Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.001 Spearphishing Attachment |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers. |
| T1566.001 Spearphishing Attachment |
CampaignFrankenstein | During Frankenstein, the threat actors likely used spearphishing emails to send malicious Microsoft Word documents. |
| T1566.001 Spearphishing Attachment |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda leveraged malicious attachments in spearphishing emails for initial access to victim environments in RedDelta Modified PlugX Infection Chain Operations. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document. |
| T1566.001 Spearphishing Attachment |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team obtained their initial foothold into many IT systems using Microsoft Office attachments delivered through phishing emails. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Spalax | During Operation Spalax, the threat actors sent phishing emails that included a PDF document that in some cases led to the download and execution of malware. |
| T1566.001 Spearphishing Attachment |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution attached password-protected ZIP archives to deliver Pikabot installers. |
| T1566.001 Spearphishing Attachment |
CampaignC0015 | For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims. |
| T1566.001 Spearphishing Attachment |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments. |
| T1566.001 Spearphishing Attachment |
CampaignC0011 | During C0011, Transparent Tribe sent malicious attachments via email to student targets in India. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.