ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1566.002
Spearphishing Link
GroupMustard Tempest

Mustard Tempest has sent victims emails containing links to compromised websites.

T1566.002
Spearphishing Link
GroupKimsuky

Kimsuky has sent spearphishing emails containing a link to a document that contained malicious macros or took the victim to an actor-controlled domain.

T1566.002
Spearphishing Link
GroupEXOTIC LILY

EXOTIC LILY has relied on victims to open malicious links in e-mails for execution.

T1566.002
Spearphishing Link
GroupTA577

TA577 has sent emails containing links to malicious JavaScript files.

T1566.002
Spearphishing Link
GroupPatchwork

Patchwork has used spearphishing with links to deliver files with exploits to initial victims.

T1566.002
Spearphishing Link
GroupEvilnum

Evilnum has sent spearphishing emails containing a link to a zip file hosted on Google Drive.

T1566.002
Spearphishing Link
GroupAPT32

APT32 has sent spearphishing emails containing malicious links.

T1566.002
Spearphishing Link
GroupMuddyWater

MuddyWater has sent targeted spearphishing e-mails with malicious links.

T1566.002
Spearphishing Link
GroupStorm-1811

Storm-1811 has distributed malicious links to victims that redirect to EvilProxy-based phishing sites to harvest credentials.

T1566.002
Spearphishing Link
GroupFIN7

FIN7 has conducted broad phishing campaigns using malicious links. Additionally, FIN7 has sent spearphishing emails containing a typosquatted link to “ip-sccanner[.]com.”

T1566.002
Spearphishing Link
GroupSandworm Team

Sandworm Team has crafted phishing emails containing malicious hyperlinks.

T1566.002
Spearphishing Link
GroupMachete

Machete has sent phishing emails that contain a link to an external server with ZIP and RAR archives.

T1566.002
Spearphishing Link
GroupSidewinder

Sidewinder has sent e-mails with malicious links often crafted for specific targets.

T1566.002
Spearphishing Link
GroupMustang Panda

Mustang Panda has delivered malicious links to their intended targets. Mustang Panda has distributed spear-phishing emails with embedded links that direct the victim to a malicious archive hosted on Google or Dropbox.

T1566.002
Spearphishing Link
GroupZIRCONIUM

ZIRCONIUM has used malicious links in e-mails to deliver malware.

T1566.002
Spearphishing Link
GroupAPT39

APT39 leveraged spearphishing emails with malicious links to initially compromise victims.

T1566.002
Spearphishing Link
GroupTA2541

TA2541 has used spearphishing e-mails with malicious links to deliver malware.

T1566.002
Spearphishing Link
GroupOilRig

OilRig has sent spearphising emails with malicious links to potential victims.

T1566.002
Spearphishing Link
GroupAPT1

APT1 has sent spearphishing emails containing hyperlinks to malicious files.

T1566.002
Spearphishing Link
GroupConfucius

Confucius has sent malicious links to victims through email campaigns.

T1566.002
Spearphishing Link
GroupBlackTech

BlackTech has used spearphishing e-mails with links to cloud services to deliver malware.

T1566.002
Spearphishing Link
GroupLeviathan

Leviathan has sent spearphishing emails with links, often using a fraudulent lookalike domain and stolen branding.

T1566.002
Spearphishing Link
GroupTurla

Turla attempted to trick targets into clicking on a link featuring a seemingly legitimate domain from Adobe.com to download their malware and gain initial access.

T1566.002
Spearphishing Link
GroupTA505

TA505 has sent spearphishing emails containing malicious links.

T1566.002
Spearphishing Link
GroupRedCurl

RedCurl has used phishing emails with malicious links to gain initial access.

T1566.002
Spearphishing Link
GroupMofang

Mofang delivered spearphishing emails with malicious links included.

T1566.002
Spearphishing Link
GroupAPT29

APT29 has used spearphishing with a link to trick victims into clicking on a link to a zip file containing malicious files.

T1566.002
Spearphishing Link
GroupMirrorFace

MirrorFace has embedded OneDrive URLs in emails leading to malicious file installation.

T1566.002
Spearphishing Link
GroupLazyScripter

LazyScripter has used spam emails that contain a link that redirects the victim to download a malicious document.

T1566.002
Spearphishing Link
GroupWindshift

Windshift has sent spearphishing emails with links to harvest credentials and deliver malware.

T1566.002
Spearphishing Link
GroupLuminousMoth

LuminousMoth has sent spearphishing emails containing a malicious Dropbox download link.

T1566.002
Spearphishing Link
GroupAPT42

APT42 has sent spearphishing emails containing malicious links.

T1566.002
Spearphishing Link
GroupAPT-C-36

APT-C-36 has sent emails containing a link that appear to lead to an urgent notification from a government institution, at times using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to.

T1566.002
Spearphishing Link
GroupLazarus Group

Lazarus Group has sent malicious links to victims via email.

T1566.002
Spearphishing Link
GroupEarth Lusca

Earth Lusca has sent spearphishing emails to potential targets that contained a malicious link.

T1566.002
Spearphishing Link
GroupFIN4

FIN4 has used spearphishing emails (often sent from compromised accounts) containing malicious links.

T1566.002
Spearphishing Link
GroupCobalt Group

Cobalt Group has sent emails with URLs pointing to malicious documents.

T1566.002
Spearphishing Link
GroupWizard Spider

Wizard Spider has sent phishing emails containing a link to an actor-controlled Google Drive document or other free online file hosting services.

T1566.002
Spearphishing Link
GroupMolerats

Molerats has sent phishing emails with malicious links included.

T1566.002
Spearphishing Link
GroupTransparent Tribe

Transparent Tribe has embedded links to malicious downloads in e-mails.

T1566.002
Spearphishing Link
GroupWIRTE

WIRTE has sent targeted spearphishing emails with malicious links directing victims to malware downloads.

T1566.002
Spearphishing Link
GroupMagic Hound

Magic Hound has sent malicious URL links through email to victims. In some cases the URLs were shortened or linked to Word documents with malicious macros that executed PowerShells scripts to download Pupy.

T1566.002
Spearphishing Link
GroupAPT33

APT33 has sent spearphishing emails containing links to .hta files.

T1566.002
Spearphishing Link
GroupFIN8

FIN8 has distributed targeted emails containing links to malicious documents with embedded macros.

T1566.003
Spearphishing via Service
GroupEXOTIC LILY

EXOTIC LILY has used the e-mail notification features of legitimate file sharing services for spearphishing.

T1566.003
Spearphishing via Service
GroupFIN6

FIN6 has used fake job advertisements sent via LinkedIn to spearphish targets.

T1566.003
Spearphishing via Service
GroupStorm-1811

Storm-1811 has used Microsoft Teams to send messages and initiate voice calls to victims posing as IT support personnel.

T1566.003
Spearphishing via Service
GroupCURIUM

CURIUM has used social media to deliver malicious files to victims.

T1566.003
Spearphishing via Service
GroupContagious Interview

Contagious Interview has used fake job advertisements and messages sent via social media to spearphish targets. Contagious Interview has also leveraged hiring websites to solicit victims.

T1566.003
Spearphishing via Service
GroupOilRig

OilRig has used LinkedIn to send spearphishing links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.