Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.001 Malicious Link |
GroupSandworm Team | Sandworm Team has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders. |
| T1204.001 Malicious Link |
GroupMachete | Machete has has relied on users opening malicious links delivered through spearphishing to execute malware. |
| T1204.001 Malicious Link |
GroupSidewinder | Sidewinder has lured targets to click on malicious links to gain execution in the target environment. |
| T1204.001 Malicious Link |
GroupMustang Panda | Mustang Panda has sent malicious links including links directing victims to a Google Drive folder. Mustang Panda has also utilized webpages with Javascript code that downloads malicious payloads to the victim device. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACrowdstrike MUSTANG PANDA June 2018Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025McAfee Dianxun March 2021Proofpoint TA416 Europe March 2022 |
| T1204.001 Malicious Link |
GroupZIRCONIUM | ZIRCONIUM has used malicious links in e-mails to lure victims into downloading malware. |
| T1204.001 Malicious Link |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link. |
| T1204.001 Malicious Link |
GroupContagious Interview | Contagious Interview has lured victims to click on a malicious link that led to download of a malicious payload. Contagious Interview has also leveraged links to malicious payloads on social media and code repositories. |
| T1204.001 Malicious Link |
GroupTA2541 | TA2541 has used malicious links to cloud and web services to gain execution on victim machines. |
| T1204.001 Malicious Link |
GroupOilRig | OilRig has delivered malicious links to achieve execution on the target system. |
| T1204.001 Malicious Link |
GroupSaint Bear | Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution. |
| T1204.001 Malicious Link |
GroupConfucius | Confucius has lured victims into clicking on a malicious link sent through spearphishing. |
| T1204.001 Malicious Link |
GroupBlackTech | BlackTech has used e-mails with malicious links to lure victims into installing malware. |
| T1204.001 Malicious Link |
GroupLeviathan | Leviathan has sent spearphishing email links attempting to get a user to click. |
| T1204.001 Malicious Link |
GroupWinter Vivern | Winter Vivern has mimicked legitimate government-related domains to deliver malicious webpages containing links to documents or other content for user execution. |
| T1204.001 Malicious Link |
GroupTurla | Turla has used spearphishing via a link to get users to download and run their malware. |
| T1204.001 Malicious Link |
GroupTA505 | TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1204.001 Malicious Link |
GroupRedCurl | RedCurl has used malicious links to infect the victim machines. |
| T1204.001 Malicious Link |
GroupMofang | Mofang's spearphishing emails required a user to click the link to connect to a compromised website. |
| T1204.001 Malicious Link |
GroupAPT29 | APT29 has used various forms of spearphishing attempting to get a user to click on a malicious link. |
| T1204.001 Malicious Link |
GroupTA578 | TA578 has placed malicious links in contact forms on victim sites, often spoofing a copyright complaint, to redirect users to malicious file downloads. |
| T1204.001 Malicious Link |
GroupLazyScripter | LazyScripter has relied upon users clicking on links to malicious files. |
| T1204.001 Malicious Link |
GroupWindshift | Windshift has used links embedded in e-mails to lure victims into executing malicious code. |
| T1204.001 Malicious Link |
GroupLuminousMoth | LuminousMoth has lured victims into clicking malicious Dropbox download links delivered through spearphishing. |
| T1204.001 Malicious Link |
GroupAPT28 | APT28 has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders. |
| T1204.001 Malicious Link |
GroupAPT-C-36 | APT-C-36 has used malicious links in emails, often impersonating official notifications and documents, to direct users to execute malicious payloads. |
| T1204.001 Malicious Link |
GroupEarth Lusca | Earth Lusca has sent spearphishing emails that required the user to click on a malicious link and subsequently open a decoy document with a malicious loader. |
| T1204.001 Malicious Link |
GroupFIN4 | FIN4 has lured victims to click malicious links delivered via spearphishing emails (often sent from compromised accounts). |
| T1204.001 Malicious Link |
GroupCobalt Group | Cobalt Group has sent emails containing malicious links that require users to execute a file or macro to infect the victim machine. |
| T1204.001 Malicious Link |
GroupWizard Spider | Wizard Spider has lured victims into clicking a malicious link delivered through spearphishing. |
| T1204.001 Malicious Link |
GroupMolerats | Molerats has sent malicious links via email trick users into opening a RAR archive and running an executable. |
| T1204.001 Malicious Link |
GroupTransparent Tribe | Transparent Tribe has directed users to open URLs hosting malicious content. |
| T1204.001 Malicious Link |
GroupDaggerfly | Daggerfly has used strategic website compromise to deliver a malicious link requiring user interaction. |
| T1204.001 Malicious Link |
GroupWIRTE | WIRTE has used links embedded in emails to lure users into downloading malicious files. |
| T1204.001 Malicious Link |
GroupMagic Hound | Magic Hound has attempted to lure victims into opening malicious links embedded in emails. |
| T1204.001 Malicious Link |
GroupAPT33 | APT33 has lured users to click links to malicious HTML applications delivered via spearphishing emails. |
| T1204.001 Malicious Link |
GroupFIN8 | FIN8 has used emails with malicious links to lure victims into installing malware. |
| T1204.002 Malicious File |
GroupAPT38 | APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files. |
| T1204.002 Malicious File |
GroupIndrik Spider | Indrik Spider has attempted to get users to click on a malicious zipped file. |
| T1204.002 Malicious File |
GroupElderwood | Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open attachments. |
| T1204.002 Malicious File |
GroupSideCopy | SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns. |
| T1204.002 Malicious File |
GroupKimsuky | Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background. |
| T1204.002 Malicious File |
GroupEXOTIC LILY | EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO. |
| T1204.002 Malicious File |
Groupadmin@338 | admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupPatchwork | Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware. |
| T1204.002 Malicious File |
GroupDragonfly | Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments. |
| T1204.002 Malicious File |
GroupGorgon Group | Gorgon Group attempted to get users to launch malicious Microsoft Office attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupmenuPass | menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns. |
| T1204.002 Malicious File |
GroupAPT32 | APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment. |
| T1204.002 Malicious File |
GroupMuddyWater | MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1204.002 Malicious File |
GroupNaikon | Naikon has convinced victims to open malicious attachments to execute malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.