleet relied on users interacting with malicious files, such as a trojanized PuTTY installer, for initial execution.

T1204.002
Malicious File
GroupInception

Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware.

T1204.002
Malicious File
GroupVOID MANTICORE

VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file. VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance.

T1204.002
Malicious File
GroupPROMETHIUM

PROMETHIUM has attempted to get users to execute compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.

T1204.002
Malicious File
GroupAPT30

APT30 has relied on users to execute malicious file attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupHEXANE

HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware.

T1204.002
Malicious File
GroupRancor

Rancor attempted to get users to click on an embedded macro within a Microsoft Office Excel document to launch their malware.

T1204.002
Malicious File
GroupWIRTE

WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads.

T1204.002
Malicious File
GroupPLATINUM

PLATINUM has attempted to get users to open malicious files by sending spearphishing emails with attachments to victims.

T1204.002
Malicious File
GroupMagic Hound

Magic Hound has attempted to lure victims into opening malicious email attachments.

T1204.002
Malicious File
GroupAjax Security Team

Ajax Security Team has lured victims into executing malicious files.

T1204.002
Malicious File
GroupThreat Group-3390

Threat Group-3390 has lured victims into opening malicious files containing malware.

T1204.002
Malicious File
GroupAPT33

APT33 has used malicious e-mail attachments to lure victims into executing malware.

T1204.002
Malicious File
GroupFIN8

FIN8 has used malicious e-mail attachments to lure victims into executing malware.

T1204.002
Malicious File
GroupAPT19

APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupNomadic Octopus

Nomadic Octopus as attempted to lure victims into clicking on malicious attachments within spearphishing emails.

T1204.002
Malicious File
MalwareTrickBot

TrickBot has attempted to get users to launch malicious documents to deliver its payload.

T1204.002
Malicious File
MalwareBLINDINGCAN

BLINDINGCAN has lured victims into executing malicious macros embedded within Microsoft Office documents.

T1204.002
Malicious File
MalwareNinja

Ninja has gained execution through victims opening malicious executable files embedded in zip archives.

T1204.002
Malicious File
MalwareBumblebee

Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs.

T1204.002
Malicious File
MalwareKOPILUWAK

KOPILUWAK has gained execution through malicious attachments.

T1204.002
Malicious File
MalwareThreatNeedle

ThreatNeedle relies on a victim to click on a malicious document for initial execution.

T1204.002
Malicious File
MalwareHavoc

Havoc has been executed by victims through the use of targeted lures and crafted decoy documents.

T1204.002
Malicious File
MalwareStrongPity

StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.

T1204.002
Malicious File
MalwarePony

Pony has attempted to lure targets into downloading an attached executable (ZIP, RAR, or CAB archives) or document (PDF or other MS Office format).

T1204.002
Malicious File
MalwareROAMINGHOUSE

During Operation AkaiRyū, MirrorFace used malicious files to drop ROAMINGHOUSE.

T1204.002
Malicious File
MalwareAppleSeed

AppleSeed can achieve execution through users running malicious file attachments distributed via email.

T1204.002
Malicious File
MalwareNETWIRE

NETWIRE has been executed through luring victims into opening malicious documents.

T1204.002
Malicious File
MalwareBad Rabbit

Bad Rabbit has been executed through user installation of an executable disguised as a flash installer.

T1204.002
Malicious File
MalwareEnvyScout

EnvyScout has been executed through malicious files attached to e-mails.

T1204.002
Malicious File
MalwareSTATICPLUGIN

STATICPLUGIN has required user execution to load subsequent malicious payloads.

T1204.002
Malicious File
MalwareEmotet

Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareWoody RAT

Woody RAT has relied on users opening a malicious email attachment for execution.

T1204.002
Malicious File
MalwareSquirrelwaffle

Squirrelwaffle has relied on users enabling malicious macros within Microsoft Excel and Word attachments.

T1204.002
Malicious File
MalwareSnip3

Snip3 can gain execution through the download of visual basic files.

T1204.002
Malicious File
MalwareRifdoor

Rifdoor has been executed from malicious Excel or Word documents containing macros.

T1204.002
Malicious File
MalwareGuLoader

The GuLoader executable has been retrieved via embedded macros in malicious Word documents.

T1204.002
Malicious File
MalwareInvisiMole

InvisiMole can deliver trojanized versions of software and documents, relying on user execution.

T1204.002
Malicious File
MalwareCLAIMLOADER

CLAIMLOADER has used tailored decoy documents as part of the installation routine to entice users to open attachments.

T1204.002
Malicious File
MalwareMispadu

Mispadu has relied on users to execute malicious files in order to gain execution on victim machines.

T1204.002
Malicious File
MalwareRustyWater

RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1204.002
Malicious File
MalwareIcedID

IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL.

T1204.002
Malicious File
MalwareFlagpro

Flagpro has relied on users clicking a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareDarkTortilla

DarkTortilla has relied on a user to open a malicious document or archived file delivered via email for initial execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.