ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1204.002×

86 examples

TechniqueUsed byProcedure example
T1204.002
Malicious File
GroupAPT38

APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files.

T1204.002
Malicious File
GroupIndrik Spider

Indrik Spider has attempted to get users to click on a malicious zipped file.

T1204.002
Malicious File
GroupElderwood

Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open attachments.

T1204.002
Malicious File
GroupSideCopy

SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns.

T1204.002
Malicious File
GroupKimsuky

Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background.

T1204.002
Malicious File
GroupEXOTIC LILY

EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO.

T1204.002
Malicious File
Groupadmin@338

admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupPatchwork

Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware.

T1204.002
Malicious File
GroupDragonfly

Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments.

T1204.002
Malicious File
GroupGorgon Group

Gorgon Group attempted to get users to launch malicious Microsoft Office attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupmenuPass

menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns.

T1204.002
Malicious File
GroupAPT32

APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment.

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1204.002
Malicious File
GroupNaikon

Naikon has convinced victims to open malicious attachments to execute malware.

T1204.002
Malicious File
GroupFIN6

FIN6 has used malicious documents to lure victims into allowing execution of PowerShell scripts.

T1204.002
Malicious File
GroupGamaredon Group

Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files.

T1204.002
Malicious File
GroupGallmaker

Gallmaker sent victims a lure document with a warning that asked victims to “enable content” for execution.

T1204.002
Malicious File
GroupStorm-1811

Storm-1811 has prompted users to execute downloaded software and payloads as the result of social engineering activity.

T1204.002
Malicious File
GroupFIN7

FIN7 lured victims to double-click on images in the attachments they sent which would then execute the hidden LNK file. Additionally, FIN7 has used malicious Microsoft Word and Excel files and Leo VBS to distribute an updated version of JSS Loader and to distribute the Harpy backdoor.

T1204.002
Malicious File
GroupSandworm Team

Sandworm Team has tricked unwitting recipients into clicking on spearphishing attachments and enabling malicious macros embedded within files.

T1204.002
Malicious File
GroupMachete

Machete has relied on users opening malicious attachments delivered through spearphishing to execute malware.

T1204.002
Malicious File
GroupAndariel

Andariel has attempted to lure victims into enabling malicious macros within email attachments.

T1204.002
Malicious File
GroupCURIUM

CURIUM has lured users into opening malicious files delivered via social media.

T1204.002
Malicious File
GroupSidewinder

Sidewinder has lured targets to click on malicious files to gain execution in the target environment.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1204.002
Malicious File
GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment.

T1204.002
Malicious File
GroupContagious Interview

Contagious Interview has distributed malicious files requiring direct victim interaction to execute through the guise of a code test.

T1204.002
Malicious File
GroupTA2541

TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads.

T1204.002
Malicious File
GroupAPT37

APT37 has sent spearphishing attachments attempting to get a user to open them.

T1204.002
Malicious File
GroupOilRig

OilRig has delivered macro-enabled documents that required targets to click the "enable content" button to execute the payload on the system.

T1204.002
Malicious File
GroupHigaisa

Higaisa used malicious e-mail attachments to lure victims into executing LNK files.

T1204.002
Malicious File
GroupTropic Trooper

Tropic Trooper has lured victims into executing malware via malicious e-mail attachments.

T1204.002
Malicious File
GroupTA459

TA459 has attempted to get victims to open malicious Microsoft Word attachment sent via spearphishing.

T1204.002
Malicious File
GroupAoqin Dragon

Aoqin Dragon has lured victims into opening weaponized documents, fake external drives, and fake antivirus to execute malicious payloads.

T1204.002
Malicious File
GroupFerocious Kitten

Ferocious Kitten has attempted to convince victims to enable malicious content within a spearphishing email by including an odd decoy message.

T1204.002
Malicious File
GroupThe White Company

The White Company has used phishing lure documents that trick users into opening them and infecting their computers.

T1204.002
Malicious File
GroupSaint Bear

Saint Bear relies on user interaction and execution of malicious attachments and similar for initial execution on victim systems.

T1204.002
Malicious File
GroupDarkHydrus

DarkHydrus has sent malware that required users to hit the enable button in Microsoft Excel to allow an .iqy file to be downloaded.

T1204.002
Malicious File
GroupConfucius

Confucius has lured victims to execute malicious attachments included in crafted spearphishing emails related to current topics.

T1204.002
Malicious File
GroupBlackTech

BlackTech has used e-mails with malicious documents to lure victims into installing malware.

T1204.002
Malicious File
GroupLeviathan

Leviathan has sent spearphishing attachments attempting to get a user to click.

T1204.002
Malicious File
GroupTA505

TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1204.002
Malicious File
GroupBITTER

BITTER has attempted to lure victims into opening malicious attachments delivered via spearphishing.

T1204.002
Malicious File
GroupRedCurl

RedCurl has used malicious files to infect the victim machines.

T1204.002
Malicious File
GroupMofang

Mofang's malicious spearphishing attachments required a user to open the file after receiving.

T1204.002
Malicious File
GroupAPT29

APT29 has used various forms of spearphishing attempting to get a user to open attachments, including, but not limited to, malicious Microsoft Word documents, .pdf, and .lnk files.

T1204.002
Malicious File
GroupDark Caracal

Dark Caracal makes their malware look like Flash Player, Office, or PDF documents in order to entice a user to click on it.

T1204.002
Malicious File
GroupMirrorFace

MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution.

T1204.002
Malicious File
GroupBRONZE BUTLER

BRONZE BUTLER has attempted to get users to launch malicious Microsoft Word attachments delivered via spearphishing emails.

T1204.002
Malicious File
GroupTA551

TA551 has prompted users to enable macros within spearphishing attachments to install malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.