Real-world descriptions of how a group, tool or campaign used a technique.
12 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.002 Malicious File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors. |
| T1204.002 Malicious File |
CampaignFrankenstein | During Frankenstein, the threat actors relied on a victim to enable macros within a malicious Microsoft Word document likely sent via email. |
| T1204.002 Malicious File |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda distributed malicious LNK objects for user execution during RedDelta Modified PlugX Infection Chain Operations. |
| T1204.002 Malicious File |
CampaignOperation Sharpshooter | During Operation Sharpshooter, the threat actors relied on victims executing malicious Microsoft Word or PDF files. |
| T1204.002 Malicious File |
CampaignOperation Honeybee | During Operation Honeybee, threat actors relied on a victim to enable macros within a malicious Word document. |
| T1204.002 Malicious File |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors relied on potential victims to open a malicious Microsoft Word document sent via email. |
| T1204.002 Malicious File |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them. |
| T1204.002 Malicious File |
CampaignOperation Spalax | During Operation Spalax, the threat actors relied on a victim to open a PDF document and click on an embedded malicious link to download malware. |
| T1204.002 Malicious File |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution delivered Pikabot installers as password-protected ZIP files containing heavily obfuscated JavaScript, or IMG files containing an LNK mimicking a Word document and a malicious DLL. |
| T1204.002 Malicious File |
CampaignC0015 | During C0015, the threat actors relied on users to enable macros within a malicious Microsoft Word document. |
| T1204.002 Malicious File |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace lured victims into executing malicious payloads by opening email attachments. |
| T1204.002 Malicious File |
CampaignC0011 | During C0011, Transparent Tribe relied on a student target to open a malicious document delivered via email. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.