Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.001 Spearphishing Attachment |
GroupTA459 | TA459 has targeted victims using spearphishing emails with malicious Microsoft Word attachments. |
| T1566.001 Spearphishing Attachment |
GroupFerocious Kitten | Ferocious Kitten has conducted spearphishing campaigns containing malicious documents to lure victims to open the attachments. |
| T1566.001 Spearphishing Attachment |
GroupThe White Company | The White Company has sent phishing emails with malicious Microsoft Word attachments to victims. |
| T1566.001 Spearphishing Attachment |
GroupSaint Bear | Saint Bear uses a variety of file formats, such as Microsoft Office documents, ZIP archives, PDF documents, and other items as phishing attachments for initial access. |
| T1566.001 Spearphishing Attachment |
GroupAPT1 | APT1 has sent spearphishing emails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
GroupDarkHydrus | DarkHydrus has sent spearphishing emails with password-protected RAR archives containing malicious Excel Web Query files (.iqy). The group has also sent spearphishing emails that contained malicious Microsoft Office documents that use the “attachedTemplate” technique to load a template from a remote server. |
| T1566.001 Spearphishing Attachment |
GroupConfucius | Confucius has crafted and sent victims malicious attachments to gain initial access. |
| T1566.001 Spearphishing Attachment |
GroupBlackTech | BlackTech has used spearphishing e-mails with malicious password-protected archived files (ZIP or RAR) to deliver malware. |
| T1566.001 Spearphishing Attachment |
GroupLeviathan | Leviathan has sent spearphishing emails with malicious attachments, including .rtf, .doc, and .xls files. |
| T1566.001 Spearphishing Attachment |
GroupWinter Vivern | Winter Vivern leverages malicious attachments delivered via email for initial access activity. |
| T1566.001 Spearphishing Attachment |
GroupTA505 | TA505 has used spearphishing emails with malicious attachments to initially compromise victims. |
| T1566.001 Spearphishing Attachment |
GroupBITTER | BITTER has sent spearphishing emails with a malicious RTF document or Excel spreadsheet. |
| T1566.001 Spearphishing Attachment |
GroupRedCurl | RedCurl has used phishing emails with malicious files to gain initial access. |
| T1566.001 Spearphishing Attachment |
GroupMofang | Mofang delivered spearphishing emails with malicious documents, PDFs, or Excel files attached. |
| T1566.001 Spearphishing Attachment |
GroupAPT29 | APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims. |
| T1566.001 Spearphishing Attachment |
GroupMirrorFace | MirrorFace has sent spearphishing emails with malicious attachments to deliver malware payloads. |
| T1566.001 Spearphishing Attachment |
GroupBRONZE BUTLER | BRONZE BUTLER used spearphishing emails with malicious Microsoft Word attachments to infect victims. |
| T1566.001 Spearphishing Attachment |
GroupTA551 | TA551 has sent spearphishing attachments with password protected ZIP files. |
| T1566.001 Spearphishing Attachment |
GroupStar Blizzard | Star Blizzard has sent emails with malicious .pdf files to spread malware. |
| T1566.001 Spearphishing Attachment |
GroupDarkhotel | Darkhotel has sent spearphishing emails with malicious RAR and .LNK attachments. |
| T1566.001 Spearphishing Attachment |
GroupLazyScripter | LazyScripter has used spam emails weaponized with archive or document files as its initial infection vector. |
| T1566.001 Spearphishing Attachment |
GroupWindshift | Windshift has sent spearphishing emails with attachment to harvest credentials and deliver malware. |
| T1566.001 Spearphishing Attachment |
GroupAPT28 | APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments. |
| T1566.001 Spearphishing Attachment |
GroupMalteiro | Malteiro has sent spearphishing emails containing malicious .zip files. |
| T1566.001 Spearphishing Attachment |
GroupRTM | RTM has used spearphishing attachments to distribute its malware. |
| T1566.001 Spearphishing Attachment |
GroupAPT12 | APT12 has sent emails with malicious Microsoft Office documents and PDFs attached. |
| T1566.001 Spearphishing Attachment |
GroupAPT-C-36 | APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway. |
| T1566.001 Spearphishing Attachment |
GroupTonto Team | Tonto Team has delivered payloads via spearphishing attachments. |
| T1566.001 Spearphishing Attachment |
GroupLazarus Group | Lazarus Group has targeted victims with spearphishing emails containing malicious Microsoft Word documents. |
| T1566.001 Spearphishing Attachment |
GroupFIN4 | FIN4 has used spearphishing emails containing attachments (which are often stolen, legitimate documents sent from compromised accounts) with embedded malicious macros. |
| T1566.001 Spearphishing Attachment |
GroupSilence | Silence has sent emails with malicious DOCX, CHM, LNK and ZIP attachments. |
| T1566.001 Spearphishing Attachment |
GroupCobalt Group | Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables. |
| T1566.001 Spearphishing Attachment |
GroupWizard Spider | Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar. |
| T1566.001 Spearphishing Attachment |
GroupMolerats | Molerats has sent phishing emails with malicious Microsoft Word and PDF attachments. |
| T1566.001 Spearphishing Attachment |
GroupTransparent Tribe | Transparent Tribe has sent spearphishing e-mails with attachments to deliver malicious payloads. |
| T1566.001 Spearphishing Attachment |
GroupIndigoZebra | IndigoZebra sent spearphishing emails containing malicious password-protected RAR attachments. |
| T1566.001 Spearphishing Attachment |
GroupMoonstone Sleet | Moonstone Sleet delivered various payloads to victims as spearphishing attachments. |
| T1566.001 Spearphishing Attachment |
GroupInception | Inception has used weaponized documents attached to spearphishing emails for reconnaissance and initial compromise. |
| T1566.001 Spearphishing Attachment |
GroupAPT30 | APT30 has used spearphishing emails with malicious DOC attachments. |
| T1566.001 Spearphishing Attachment |
GroupRancor | Rancor has attached a malicious document to an email to gain initial access. |
| T1566.001 Spearphishing Attachment |
GroupWIRTE | WIRTE has sent emails to intended victims with malicious MS Word and Excel attachments. |
| T1566.001 Spearphishing Attachment |
GroupPLATINUM | PLATINUM has sent spearphishing emails with attachments to victims as its primary initial access vector. |
| T1566.001 Spearphishing Attachment |
GroupAjax Security Team | Ajax Security Team has used personalized spearphishing attachments. |
| T1566.001 Spearphishing Attachment |
GroupThreat Group-3390 | Threat Group-3390 has used e-mail to deliver malicious attachments to victims. |
| T1566.001 Spearphishing Attachment |
GroupAPT33 | APT33 has sent spearphishing e-mails with archive attachments. |
| T1566.001 Spearphishing Attachment |
GroupFIN8 | FIN8 has distributed targeted emails containing Word documents with embedded malicious macros. |
| T1566.001 Spearphishing Attachment |
GroupAPT19 | APT19 sent spearphishing emails with malicious attachments in RTF and XLSM formats to deliver initial exploits. |
| T1566.001 Spearphishing Attachment |
GroupNomadic Octopus | Nomadic Octopus has targeted victims with spearphishing emails containing malicious attachments. |
| T1566.002 Spearphishing Link |
GroupElderwood | Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing a link to malicious content hosted on an uncommon Web server. |
| T1566.002 Spearphishing Link |
GroupAPT3 | APT3 has sent spearphishing emails containing malicious links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.