Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.002 Malicious File |
GroupFIN6 | FIN6 has used malicious documents to lure victims into allowing execution of PowerShell scripts. |
| T1204.002 Malicious File |
GroupGamaredon Group | Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files. |
| T1204.002 Malicious File |
GroupGallmaker | Gallmaker sent victims a lure document with a warning that asked victims to “enable content” for execution. |
| T1204.002 Malicious File |
GroupStorm-1811 | Storm-1811 has prompted users to execute downloaded software and payloads as the result of social engineering activity. |
| T1204.002 Malicious File |
GroupFIN7 | FIN7 lured victims to double-click on images in the attachments they sent which would then execute the hidden LNK file. Additionally, FIN7 has used malicious Microsoft Word and Excel files and Leo VBS to distribute an updated version of JSS Loader and to distribute the Harpy backdoor. |
| T1204.002 Malicious File |
GroupSandworm Team | Sandworm Team has tricked unwitting recipients into clicking on spearphishing attachments and enabling malicious macros embedded within files. |
| T1204.002 Malicious File |
GroupMachete | Machete has relied on users opening malicious attachments delivered through spearphishing to execute malware. |
| T1204.002 Malicious File |
GroupAndariel | Andariel has attempted to lure victims into enabling malicious macros within email attachments. |
| T1204.002 Malicious File |
GroupCURIUM | CURIUM has lured users into opening malicious files delivered via social media. |
| T1204.002 Malicious File |
GroupSidewinder | Sidewinder has lured targets to click on malicious files to gain execution in the target environment. |
| T1204.002 Malicious File |
GroupMustang Panda | Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019Avira Mustang Panda January 2020CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Proofpoint TA416 Europe March 2022Recorded Future REDDELTA July 2020Sophos Mustang Panda PLUGXSophos PlugX September 2022Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1204.002 Malicious File |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment. |
| T1204.002 Malicious File |
GroupContagious Interview | Contagious Interview has distributed malicious files requiring direct victim interaction to execute through the guise of a code test. |
| T1204.002 Malicious File |
GroupTA2541 | TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads. |
| T1204.002 Malicious File |
GroupAPT37 | APT37 has sent spearphishing attachments attempting to get a user to open them. |
| T1204.002 Malicious File |
GroupOilRig | OilRig has delivered macro-enabled documents that required targets to click the "enable content" button to execute the payload on the system. |
| T1204.002 Malicious File |
GroupHigaisa | Higaisa used malicious e-mail attachments to lure victims into executing LNK files. |
| T1204.002 Malicious File |
GroupTropic Trooper | Tropic Trooper has lured victims into executing malware via malicious e-mail attachments. |
| T1204.002 Malicious File |
GroupTA459 | TA459 has attempted to get victims to open malicious Microsoft Word attachment sent via spearphishing. |
| T1204.002 Malicious File |
GroupAoqin Dragon | Aoqin Dragon has lured victims into opening weaponized documents, fake external drives, and fake antivirus to execute malicious payloads. |
| T1204.002 Malicious File |
GroupFerocious Kitten | Ferocious Kitten has attempted to convince victims to enable malicious content within a spearphishing email by including an odd decoy message. |
| T1204.002 Malicious File |
GroupThe White Company | The White Company has used phishing lure documents that trick users into opening them and infecting their computers. |
| T1204.002 Malicious File |
GroupSaint Bear | Saint Bear relies on user interaction and execution of malicious attachments and similar for initial execution on victim systems. |
| T1204.002 Malicious File |
GroupDarkHydrus | DarkHydrus has sent malware that required users to hit the enable button in Microsoft Excel to allow an .iqy file to be downloaded. |
| T1204.002 Malicious File |
GroupConfucius | Confucius has lured victims to execute malicious attachments included in crafted spearphishing emails related to current topics. |
| T1204.002 Malicious File |
GroupBlackTech | BlackTech has used e-mails with malicious documents to lure victims into installing malware. |
| T1204.002 Malicious File |
GroupLeviathan | Leviathan has sent spearphishing attachments attempting to get a user to click. |
| T1204.002 Malicious File |
GroupTA505 | TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1204.002 Malicious File |
GroupBITTER | BITTER has attempted to lure victims into opening malicious attachments delivered via spearphishing. |
| T1204.002 Malicious File |
GroupRedCurl | RedCurl has used malicious files to infect the victim machines. |
| T1204.002 Malicious File |
GroupMofang | Mofang's malicious spearphishing attachments required a user to open the file after receiving. |
| T1204.002 Malicious File |
GroupAPT29 | APT29 has used various forms of spearphishing attempting to get a user to open attachments, including, but not limited to, malicious Microsoft Word documents, .pdf, and .lnk files. |
| T1204.002 Malicious File |
GroupDark Caracal | Dark Caracal makes their malware look like Flash Player, Office, or PDF documents in order to entice a user to click on it. |
| T1204.002 Malicious File |
GroupMirrorFace | MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution. |
| T1204.002 Malicious File |
GroupBRONZE BUTLER | BRONZE BUTLER has attempted to get users to launch malicious Microsoft Word attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupTA551 | TA551 has prompted users to enable macros within spearphishing attachments to install malware. |
| T1204.002 Malicious File |
GroupStar Blizzard | Star Blizzard has lured targets into opening malicious .pdf files to deliver malware. |
| T1204.002 Malicious File |
GroupDarkhotel | Darkhotel has sent spearphishing emails in an attempt to lure users into clicking on a malicious attachments. |
| T1204.002 Malicious File |
GroupLazyScripter | LazyScripter has lured users to open malicious email attachments. |
| T1204.002 Malicious File |
GroupWindshift | Windshift has used e-mail attachments to lure victims into executing malicious code. |
| T1204.002 Malicious File |
GroupWhitefly | Whitefly has used malicious .exe or .dll files disguised as documents or images. |
| T1204.002 Malicious File |
GroupAPT28 | APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts. |
| T1204.002 Malicious File |
GroupMalteiro | Malteiro has relied on users to execute .zip file attachments containing malicious URLs. |
| T1204.002 Malicious File |
GroupRTM | RTM has attempted to lure victims into opening e-mail attachments to execute malicious code. |
| T1204.002 Malicious File |
GroupAPT12 | APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing. |
| T1204.002 Malicious File |
GroupAPT-C-36 | APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware. |
| T1204.002 Malicious File |
GroupTonto Team | Tonto Team has relied on user interaction to open their malicious RTF documents. |
| T1204.002 Malicious File |
GroupLazarus Group | Lazarus Group has attempted to get users to launch a malicious Microsoft Word attachment delivered via a spearphishing email. |
| T1204.002 Malicious File |
GroupEarth Lusca | Earth Lusca required users to click on a malicious file for the loader to activate. |
| T1204.002 Malicious File |
GroupFIN4 | FIN4 has lured victims to launch malicious attachments delivered via spearphishing emails (often sent from compromised accounts). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.