ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1204.001
Malicious Link
GroupSandworm Team

Sandworm Team has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders.

T1204.001
Malicious Link
GroupMachete

Machete has has relied on users opening malicious links delivered through spearphishing to execute malware.

T1204.001
Malicious Link
GroupSidewinder

Sidewinder has lured targets to click on malicious links to gain execution in the target environment.

T1204.001
Malicious Link
GroupMustang Panda

Mustang Panda has sent malicious links including links directing victims to a Google Drive folder. Mustang Panda has also utilized webpages with Javascript code that downloads malicious payloads to the victim device.

T1204.001
Malicious Link
GroupZIRCONIUM

ZIRCONIUM has used malicious links in e-mails to lure victims into downloading malware.

T1204.001
Malicious Link
GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link.

T1204.001
Malicious Link
GroupContagious Interview

Contagious Interview has lured victims to click on a malicious link that led to download of a malicious payload. Contagious Interview has also leveraged links to malicious payloads on social media and code repositories.

T1204.001
Malicious Link
GroupTA2541

TA2541 has used malicious links to cloud and web services to gain execution on victim machines.

T1204.001
Malicious Link
GroupOilRig

OilRig has delivered malicious links to achieve execution on the target system.

T1204.001
Malicious Link
GroupSaint Bear

Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution.

T1204.001
Malicious Link
GroupConfucius

Confucius has lured victims into clicking on a malicious link sent through spearphishing.

T1204.001
Malicious Link
GroupBlackTech

BlackTech has used e-mails with malicious links to lure victims into installing malware.

T1204.001
Malicious Link
GroupLeviathan

Leviathan has sent spearphishing email links attempting to get a user to click.

T1204.001
Malicious Link
GroupWinter Vivern

Winter Vivern has mimicked legitimate government-related domains to deliver malicious webpages containing links to documents or other content for user execution.

T1204.001
Malicious Link
GroupTurla

Turla has used spearphishing via a link to get users to download and run their malware.

T1204.001
Malicious Link
GroupTA505

TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1204.001
Malicious Link
GroupRedCurl

RedCurl has used malicious links to infect the victim machines.

T1204.001
Malicious Link
GroupMofang

Mofang's spearphishing emails required a user to click the link to connect to a compromised website.

T1204.001
Malicious Link
GroupAPT29

APT29 has used various forms of spearphishing attempting to get a user to click on a malicious link.

T1204.001
Malicious Link
GroupTA578

TA578 has placed malicious links in contact forms on victim sites, often spoofing a copyright complaint, to redirect users to malicious file downloads.

T1204.001
Malicious Link
GroupLazyScripter

LazyScripter has relied upon users clicking on links to malicious files.

T1204.001
Malicious Link
GroupWindshift

Windshift has used links embedded in e-mails to lure victims into executing malicious code.

T1204.001
Malicious Link
GroupLuminousMoth

LuminousMoth has lured victims into clicking malicious Dropbox download links delivered through spearphishing.

T1204.001
Malicious Link
GroupAPT28

APT28 has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders.

T1204.001
Malicious Link
GroupAPT-C-36

APT-C-36 has used malicious links in emails, often impersonating official notifications and documents, to direct users to execute malicious payloads.

T1204.001
Malicious Link
GroupEarth Lusca

Earth Lusca has sent spearphishing emails that required the user to click on a malicious link and subsequently open a decoy document with a malicious loader.

T1204.001
Malicious Link
GroupFIN4

FIN4 has lured victims to click malicious links delivered via spearphishing emails (often sent from compromised accounts).

T1204.001
Malicious Link
GroupCobalt Group

Cobalt Group has sent emails containing malicious links that require users to execute a file or macro to infect the victim machine.

T1204.001
Malicious Link
GroupWizard Spider

Wizard Spider has lured victims into clicking a malicious link delivered through spearphishing.

T1204.001
Malicious Link
GroupMolerats

Molerats has sent malicious links via email trick users into opening a RAR archive and running an executable.

T1204.001
Malicious Link
GroupTransparent Tribe

Transparent Tribe has directed users to open URLs hosting malicious content.

T1204.001
Malicious Link
GroupDaggerfly

Daggerfly has used strategic website compromise to deliver a malicious link requiring user interaction.

T1204.001
Malicious Link
GroupWIRTE

WIRTE has used links embedded in emails to lure users into downloading malicious files.

T1204.001
Malicious Link
GroupMagic Hound

Magic Hound has attempted to lure victims into opening malicious links embedded in emails.

T1204.001
Malicious Link
GroupAPT33

APT33 has lured users to click links to malicious HTML applications delivered via spearphishing emails.

T1204.001
Malicious Link
GroupFIN8

FIN8 has used emails with malicious links to lure victims into installing malware.

T1204.002
Malicious File
GroupAPT38

APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files.

T1204.002
Malicious File
GroupIndrik Spider

Indrik Spider has attempted to get users to click on a malicious zipped file.

T1204.002
Malicious File
GroupElderwood

Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open attachments.

T1204.002
Malicious File
GroupSideCopy

SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns.

T1204.002
Malicious File
GroupKimsuky

Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background.

T1204.002
Malicious File
GroupEXOTIC LILY

EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO.

T1204.002
Malicious File
Groupadmin@338

admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupPatchwork

Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware.

T1204.002
Malicious File
GroupDragonfly

Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments.

T1204.002
Malicious File
GroupGorgon Group

Gorgon Group attempted to get users to launch malicious Microsoft Office attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupmenuPass

menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns.

T1204.002
Malicious File
GroupAPT32

APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment.

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1204.002
Malicious File
GroupNaikon

Naikon has convinced victims to open malicious attachments to execute malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.