ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1566.001×

10 examples

TechniqueUsed byProcedure example
T1566.001
Spearphishing Attachment
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers.

T1566.001
Spearphishing Attachment
CampaignFrankenstein

During Frankenstein, the threat actors likely used spearphishing emails to send malicious Microsoft Word documents.

T1566.001
Spearphishing Attachment
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda leveraged malicious attachments in spearphishing emails for initial access to victim environments in RedDelta Modified PlugX Infection Chain Operations.

T1566.001
Spearphishing Attachment
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document.

T1566.001
Spearphishing Attachment
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team obtained their initial foothold into many IT systems using Microsoft Office attachments delivered through phishing emails.

T1566.001
Spearphishing Attachment
CampaignOperation Spalax

During Operation Spalax, the threat actors sent phishing emails that included a PDF document that in some cases led to the download and execution of malware.

T1566.001
Spearphishing Attachment
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution attached password-protected ZIP archives to deliver Pikabot installers.

T1566.001
Spearphishing Attachment
CampaignC0015

For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims.

T1566.001
Spearphishing Attachment
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments.

T1566.001
Spearphishing Attachment
CampaignC0011

During C0011, Transparent Tribe sent malicious attachments via email to student targets in India.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.