Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.001 Spearphishing Attachment |
MalwareDarkGate | DarkGate can be distributed through emails with malicious attachments from a spoofed email address. |
| T1566.001 Spearphishing Attachment |
MalwareSVCReady | SVCReady has been distributed via spearphishing campaigns containing malicious Mircrosoft Word documents. |
| T1566.001 Spearphishing Attachment |
MalwareLatrodectus | Latrodectus has been distributed through reply-chain phishing emails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareSaint Bot | Saint Bot has been distributed as malicious attachments within spearphishing emails. |
| T1566.001 Spearphishing Attachment |
MalwareChaes | Chaes has been delivered by sending victims a phishing email containing a malicious .docx file. |
| T1566.001 Spearphishing Attachment |
MalwareLODEINFO | LODEINFO has been distributed to targeted victims via malicious email attachments. |
| T1566.001 Spearphishing Attachment |
MalwareMetamorfo | Metamorfo has been delivered to victims via emails with malicious HTML attachments. |
| T1566.001 Spearphishing Attachment |
MalwareBandook | Bandook is delivered via a malicious Word document inside a zip file. |
| T1566.001 Spearphishing Attachment |
MalwareKONNI | KONNI has been delivered via spearphishing campaigns through a malicious Word document. |
| T1566.001 Spearphishing Attachment |
MalwareKerrdown | Kerrdown has been distributed through malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareRTM | RTM has been delivered via spearphishing attachments disguised as PDF documents. |
| T1566.001 Spearphishing Attachment |
MalwareStrelaStealer | StrelaStealer has been distributed as a spearphishing attachment. |
| T1566.001 Spearphishing Attachment |
MalwareZxxZ | ZxxZ has been distributed via spearphishing emails, usually containing a malicious RTF or Excel attachment. |
| T1566.001 Spearphishing Attachment |
MalwareXLoader | XLoader has been delivered as a phishing attachment, including PDFs with embedded links, Word and Excel files, and various archive files (ZIP, RAR, ACE, and ISOs) containing EXE payloads. |
| T1566.001 Spearphishing Attachment |
MalwareREvil | REvil has been distributed via malicious e-mail attachments including MS Word Documents. |
| T1566.001 Spearphishing Attachment |
MalwareValak | Valak has been delivered via spearphishing e-mails with password protected ZIP files. |
| T1566.001 Spearphishing Attachment |
MalwareTaidoor | Taidoor has been delivered through spearphishing emails. |
| T1566.001 Spearphishing Attachment |
MalwareDanBot | DanBot has been distributed within a malicious Excel attachment via spearphishing emails. |
| T1566.001 Spearphishing Attachment |
MalwareRamsay | Ramsay has been distributed through spearphishing emails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareOutSteel | OutSteel has been distributed as a malicious attachment within a spearphishing email. |
| T1566.001 Spearphishing Attachment |
MalwareLAMEHUG | LAMEHUG has been distributed through spearphishing emails with various AI-themed malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareLokibot | Lokibot is delivered via a malicious XLS attachment contained within a spearhpishing email. |
| T1566.001 Spearphishing Attachment |
MalwarePoetRAT | PoetRAT was distributed via malicious Word documents. |
| T1566.001 Spearphishing Attachment |
MalwareKOCTOPUS | KOCTOPUS has been distributed via spearphishing emails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareOctopus | Octopus has been delivered via spearsphishing emails. |
| T1566.001 Spearphishing Attachment |
MalwareQilin | Qilin has been delivered to victims through malicious email attachments. |
| T1566.001 Spearphishing Attachment |
MalwareAgent Tesla | The primary delivered mechanism for Agent Tesla is through email phishing messages. |
| T1566.001 Spearphishing Attachment |
MalwareAstaroth | Astaroth has been delivered via malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareQakBot | QakBot has spread through emails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareHancitor | Hancitor has been delivered via phishing emails with malicious attachments. |
| T1566.001 Spearphishing Attachment |
MalwareJSS Loader | JSS Loader has been delivered by phishing emails containing malicious Microsoft Excel attachments. |
| T1566.001 Spearphishing Attachment |
MalwareWarzoneRAT | WarzoneRAT has been distributed as a malicious attachment within an email. |
| T1566.001 Spearphishing Attachment |
ToolAsyncRAT | AsyncRAT has been delivered via malicious email attachments. |
| T1566.001 Spearphishing Attachment |
ToolRemcos | Remcos has been spread through emails containing malicious documents. |
| T1566.001 Spearphishing Attachment |
MalwareKali365 | Kali365 has delivered phishing emails with malicious PDF, Word, Excel, and PowerPoint attachments that direct victims to actor-controlled landing pages. |
| T1566.001 Spearphishing Attachment |
MalwareBADFLICK | BADFLICK has been distributed via spearphishing campaigns containing malicious Microsoft Word documents. |
| T1566.002 Spearphishing Link |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email. |
| T1566.002 Spearphishing Link |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda distributed malicious links in phishing emails leading to HTML files that would direct the victim to malicious MSC files if running Windows based on User Agent fingerprinting during RedDelta Modified PlugX Infection Chain Operations. |
| T1566.002 Spearphishing Link |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors sent spearphishing emails containing a malicious link. |
| T1566.002 Spearphishing Link |
CampaignOperation Spalax | During Operation Spalax, the threat actors sent phishing emails to victims that contained a malicious link. |
| T1566.002 Spearphishing Link |
CampaignC0021 | During C0021, the threat actors sent phishing emails with unique malicious links, likely for tracking victim clicks. |
| T1566.002 Spearphishing Link |
CampaignPikabot Distribution February 2024 | Pikabot Distribution February 2024 utilized emails with hyperlinks leading to malicious ZIP archive files containing scripts to download and install Pikabot. |
| T1566.002 Spearphishing Link |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace sent spearphishing emails with malicious OneDrive links. |
| T1566.002 Spearphishing Link |
CampaignNight Dragon | During Night Dragon, threat actors sent spearphishing emails containing links to compromised websites where malware was downloaded. |
| T1566.002 Spearphishing Link |
CampaignC0011 | During C0011, Transparent Tribe sent emails containing a malicious link to student targets in India. |
| T1566.002 Spearphishing Link |
GroupElderwood | Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing a link to malicious content hosted on an uncommon Web server. |
| T1566.002 Spearphishing Link |
GroupAPT3 | APT3 has sent spearphishing emails containing malicious links. |
| T1566.002 Spearphishing Link |
GroupMustard Tempest | Mustard Tempest has sent victims emails containing links to compromised websites. |
| T1566.002 Spearphishing Link |
GroupKimsuky | Kimsuky has sent spearphishing emails containing a link to a document that contained malicious macros or took the victim to an actor-controlled domain. |
| T1566.002 Spearphishing Link |
GroupEXOTIC LILY | EXOTIC LILY has relied on victims to open malicious links in e-mails for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.