Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.002 Spearphishing Link |
GroupTA577 | TA577 has sent emails containing links to malicious JavaScript files. |
| T1566.002 Spearphishing Link |
GroupPatchwork | Patchwork has used spearphishing with links to deliver files with exploits to initial victims. |
| T1566.002 Spearphishing Link |
GroupEvilnum | Evilnum has sent spearphishing emails containing a link to a zip file hosted on Google Drive. |
| T1566.002 Spearphishing Link |
GroupAPT32 | APT32 has sent spearphishing emails containing malicious links. |
| T1566.002 Spearphishing Link |
GroupMuddyWater | MuddyWater has sent targeted spearphishing e-mails with malicious links. |
| T1566.002 Spearphishing Link |
GroupStorm-1811 | Storm-1811 has distributed malicious links to victims that redirect to EvilProxy-based phishing sites to harvest credentials. |
| T1566.002 Spearphishing Link |
GroupFIN7 | FIN7 has conducted broad phishing campaigns using malicious links. Additionally, FIN7 has sent spearphishing emails containing a typosquatted link to “ip-sccanner[.]com.” |
| T1566.002 Spearphishing Link |
GroupSandworm Team | Sandworm Team has crafted phishing emails containing malicious hyperlinks. |
| T1566.002 Spearphishing Link |
GroupMachete | Machete has sent phishing emails that contain a link to an external server with ZIP and RAR archives. |
| T1566.002 Spearphishing Link |
GroupSidewinder | Sidewinder has sent e-mails with malicious links often crafted for specific targets. |
| T1566.002 Spearphishing Link |
GroupMustang Panda | Mustang Panda has delivered malicious links to their intended targets. Mustang Panda has distributed spear-phishing emails with embedded links that direct the victim to a malicious archive hosted on Google or Dropbox. |
| T1566.002 Spearphishing Link |
GroupZIRCONIUM | ZIRCONIUM has used malicious links in e-mails to deliver malware. |
| T1566.002 Spearphishing Link |
GroupAPT39 | APT39 leveraged spearphishing emails with malicious links to initially compromise victims. |
| T1566.002 Spearphishing Link |
GroupTA2541 | TA2541 has used spearphishing e-mails with malicious links to deliver malware. |
| T1566.002 Spearphishing Link |
GroupOilRig | OilRig has sent spearphising emails with malicious links to potential victims. |
| T1566.002 Spearphishing Link |
GroupAPT1 | APT1 has sent spearphishing emails containing hyperlinks to malicious files. |
| T1566.002 Spearphishing Link |
GroupConfucius | Confucius has sent malicious links to victims through email campaigns. |
| T1566.002 Spearphishing Link |
GroupBlackTech | BlackTech has used spearphishing e-mails with links to cloud services to deliver malware. |
| T1566.002 Spearphishing Link |
GroupLeviathan | Leviathan has sent spearphishing emails with links, often using a fraudulent lookalike domain and stolen branding. |
| T1566.002 Spearphishing Link |
GroupTurla | Turla attempted to trick targets into clicking on a link featuring a seemingly legitimate domain from Adobe.com to download their malware and gain initial access. |
| T1566.002 Spearphishing Link |
GroupTA505 | TA505 has sent spearphishing emails containing malicious links. |
| T1566.002 Spearphishing Link |
GroupRedCurl | RedCurl has used phishing emails with malicious links to gain initial access. |
| T1566.002 Spearphishing Link |
GroupMofang | Mofang delivered spearphishing emails with malicious links included. |
| T1566.002 Spearphishing Link |
GroupAPT29 | APT29 has used spearphishing with a link to trick victims into clicking on a link to a zip file containing malicious files. |
| T1566.002 Spearphishing Link |
GroupMirrorFace | MirrorFace has embedded OneDrive URLs in emails leading to malicious file installation. |
| T1566.002 Spearphishing Link |
GroupLazyScripter | LazyScripter has used spam emails that contain a link that redirects the victim to download a malicious document. |
| T1566.002 Spearphishing Link |
GroupWindshift | Windshift has sent spearphishing emails with links to harvest credentials and deliver malware. |
| T1566.002 Spearphishing Link |
GroupLuminousMoth | LuminousMoth has sent spearphishing emails containing a malicious Dropbox download link. |
| T1566.002 Spearphishing Link |
GroupAPT42 | APT42 has sent spearphishing emails containing malicious links. |
| T1566.002 Spearphishing Link |
GroupAPT-C-36 | APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. |
| T1566.002 Spearphishing Link |
GroupLazarus Group | Lazarus Group has sent malicious links to victims via email. |
| T1566.002 Spearphishing Link |
GroupEarth Lusca | Earth Lusca has sent spearphishing emails to potential targets that contained a malicious link. |
| T1566.002 Spearphishing Link |
GroupFIN4 | FIN4 has used spearphishing emails (often sent from compromised accounts) containing malicious links. |
| T1566.002 Spearphishing Link |
GroupCobalt Group | Cobalt Group has sent emails with URLs pointing to malicious documents. |
| T1566.002 Spearphishing Link |
GroupWizard Spider | Wizard Spider has sent phishing emails containing a link to an actor-controlled Google Drive document or other free online file hosting services. |
| T1566.002 Spearphishing Link |
GroupMolerats | Molerats has sent phishing emails with malicious links included. |
| T1566.002 Spearphishing Link |
GroupTransparent Tribe | Transparent Tribe has embedded links to malicious downloads in e-mails. |
| T1566.002 Spearphishing Link |
GroupWIRTE | WIRTE has sent targeted spearphishing emails with malicious links directing victims to malware downloads. |
| T1566.002 Spearphishing Link |
GroupMagic Hound | Magic Hound has sent malicious URL links through email to victims. In some cases the URLs were shortened or linked to Word documents with malicious macros that executed PowerShells scripts to download Pupy. |
| T1566.002 Spearphishing Link |
GroupAPT33 | APT33 has sent spearphishing emails containing links to .hta files. |
| T1566.002 Spearphishing Link |
GroupFIN8 | FIN8 has distributed targeted emails containing links to malicious documents with embedded macros. |
| T1566.002 Spearphishing Link |
MalwareTrickBot | TrickBot has been delivered via malicious links in phishing e-mails. |
| T1566.002 Spearphishing Link |
MalwareBumblebee | Bumblebee has been spread through e-mail campaigns with malicious links. |
| T1566.002 Spearphishing Link |
MalwareHavoc | Havoc has been distributed through ClickFix phishing campaigns. |
| T1566.002 Spearphishing Link |
MalwarePony | Pony has been delivered via spearphishing emails which contained malicious links. |
| T1566.002 Spearphishing Link |
MalwareROAMINGHOUSE | ROAMINGHOUSE has been distributed through phishing emails containing malicious OneDrive links. |
| T1566.002 Spearphishing Link |
MalwareNETWIRE | NETWIRE has been spread via e-mail campaigns utilizing malicious links. |
| T1566.002 Spearphishing Link |
MalwareEmotet | Emotet has been delivered by phishing emails containing links. |
| T1566.002 Spearphishing Link |
MalwareSquirrelwaffle | Squirrelwaffle has been distributed through phishing emails containing a malicious URL. |
| T1566.002 Spearphishing Link |
MalwareSnip3 | Snip3 has been delivered to victims through e-mail links to malicious files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.