Real-world descriptions of how a group, tool or campaign used a technique.
49 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.001 Malicious Link |
GroupAPT38 | APT38 has used links to execute a malicious Visual Basic script. |
| T1204.001 Malicious Link |
GroupElderwood | Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open links. |
| T1204.001 Malicious Link |
GroupAPT3 | APT3 has lured victims into clicking malicious links delivered through spearphishing. |
| T1204.001 Malicious Link |
GroupMustard Tempest | Mustard Tempest has lured users into downloading malware through malicious links in fake advertisements and spearphishing emails. |
| T1204.001 Malicious Link |
GroupKimsuky | Kimsuky has lured victims into clicking malicious links. |
| T1204.001 Malicious Link |
GroupEXOTIC LILY | EXOTIC LILY has used malicious links to lure users into executing malicious payloads. |
| T1204.001 Malicious Link |
GroupTA577 | TA577 has lured users into executing malicious JavaScript files by sending malicious links via email. |
| T1204.001 Malicious Link |
GroupPatchwork | Patchwork has used spearphishing with links to try to get users to click, download and open malicious files. |
| T1204.001 Malicious Link |
GroupEvilnum | Evilnum has sent spearphishing emails designed to trick the recipient into opening malicious shortcut links which downloads a .LNK file. |
| T1204.001 Malicious Link |
GroupAPT32 | APT32 has lured targets to download a Cobalt Strike beacon by including a malicious link within spearphishing emails. |
| T1204.001 Malicious Link |
GroupMuddyWater | MuddyWater has distributed URLs in phishing e-mails that link to lure documents. |
| T1204.001 Malicious Link |
GroupGamaredon Group | Gamaredon Group has attempted to get users to click on a link pointing to a malicious HTML file leading to follow-on malicious content. |
| T1204.001 Malicious Link |
GroupFIN7 | FIN7 has used malicious links to lure victims into downloading malware. |
| T1204.001 Malicious Link |
GroupSandworm Team | Sandworm Team has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders. |
| T1204.001 Malicious Link |
GroupMachete | Machete has has relied on users opening malicious links delivered through spearphishing to execute malware. |
| T1204.001 Malicious Link |
GroupSidewinder | Sidewinder has lured targets to click on malicious links to gain execution in the target environment. |
| T1204.001 Malicious Link |
GroupMustang Panda | Mustang Panda has sent malicious links including links directing victims to a Google Drive folder. Mustang Panda has also utilized webpages with Javascript code that downloads malicious payloads to the victim device. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACrowdstrike MUSTANG PANDA June 2018Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025McAfee Dianxun March 2021Proofpoint TA416 Europe March 2022 |
| T1204.001 Malicious Link |
GroupZIRCONIUM | ZIRCONIUM has used malicious links in e-mails to lure victims into downloading malware. |
| T1204.001 Malicious Link |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link. |
| T1204.001 Malicious Link |
GroupContagious Interview | Contagious Interview has lured victims to click on a malicious link that led to download of a malicious payload. Contagious Interview has also leveraged links to malicious payloads on social media and code repositories. |
| T1204.001 Malicious Link |
GroupTA2541 | TA2541 has used malicious links to cloud and web services to gain execution on victim machines. |
| T1204.001 Malicious Link |
GroupOilRig | OilRig has delivered malicious links to achieve execution on the target system. |
| T1204.001 Malicious Link |
GroupSaint Bear | Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution. |
| T1204.001 Malicious Link |
GroupConfucius | Confucius has lured victims into clicking on a malicious link sent through spearphishing. |
| T1204.001 Malicious Link |
GroupBlackTech | BlackTech has used e-mails with malicious links to lure victims into installing malware. |
| T1204.001 Malicious Link |
GroupLeviathan | Leviathan has sent spearphishing email links attempting to get a user to click. |
| T1204.001 Malicious Link |
GroupWinter Vivern | Winter Vivern has mimicked legitimate government-related domains to deliver malicious webpages containing links to documents or other content for user execution. |
| T1204.001 Malicious Link |
GroupTurla | Turla has used spearphishing via a link to get users to download and run their malware. |
| T1204.001 Malicious Link |
GroupTA505 | TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1204.001 Malicious Link |
GroupRedCurl | RedCurl has used malicious links to infect the victim machines. |
| T1204.001 Malicious Link |
GroupMofang | Mofang's spearphishing emails required a user to click the link to connect to a compromised website. |
| T1204.001 Malicious Link |
GroupAPT29 | APT29 has used various forms of spearphishing attempting to get a user to click on a malicious link. |
| T1204.001 Malicious Link |
GroupTA578 | TA578 has placed malicious links in contact forms on victim sites, often spoofing a copyright complaint, to redirect users to malicious file downloads. |
| T1204.001 Malicious Link |
GroupLazyScripter | LazyScripter has relied upon users clicking on links to malicious files. |
| T1204.001 Malicious Link |
GroupWindshift | Windshift has used links embedded in e-mails to lure victims into executing malicious code. |
| T1204.001 Malicious Link |
GroupLuminousMoth | LuminousMoth has lured victims into clicking malicious Dropbox download links delivered through spearphishing. |
| T1204.001 Malicious Link |
GroupAPT28 | APT28 has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders. |
| T1204.001 Malicious Link |
GroupAPT-C-36 | APT-C-36 has used malicious links in emails, often impersonating official notifications and documents, to direct users to execute malicious payloads. |
| T1204.001 Malicious Link |
GroupEarth Lusca | Earth Lusca has sent spearphishing emails that required the user to click on a malicious link and subsequently open a decoy document with a malicious loader. |
| T1204.001 Malicious Link |
GroupFIN4 | FIN4 has lured victims to click malicious links delivered via spearphishing emails (often sent from compromised accounts). |
| T1204.001 Malicious Link |
GroupCobalt Group | Cobalt Group has sent emails containing malicious links that require users to execute a file or macro to infect the victim machine. |
| T1204.001 Malicious Link |
GroupWizard Spider | Wizard Spider has lured victims into clicking a malicious link delivered through spearphishing. |
| T1204.001 Malicious Link |
GroupMolerats | Molerats has sent malicious links via email trick users into opening a RAR archive and running an executable. |
| T1204.001 Malicious Link |
GroupTransparent Tribe | Transparent Tribe has directed users to open URLs hosting malicious content. |
| T1204.001 Malicious Link |
GroupDaggerfly | Daggerfly has used strategic website compromise to deliver a malicious link requiring user interaction. |
| T1204.001 Malicious Link |
GroupWIRTE | WIRTE has used links embedded in emails to lure users into downloading malicious files. |
| T1204.001 Malicious Link |
GroupMagic Hound | Magic Hound has attempted to lure victims into opening malicious links embedded in emails. |
| T1204.001 Malicious Link |
GroupAPT33 | APT33 has lured users to click links to malicious HTML applications delivered via spearphishing emails. |
| T1204.001 Malicious Link |
GroupFIN8 | FIN8 has used emails with malicious links to lure victims into installing malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.