Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.002 Malicious File |
GroupSilence | Silence attempts to get users to launch malicious attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupCobalt Group | Cobalt Group has sent emails containing malicious attachments that require users to execute a file or macro to infect the victim machine. |
| T1204.002 Malicious File |
GroupWizard Spider | Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar. |
| T1204.002 Malicious File |
GroupMolerats | Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives. |
| T1204.002 Malicious File |
GroupTransparent Tribe | Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems. |
| T1204.002 Malicious File |
GroupIndigoZebra | IndigoZebra sent spearphishing emails containing malicious attachments that urged recipients to review modifications in the file which would trigger the attack. |
| T1204.002 Malicious File |
GroupMoonstone Sleet | Moonstone Sleet relied on users interacting with malicious files, such as a trojanized PuTTY installer, for initial execution. |
| T1204.002 Malicious File |
GroupInception | Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware. |
| T1204.002 Malicious File |
GroupVOID MANTICORE | VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file. VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance. |
| T1204.002 Malicious File |
GroupPROMETHIUM | PROMETHIUM has attempted to get users to execute compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities. |
| T1204.002 Malicious File |
GroupAPT30 | APT30 has relied on users to execute malicious file attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupHEXANE | HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware. |
| T1204.002 Malicious File |
GroupRancor | Rancor attempted to get users to click on an embedded macro within a Microsoft Office Excel document to launch their malware. |
| T1204.002 Malicious File |
GroupWIRTE | WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads. |
| T1204.002 Malicious File |
GroupPLATINUM | PLATINUM has attempted to get users to open malicious files by sending spearphishing emails with attachments to victims. |
| T1204.002 Malicious File |
GroupMagic Hound | Magic Hound has attempted to lure victims into opening malicious email attachments. |
| T1204.002 Malicious File |
GroupAjax Security Team | Ajax Security Team has lured victims into executing malicious files. |
| T1204.002 Malicious File |
GroupThreat Group-3390 | Threat Group-3390 has lured victims into opening malicious files containing malware. |
| T1204.002 Malicious File |
GroupAPT33 | APT33 has used malicious e-mail attachments to lure victims into executing malware. |
| T1204.002 Malicious File |
GroupFIN8 | FIN8 has used malicious e-mail attachments to lure victims into executing malware. |
| T1204.002 Malicious File |
GroupAPT19 | APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupNomadic Octopus | Nomadic Octopus as attempted to lure victims into clicking on malicious attachments within spearphishing emails. |
| T1204.002 Malicious File |
MalwareTrickBot | TrickBot has attempted to get users to launch malicious documents to deliver its payload. |
| T1204.002 Malicious File |
MalwareBLINDINGCAN | BLINDINGCAN has lured victims into executing malicious macros embedded within Microsoft Office documents. |
| T1204.002 Malicious File |
MalwareNinja | Ninja has gained execution through victims opening malicious executable files embedded in zip archives. |
| T1204.002 Malicious File |
MalwareBumblebee | Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs. |
| T1204.002 Malicious File |
MalwareKOPILUWAK | KOPILUWAK has gained execution through malicious attachments. |
| T1204.002 Malicious File |
MalwareThreatNeedle | ThreatNeedle relies on a victim to click on a malicious document for initial execution. |
| T1204.002 Malicious File |
MalwareHavoc | Havoc has been executed by victims through the use of targeted lures and crafted decoy documents. |
| T1204.002 Malicious File |
MalwareStrongPity | StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities. |
| T1204.002 Malicious File |
MalwarePony | Pony has attempted to lure targets into downloading an attached executable (ZIP, RAR, or CAB archives) or document (PDF or other MS Office format). |
| T1204.002 Malicious File |
MalwareROAMINGHOUSE | During Operation AkaiRyū, MirrorFace used malicious files to drop ROAMINGHOUSE. |
| T1204.002 Malicious File |
MalwareAppleSeed | AppleSeed can achieve execution through users running malicious file attachments distributed via email. |
| T1204.002 Malicious File |
MalwareNETWIRE | NETWIRE has been executed through luring victims into opening malicious documents. |
| T1204.002 Malicious File |
MalwareBad Rabbit | Bad Rabbit has been executed through user installation of an executable disguised as a flash installer. |
| T1204.002 Malicious File |
MalwareEnvyScout | EnvyScout has been executed through malicious files attached to e-mails. |
| T1204.002 Malicious File |
MalwareSTATICPLUGIN | STATICPLUGIN has required user execution to load subsequent malicious payloads. |
| T1204.002 Malicious File |
MalwareEmotet | Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareWoody RAT | Woody RAT has relied on users opening a malicious email attachment for execution. |
| T1204.002 Malicious File |
MalwareSquirrelwaffle | Squirrelwaffle has relied on users enabling malicious macros within Microsoft Excel and Word attachments. |
| T1204.002 Malicious File |
MalwareSnip3 | Snip3 can gain execution through the download of visual basic files. |
| T1204.002 Malicious File |
MalwareRifdoor | Rifdoor has been executed from malicious Excel or Word documents containing macros. |
| T1204.002 Malicious File |
MalwareGuLoader | The GuLoader executable has been retrieved via embedded macros in malicious Word documents. |
| T1204.002 Malicious File |
MalwareInvisiMole | InvisiMole can deliver trojanized versions of software and documents, relying on user execution. |
| T1204.002 Malicious File |
MalwareCLAIMLOADER | CLAIMLOADER has used tailored decoy documents as part of the installation routine to entice users to open attachments. |
| T1204.002 Malicious File |
MalwareMispadu | Mispadu has relied on users to execute malicious files in order to gain execution on victim machines. |
| T1204.002 Malicious File |
MalwareRustyWater | RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. |
| T1204.002 Malicious File |
MalwareIcedID | IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL. |
| T1204.002 Malicious File |
MalwareFlagpro | Flagpro has relied on users clicking a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareDarkTortilla | DarkTortilla has relied on a user to open a malicious document or archived file delivered via email for initial execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.