Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.001 Spearphishing Attachment |
GroupMalteiro | Malteiro has sent spearphishing emails containing malicious .zip files. |
| T1566.001 Spearphishing Attachment |
GroupRTM | RTM has used spearphishing attachments to distribute its malware. |
| T1566.001 Spearphishing Attachment |
GroupAPT12 | APT12 has sent emails with malicious Microsoft Office documents and PDFs attached. |
| T1566.001 Spearphishing Attachment |
GroupAPT-C-36 | APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway. |
| T1566.001 Spearphishing Attachment |
GroupTonto Team | Tonto Team has delivered payloads via spearphishing attachments. |
| T1566.001 Spearphishing Attachment |
GroupLazarus Group | Lazarus Group has targeted victims with spearphishing emails containing malicious Microsoft Word documents. |
| T1566.001 Spearphishing Attachment |
GroupFIN4 | FIN4 has used spearphishing emails containing attachments (which are often stolen, legitimate documents sent from compromised accounts) with embedded malicious macros. |
| T1566.001 Spearphishing Attachment |
GroupSilence | Silence has sent emails with malicious DOCX, CHM, LNK and ZIP attachments. |
| T1566.001 Spearphishing Attachment |
GroupCobalt Group | Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables. |
| T1566.001 Spearphishing Attachment |
GroupWizard Spider | Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar. |
| T1566.001 Spearphishing Attachment |
GroupMolerats | Molerats has sent phishing emails with malicious Microsoft Word and PDF attachments. |
| T1566.001 Spearphishing Attachment |
GroupTransparent Tribe | Transparent Tribe has sent spearphishing e-mails with attachments to deliver malicious payloads. |
| T1566.001 Spearphishing Attachment |
GroupIndigoZebra | IndigoZebra sent spearphishing emails containing malicious password-protected RAR attachments. |
| T1566.001 Spearphishing Attachment |
GroupMoonstone Sleet | Moonstone Sleet delivered various payloads to victims as spearphishing attachments. |
| T1566.001 Spearphishing Attachment |
GroupInception | Inception has used weaponized documents attached to spearphishing emails for reconnaissance and initial compromise. |
| T1566.001 Spearphishing Attachment |
GroupAPT30 | APT30 has used spearphishing emails with malicious DOC attachments. |
| T1566.001 Spearphishing Attachment |
GroupRancor | Rancor has attached a malicious document to an email to gain initial access. |
| T1566.001 Spearphishing Attachment |
GroupWIRTE | WIRTE has sent emails to intended victims with malicious MS Word and Excel attachments. |
| T1566.001 Spearphishing Attachment |
GroupPLATINUM | PLATINUM has sent spearphishing emails with attachments to victims as its primary initial access vector. |
| T1566.001 Spearphishing Attachment |
GroupAjax Security Team | Ajax Security Team has used personalized spearphishing attachments. |
| T1566.001 Spearphishing Attachment |
GroupThreat Group-3390 | Threat Group-3390 has used e-mail to deliver malicious attachments to victims. |
| T1566.001 Spearphishing Attachment |
GroupAPT33 | APT33 has sent spearphishing e-mails with archive attachments. |
| T1566.001 Spearphishing Attachment |
GroupFIN8 | FIN8 has distributed targeted emails containing Word documents with embedded malicious macros. |
| T1566.001 Spearphishing Attachment |
GroupAPT19 | APT19 sent spearphishing emails with malicious attachments in RTF and XLSM formats to deliver initial exploits. |
| T1566.001 Spearphishing Attachment |
GroupNomadic Octopus | Nomadic Octopus has targeted victims with spearphishing emails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareTrickBot | TrickBot has used an email with an Excel sheet containing a malicious macro to deploy the malware |
| T1566.001 Spearphishing Attachment |
MalwareBLINDINGCAN | BLINDINGCAN has been delivered by phishing emails containing malicious Microsoft Office documents. |
| T1566.001 Spearphishing Attachment |
MalwareBumblebee | Bumblebee has gained execution through luring users into opening malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareKOPILUWAK | KOPILUWAK has been delivered to victims as a malicious email attachment. |
| T1566.001 Spearphishing Attachment |
MalwareThreatNeedle | ThreatNeedle has been distributed via a malicious Word document within a spearphishing email. |
| T1566.001 Spearphishing Attachment |
MalwarePony | Pony has been delivered via spearphishing attachments. |
| T1566.001 Spearphishing Attachment |
MalwareOceanSalt | OceanSalt has been delivered via spearphishing emails with Microsoft Office attachments. |
| T1566.001 Spearphishing Attachment |
MalwareAppleSeed | AppleSeed has been distributed to victims through malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareNETWIRE | NETWIRE has been spread via e-mail campaigns utilizing malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareEnvyScout | EnvyScout has been distributed via spearphishing as an email attachment. |
| T1566.001 Spearphishing Attachment |
MalwareEmotet | Emotet has been delivered by phishing emails containing attachments. |
| T1566.001 Spearphishing Attachment |
MalwareWoody RAT | Woody RAT has been delivered via malicious Word documents and archive files. |
| T1566.001 Spearphishing Attachment |
MalwareSquirrelwaffle | Squirrelwaffle has been distributed via malicious Microsoft Office documents within spam emails. |
| T1566.001 Spearphishing Attachment |
MalwareSnip3 | Snip3 has been delivered to victims through malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareRifdoor | Rifdoor has been distributed in e-mails with malicious Excel or Word documents. |
| T1566.001 Spearphishing Attachment |
MalwareRustyWater | RustyWater has sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primary payload for the next stage. |
| T1566.001 Spearphishing Attachment |
MalwareIcedID | IcedID has been delivered via phishing e-mails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareFlagpro | Flagpro has been distributed via spearphishing as an email attachment. |
| T1566.001 Spearphishing Attachment |
MalwareDarkTortilla | DarkTortilla has been distributed via spearphishing emails containing archive attachments, with file types such as .iso, .zip, .img, .dmg, and .tar, as well as through malicious documents. |
| T1566.001 Spearphishing Attachment |
MalwareROKRAT | ROKRAT has been delivered via spearphishing emails that contain a malicious Hangul Office or Microsoft Word document. |
| T1566.001 Spearphishing Attachment |
MalwareDarkWatchman | DarkWatchman has been delivered via spearphishing emails that contain a malicious zip file. |
| T1566.001 Spearphishing Attachment |
MalwareJavali | Javali has been delivered as malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareBisonal | Bisonal has been delivered as malicious email attachments. |
| T1566.001 Spearphishing Attachment |
MalwareLumma Stealer | Lumma Stealer has been delivered through phishing emails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareClambling | Clambling has been delivered to victim's machines through malicious e-mail attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.