ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1204.001×

49 examples

TechniqueUsed byProcedure example
T1204.001
Malicious Link
GroupAPT38

APT38 has used links to execute a malicious Visual Basic script.

T1204.001
Malicious Link
GroupElderwood

Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open links.

T1204.001
Malicious Link
GroupAPT3

APT3 has lured victims into clicking malicious links delivered through spearphishing.

T1204.001
Malicious Link
GroupMustard Tempest

Mustard Tempest has lured users into downloading malware through malicious links in fake advertisements and spearphishing emails.

T1204.001
Malicious Link
GroupKimsuky

Kimsuky has lured victims into clicking malicious links.

T1204.001
Malicious Link
GroupEXOTIC LILY

EXOTIC LILY has used malicious links to lure users into executing malicious payloads.

T1204.001
Malicious Link
GroupTA577

TA577 has lured users into executing malicious JavaScript files by sending malicious links via email.

T1204.001
Malicious Link
GroupPatchwork

Patchwork has used spearphishing with links to try to get users to click, download and open malicious files.

T1204.001
Malicious Link
GroupEvilnum

Evilnum has sent spearphishing emails designed to trick the recipient into opening malicious shortcut links which downloads a .LNK file.

T1204.001
Malicious Link
GroupAPT32

APT32 has lured targets to download a Cobalt Strike beacon by including a malicious link within spearphishing emails.

T1204.001
Malicious Link
GroupMuddyWater

MuddyWater has distributed URLs in phishing e-mails that link to lure documents.

T1204.001
Malicious Link
GroupGamaredon Group

Gamaredon Group has attempted to get users to click on a link pointing to a malicious HTML file leading to follow-on malicious content.

T1204.001
Malicious Link
GroupFIN7

FIN7 has used malicious links to lure victims into downloading malware.

T1204.001
Malicious Link
GroupSandworm Team

Sandworm Team has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders.

T1204.001
Malicious Link
GroupMachete

Machete has has relied on users opening malicious links delivered through spearphishing to execute malware.

T1204.001
Malicious Link
GroupSidewinder

Sidewinder has lured targets to click on malicious links to gain execution in the target environment.

T1204.001
Malicious Link
GroupMustang Panda

Mustang Panda has sent malicious links including links directing victims to a Google Drive folder. Mustang Panda has also utilized webpages with Javascript code that downloads malicious payloads to the victim device.

T1204.001
Malicious Link
GroupZIRCONIUM

ZIRCONIUM has used malicious links in e-mails to lure victims into downloading malware.

T1204.001
Malicious Link
GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link.

T1204.001
Malicious Link
GroupContagious Interview

Contagious Interview has lured victims to click on a malicious link that led to download of a malicious payload. Contagious Interview has also leveraged links to malicious payloads on social media and code repositories.

T1204.001
Malicious Link
GroupTA2541

TA2541 has used malicious links to cloud and web services to gain execution on victim machines.

T1204.001
Malicious Link
GroupOilRig

OilRig has delivered malicious links to achieve execution on the target system.

T1204.001
Malicious Link
GroupSaint Bear

Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution.

T1204.001
Malicious Link
GroupConfucius

Confucius has lured victims into clicking on a malicious link sent through spearphishing.

T1204.001
Malicious Link
GroupBlackTech

BlackTech has used e-mails with malicious links to lure victims into installing malware.

T1204.001
Malicious Link
GroupLeviathan

Leviathan has sent spearphishing email links attempting to get a user to click.

T1204.001
Malicious Link
GroupWinter Vivern

Winter Vivern has mimicked legitimate government-related domains to deliver malicious webpages containing links to documents or other content for user execution.

T1204.001
Malicious Link
GroupTurla

Turla has used spearphishing via a link to get users to download and run their malware.

T1204.001
Malicious Link
GroupTA505

TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1204.001
Malicious Link
GroupRedCurl

RedCurl has used malicious links to infect the victim machines.

T1204.001
Malicious Link
GroupMofang

Mofang's spearphishing emails required a user to click the link to connect to a compromised website.

T1204.001
Malicious Link
GroupAPT29

APT29 has used various forms of spearphishing attempting to get a user to click on a malicious link.

T1204.001
Malicious Link
GroupTA578

TA578 has placed malicious links in contact forms on victim sites, often spoofing a copyright complaint, to redirect users to malicious file downloads.

T1204.001
Malicious Link
GroupLazyScripter

LazyScripter has relied upon users clicking on links to malicious files.

T1204.001
Malicious Link
GroupWindshift

Windshift has used links embedded in e-mails to lure victims into executing malicious code.

T1204.001
Malicious Link
GroupLuminousMoth

LuminousMoth has lured victims into clicking malicious Dropbox download links delivered through spearphishing.

T1204.001
Malicious Link
GroupAPT28

APT28 has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders.

T1204.001
Malicious Link
GroupAPT-C-36

APT-C-36 has used malicious links in emails, often impersonating official notifications and documents, to direct users to execute malicious payloads.

T1204.001
Malicious Link
GroupEarth Lusca

Earth Lusca has sent spearphishing emails that required the user to click on a malicious link and subsequently open a decoy document with a malicious loader.

T1204.001
Malicious Link
GroupFIN4

FIN4 has lured victims to click malicious links delivered via spearphishing emails (often sent from compromised accounts).

T1204.001
Malicious Link
GroupCobalt Group

Cobalt Group has sent emails containing malicious links that require users to execute a file or macro to infect the victim machine.

T1204.001
Malicious Link
GroupWizard Spider

Wizard Spider has lured victims into clicking a malicious link delivered through spearphishing.

T1204.001
Malicious Link
GroupMolerats

Molerats has sent malicious links via email trick users into opening a RAR archive and running an executable.

T1204.001
Malicious Link
GroupTransparent Tribe

Transparent Tribe has directed users to open URLs hosting malicious content.

T1204.001
Malicious Link
GroupDaggerfly

Daggerfly has used strategic website compromise to deliver a malicious link requiring user interaction.

T1204.001
Malicious Link
GroupWIRTE

WIRTE has used links embedded in emails to lure users into downloading malicious files.

T1204.001
Malicious Link
GroupMagic Hound

Magic Hound has attempted to lure victims into opening malicious links embedded in emails.

T1204.001
Malicious Link
GroupAPT33

APT33 has lured users to click links to malicious HTML applications delivered via spearphishing emails.

T1204.001
Malicious Link
GroupFIN8

FIN8 has used emails with malicious links to lure victims into installing malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.