ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1566.002×

9 examples

TechniqueUsed byProcedure example
T1566.002
Spearphishing Link
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email.

T1566.002
Spearphishing Link
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda distributed malicious links in phishing emails leading to HTML files that would direct the victim to malicious MSC files if running Windows based on User Agent fingerprinting during RedDelta Modified PlugX Infection Chain Operations.

T1566.002
Spearphishing Link
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors sent spearphishing emails containing a malicious link.

T1566.002
Spearphishing Link
CampaignOperation Spalax

During Operation Spalax, the threat actors sent phishing emails to victims that contained a malicious link.

T1566.002
Spearphishing Link
CampaignC0021

During C0021, the threat actors sent phishing emails with unique malicious links, likely for tracking victim clicks.

T1566.002
Spearphishing Link
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized emails with hyperlinks leading to malicious ZIP archive files containing scripts to download and install Pikabot.

T1566.002
Spearphishing Link
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace sent spearphishing emails with malicious OneDrive links.

T1566.002
Spearphishing Link
CampaignNight Dragon

During Night Dragon, threat actors sent spearphishing emails containing links to compromised websites where malware was downloaded.

T1566.002
Spearphishing Link
CampaignC0011

During C0011, Transparent Tribe sent emails containing a malicious link to student targets in India.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.