Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.002 Malicious File |
MalwareDisco | Disco has been executed through inducing user interaction with malicious .zip and .msi files. |
| T1204.002 Malicious File |
MalwareOctopus | Octopus has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareQilin | Qilin has been delivered to victims through spearphishing emails with malicious attachments. |
| T1204.002 Malicious File |
MalwareAppleJeus | AppleJeus has required user execution of a malicious MSI installer. |
| T1204.002 Malicious File |
MalwareSTARWHALE | STARWHALE has relied on victims opening a malicious Excel file for execution. |
| T1204.002 Malicious File |
MalwareAgent Tesla | Agent Tesla has been executed through malicious e-mail attachments |
| T1204.002 Malicious File |
MalwareAstaroth | Astaroth has used malicious files including VBS, LNK, and HTML for execution. |
| T1204.002 Malicious File |
MalwareQakBot | QakBot has gained execution through users opening malicious attachments. |
| T1204.002 Malicious File |
MalwareSYSCON | SYSCON has been executed by luring victims to open malicious e-mail attachments. |
| T1204.002 Malicious File |
MalwareHancitor | Hancitor has used malicious Microsoft Word documents, sent via email, which prompted the victim to enable macros. |
| T1204.002 Malicious File |
MalwareDridex | Dridex has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareOSX/Shlayer | OSX/Shlayer has relied on users mounting and executing a malicious DMG file. |
| T1204.002 Malicious File |
MalwareJSS Loader | JSS Loader has been executed through malicious attachments contained in spearphishing emails. |
| T1204.002 Malicious File |
MalwareWarzoneRAT | WarzoneRAT has relied on a victim to open a malicious attachment within an email for execution. |
| T1204.002 Malicious File |
ToolCSPY Downloader | CSPY Downloader has been delivered via malicious documents with embedded macros. |
| T1204.002 Malicious File |
ToolCARROTBALL | CARROTBALL has been executed through users being lured into opening malicious e-mail attachments. |
| T1204.002 Malicious File |
ToolAsyncRAT | AsyncRAT has been executed through victims opening malicious file attachments. |
| T1204.002 Malicious File |
ToolBrute Ratel C4 | Brute Ratel C4 has gained execution through users opening malicious documents. |
| T1204.002 Malicious File |
ToolRemcos | Remcos has been executed by luring victims into opening malicious email attachments including Excel files. |
| T1204.002 Malicious File |
MalwareBADFLICK | BADFLICK has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1204.003 Malicious Image |
GroupTeamTNT | TeamTNT has relied on users to download and execute malicious Docker images. |
| T1204.004 Malicious Copy and Paste |
GroupKimsuky | Kimsuky has leveraged ClickFix type tactics enticing victims to copy and paste malicious code. |
| T1204.004 Malicious Copy and Paste |
GroupMuddyWater | MuddyWater has leveraged ClickFix type tactics enticing victims to copy and paste malicious PowerShell code. |
| T1204.004 Malicious Copy and Paste |
GroupContagious Interview | Contagious Interview has leveraged ClickFix type tactics enticing victims to copy and paste malicious code. |
| T1204.004 Malicious Copy and Paste |
MalwareHavoc | The Havoc infection chain has been initiated via ClickFix lures in phishing emails. |
| T1204.004 Malicious Copy and Paste |
MalwareKali365 | Kali365 has dynamically generated legitimate device codes that displays on the victims screen alongside instructions to copy and paste the device code to initiate and complete a successful authentication process. |
| T1204.005 Malicious Library |
GroupContagious Interview | Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Securonix Contagious Interview DEVPOPPER April 2024Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1205 Traffic Signaling |
CampaignRedPenguin | During RedPenguin, UNC3886 leveraged malware capable of inpecting packets for a magic-string to activate backdoor functionalities. |
| T1205 Traffic Signaling |
CampaignCutting Edge | During Cutting Edge, threat actors sent a magic 48-byte sequence to enable the PITSOCK backdoor to communicate via the `/tmp/clientsDownload.sock` socket. |
| T1205 Traffic Signaling |
GroupKimsuky | Kimsuky has used TRANSLATEXT to redirect clients to legitimate Gmail, Naver or Kakao pages if the clients connect with no parameters. |
| T1205 Traffic Signaling |
GroupMustang Panda | Mustang Panda has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of “17 03 03” or “46 77 4d”. |
| T1205 Traffic Signaling |
GroupUNC3886 | UNC3886 has used the TABLEFLIP traffic redirection utility to listen for specialized command packets on compromised FortiManager devices. |
| T1205 Traffic Signaling |
MalwareTONESHELL | TONESHELL has utilized a magic value in C2 communications and only executes in memory when response packets match specific values. |
| T1205 Traffic Signaling |
MalwareBUSHWALK | BUSHWALK can modify the `DSUserAgentCap.pm` Perl module on Ivanti Connect Secure VPNs and either activate or deactivate depending on the value of the user agent in incoming HTTP requests. |
| T1205 Traffic Signaling |
MalwareJ-magic | J-magic can monitor TCP traffic for packets containing one of five different predefined parameters and will spawn a reverse shell if one of the parameters and the proper response string to a subsequent challenge is received. |
| T1205 Traffic Signaling |
MalwarePUBLOAD | PUBLOAD has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of 17 03 03. PUBLOAD has also used magic bytes consisting of 46 77 4d. |
| T1205 Traffic Signaling |
MalwareUmbreon | Umbreon provides additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet. |
| T1205 Traffic Signaling |
MalwareTRANSLATEXT | TRANSLATEXT has redirected clients to legitimate Gmail, Naver or Kakao pages if the clients connect with no parameters. |
| T1205 Traffic Signaling |
MalwareREPTILE | The REPTILE reverse shell component can listen for a specialized packet in TCP, UDP, or ICMP for activation. |
| T1205 Traffic Signaling |
MalwareChaos | Chaos provides a reverse shell is triggered upon receipt of a packet with a special string, sent to any port. |
| T1205 Traffic Signaling |
MalwareUroburos | Uroburos can intercept the first client to server packet in the 3-way TCP handshake to determine if the packet contains the correct unique value for a specific Uroburos implant. If the value does not match, the packet and the rest of the TCP session are passed to the legitimate listening application. |
| T1205 Traffic Signaling |
MalwareSYNful Knock | SYNful Knock can be sent instructions via special packets to change its functionality. Code for new functionality can be included in these messages. |
| T1205 Traffic Signaling |
MalwareWinnti for Linux | Winnti for Linux has used a passive listener, capable of identifying a specific magic value before executing tasking, as a secondary command and control (C2) mechanism. |
| T1205 Traffic Signaling |
MalwareKobalos | Kobalos is triggered by an incoming TCP connection to a legitimate service from a specific source port. |
| T1205 Traffic Signaling |
MalwareRyuk | Ryuk has used Wake-on-Lan to power on turned off systems for lateral movement. |
| T1205 Traffic Signaling |
MalwarePandora | Pandora can identify if incoming HTTP traffic contains a token and if so it will intercept the traffic and process the received command. |
| T1205 Traffic Signaling |
MalwarePenquin | Penquin will connect to C2 only after sniffing a "magic packet" value in TCP or UDP packets matching specific conditions. |
| T1205 Traffic Signaling |
MalwareZIPLINE | ZIPLINE can identify a specific string in intercepted network traffic, `SSH-2.0-OpenSSH_0.3xx.`, to trigger its command functionality. |
| T1205 Traffic Signaling |
MalwareBRUSHFIRE | BRUSHFIRE has monitored inbound VPN traffic to compromised appliances until specific inbound packets contain a specific magic string/pattern instead of external beaconing. |
| T1205 Traffic Signaling |
MalwareMini Shai-Hulud | Mini Shai-Hulud has examined commit messages for a keyword followed by base64 encoded segments to validate communications and to execute subsequent actions to include exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.