ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1566.001
Spearphishing Attachment
MalwareDarkGate

DarkGate can be distributed through emails with malicious attachments from a spoofed email address.

T1566.001
Spearphishing Attachment
MalwareSVCReady

SVCReady has been distributed via spearphishing campaigns containing malicious Mircrosoft Word documents.

T1566.001
Spearphishing Attachment
MalwareLatrodectus

Latrodectus has been distributed through reply-chain phishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareSaint Bot

Saint Bot has been distributed as malicious attachments within spearphishing emails.

T1566.001
Spearphishing Attachment
MalwareChaes

Chaes has been delivered by sending victims a phishing email containing a malicious .docx file.

T1566.001
Spearphishing Attachment
MalwareLODEINFO

LODEINFO has been distributed to targeted victims via malicious email attachments.

T1566.001
Spearphishing Attachment
MalwareMetamorfo

Metamorfo has been delivered to victims via emails with malicious HTML attachments.

T1566.001
Spearphishing Attachment
MalwareBandook

Bandook is delivered via a malicious Word document inside a zip file.

T1566.001
Spearphishing Attachment
MalwareKONNI

KONNI has been delivered via spearphishing campaigns through a malicious Word document.

T1566.001
Spearphishing Attachment
MalwareKerrdown

Kerrdown has been distributed through malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareRTM

RTM has been delivered via spearphishing attachments disguised as PDF documents.

T1566.001
Spearphishing Attachment
MalwareStrelaStealer

StrelaStealer has been distributed as a spearphishing attachment.

T1566.001
Spearphishing Attachment
MalwareZxxZ

ZxxZ has been distributed via spearphishing emails, usually containing a malicious RTF or Excel attachment.

T1566.001
Spearphishing Attachment
MalwareXLoader

XLoader has been delivered as a phishing attachment, including PDFs with embedded links, Word and Excel files, and various archive files (ZIP, RAR, ACE, and ISOs) containing EXE payloads.

T1566.001
Spearphishing Attachment
MalwareREvil

REvil has been distributed via malicious e-mail attachments including MS Word Documents.

T1566.001
Spearphishing Attachment
MalwareValak

Valak has been delivered via spearphishing e-mails with password protected ZIP files.

T1566.001
Spearphishing Attachment
MalwareTaidoor

Taidoor has been delivered through spearphishing emails.

T1566.001
Spearphishing Attachment
MalwareDanBot

DanBot has been distributed within a malicious Excel attachment via spearphishing emails.

T1566.001
Spearphishing Attachment
MalwareRamsay

Ramsay has been distributed through spearphishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareOutSteel

OutSteel has been distributed as a malicious attachment within a spearphishing email.

T1566.001
Spearphishing Attachment
MalwareLAMEHUG

LAMEHUG has been distributed through spearphishing emails with various AI-themed malicious attachments.

T1566.001
Spearphishing Attachment
MalwareLokibot

Lokibot is delivered via a malicious XLS attachment contained within a spearhpishing email.

T1566.001
Spearphishing Attachment
MalwarePoetRAT

PoetRAT was distributed via malicious Word documents.

T1566.001
Spearphishing Attachment
MalwareKOCTOPUS

KOCTOPUS has been distributed via spearphishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareOctopus

Octopus has been delivered via spearsphishing emails.

T1566.001
Spearphishing Attachment
MalwareQilin

Qilin has been delivered to victims through malicious email attachments.

T1566.001
Spearphishing Attachment
MalwareAgent Tesla

The primary delivered mechanism for Agent Tesla is through email phishing messages.

T1566.001
Spearphishing Attachment
MalwareAstaroth

Astaroth has been delivered via malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareQakBot

QakBot has spread through emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareHancitor

Hancitor has been delivered via phishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareJSS Loader

JSS Loader has been delivered by phishing emails containing malicious Microsoft Excel attachments.

T1566.001
Spearphishing Attachment
MalwareWarzoneRAT

WarzoneRAT has been distributed as a malicious attachment within an email.

T1566.001
Spearphishing Attachment
ToolAsyncRAT

AsyncRAT has been delivered via malicious email attachments.

T1566.001
Spearphishing Attachment
ToolRemcos

Remcos has been spread through emails containing malicious documents.

T1566.001
Spearphishing Attachment
MalwareKali365

Kali365 has delivered phishing emails with malicious PDF, Word, Excel, and PowerPoint attachments that direct victims to actor-controlled landing pages.

T1566.001
Spearphishing Attachment
MalwareBADFLICK

BADFLICK has been distributed via spearphishing campaigns containing malicious Microsoft Word documents.

T1566.002
Spearphishing Link
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email.

T1566.002
Spearphishing Link
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda distributed malicious links in phishing emails leading to HTML files that would direct the victim to malicious MSC files if running Windows based on User Agent fingerprinting during RedDelta Modified PlugX Infection Chain Operations.

T1566.002
Spearphishing Link
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors sent spearphishing emails containing a malicious link.

T1566.002
Spearphishing Link
CampaignOperation Spalax

During Operation Spalax, the threat actors sent phishing emails to victims that contained a malicious link.

T1566.002
Spearphishing Link
CampaignC0021

During C0021, the threat actors sent phishing emails with unique malicious links, likely for tracking victim clicks.

T1566.002
Spearphishing Link
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized emails with hyperlinks leading to malicious ZIP archive files containing scripts to download and install Pikabot.

T1566.002
Spearphishing Link
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace sent spearphishing emails with malicious OneDrive links.

T1566.002
Spearphishing Link
CampaignNight Dragon

During Night Dragon, threat actors sent spearphishing emails containing links to compromised websites where malware was downloaded.

T1566.002
Spearphishing Link
CampaignC0011

During C0011, Transparent Tribe sent emails containing a malicious link to student targets in India.

T1566.002
Spearphishing Link
GroupElderwood

Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing a link to malicious content hosted on an uncommon Web server.

T1566.002
Spearphishing Link
GroupAPT3

APT3 has sent spearphishing emails containing malicious links.

T1566.002
Spearphishing Link
GroupMustard Tempest

Mustard Tempest has sent victims emails containing links to compromised websites.

T1566.002
Spearphishing Link
GroupKimsuky

Kimsuky has sent spearphishing emails containing a link to a document that contained malicious macros or took the victim to an actor-controlled domain.

T1566.002
Spearphishing Link
GroupEXOTIC LILY

EXOTIC LILY has relied on victims to open malicious links in e-mails for execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.