Real-world descriptions of how a group, tool or campaign used a technique.
98 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1204.002 Malicious File |
MalwareTrickBot | TrickBot has attempted to get users to launch malicious documents to deliver its payload. |
| T1204.002 Malicious File |
MalwareBLINDINGCAN | BLINDINGCAN has lured victims into executing malicious macros embedded within Microsoft Office documents. |
| T1204.002 Malicious File |
MalwareNinja | Ninja has gained execution through victims opening malicious executable files embedded in zip archives. |
| T1204.002 Malicious File |
MalwareBumblebee | Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs. |
| T1204.002 Malicious File |
MalwareKOPILUWAK | KOPILUWAK has gained execution through malicious attachments. |
| T1204.002 Malicious File |
MalwareThreatNeedle | ThreatNeedle relies on a victim to click on a malicious document for initial execution. |
| T1204.002 Malicious File |
MalwareHavoc | Havoc has been executed by victims through the use of targeted lures and crafted decoy documents. |
| T1204.002 Malicious File |
MalwareStrongPity | StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities. |
| T1204.002 Malicious File |
MalwarePony | Pony has attempted to lure targets into downloading an attached executable (ZIP, RAR, or CAB archives) or document (PDF or other MS Office format). |
| T1204.002 Malicious File |
MalwareROAMINGHOUSE | During Operation AkaiRyū, MirrorFace used malicious files to drop ROAMINGHOUSE. |
| T1204.002 Malicious File |
MalwareAppleSeed | AppleSeed can achieve execution through users running malicious file attachments distributed via email. |
| T1204.002 Malicious File |
MalwareNETWIRE | NETWIRE has been executed through luring victims into opening malicious documents. |
| T1204.002 Malicious File |
MalwareBad Rabbit | Bad Rabbit has been executed through user installation of an executable disguised as a flash installer. |
| T1204.002 Malicious File |
MalwareEnvyScout | EnvyScout has been executed through malicious files attached to e-mails. |
| T1204.002 Malicious File |
MalwareSTATICPLUGIN | STATICPLUGIN has required user execution to load subsequent malicious payloads. |
| T1204.002 Malicious File |
MalwareEmotet | Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareWoody RAT | Woody RAT has relied on users opening a malicious email attachment for execution. |
| T1204.002 Malicious File |
MalwareSquirrelwaffle | Squirrelwaffle has relied on users enabling malicious macros within Microsoft Excel and Word attachments. |
| T1204.002 Malicious File |
MalwareSnip3 | Snip3 can gain execution through the download of visual basic files. |
| T1204.002 Malicious File |
MalwareRifdoor | Rifdoor has been executed from malicious Excel or Word documents containing macros. |
| T1204.002 Malicious File |
MalwareGuLoader | The GuLoader executable has been retrieved via embedded macros in malicious Word documents. |
| T1204.002 Malicious File |
MalwareInvisiMole | InvisiMole can deliver trojanized versions of software and documents, relying on user execution. |
| T1204.002 Malicious File |
MalwareCLAIMLOADER | CLAIMLOADER has used tailored decoy documents as part of the installation routine to entice users to open attachments. |
| T1204.002 Malicious File |
MalwareMispadu | Mispadu has relied on users to execute malicious files in order to gain execution on victim machines. |
| T1204.002 Malicious File |
MalwareRustyWater | RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. |
| T1204.002 Malicious File |
MalwareIcedID | IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL. |
| T1204.002 Malicious File |
MalwareFlagpro | Flagpro has relied on users clicking a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareDarkTortilla | DarkTortilla has relied on a user to open a malicious document or archived file delivered via email for initial execution. |
| T1204.002 Malicious File |
MalwareBeaverTail | BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications. |
| T1204.002 Malicious File |
MalwareROKRAT | ROKRAT has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareJavali | Javali has achieved execution through victims opening malicious attachments, including MSI files with embedded VBScript. |
| T1204.002 Malicious File |
MalwarePlugX | PlugX has leveraged an initial executable disguised as a legitimate document to trick the target into opening it. |
| T1204.002 Malicious File |
MalwareBisonal | Bisonal has relied on users to execute malicious file attachments delivered via spearphishing emails. |
| T1204.002 Malicious File |
MalwareLumma Stealer | Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files. |
| T1204.002 Malicious File |
MalwareClambling | Clambling has gained execution through luring victims into opening malicious files. |
| T1204.002 Malicious File |
MalwareDarkGate | DarkGate initial infection payloads can masquerade as pirated media content requiring user interaction for code execution. DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution. |
| T1204.002 Malicious File |
MalwareMongall | Mongall has relied on a user opening a malicious document for execution. |
| T1204.002 Malicious File |
MalwareSVCReady | SVCReady has relied on users clicking a malicious attachment delivered through spearphishing. |
| T1204.002 Malicious File |
MalwareLatrodectus | Latrodectus has lured users into opening malicious email attachments for execution. |
| T1204.002 Malicious File |
MalwareSaint Bot | Saint Bot has relied on users to execute a malicious attachment delivered via spearphishing. |
| T1204.002 Malicious File |
MalwareChaes | Chaes requires the user to click on the malicious Word document to execute the next part of the attack. |
| T1204.002 Malicious File |
MalwareLODEINFO | LODEINFO has been executed via victims opening malicious email attachments. |
| T1204.002 Malicious File |
MalwareTYPEFRAME | A Word document delivering TYPEFRAME prompts the user to enable macro execution. |
| T1204.002 Malicious File |
MalwareBundlore | Bundlore has attempted to get users to execute a malicious .app file that looks like a Flash Player update. |
| T1204.002 Malicious File |
MalwareMetamorfo | Metamorfo requires the user to double-click the executable to run the malicious HTA file or to download a malicious installer. |
| T1204.002 Malicious File |
MalwareBandook | Bandook has used lure documents to convince the user to enable macros. |
| T1204.002 Malicious File |
MalwareKONNI | KONNI has relied on a victim to enable malicious macros within an attachment delivered via email. |
| T1204.002 Malicious File |
MalwareDnsSystem | DnsSystem has lured victims into opening macro-enabled Word documents for execution. |
| T1204.002 Malicious File |
MalwareKGH_SPY | KGH_SPY has been spread through Word documents containing malicious macros. |
| T1204.002 Malicious File |
MalwareKerrdown | Kerrdown has gained execution through victims opening malicious files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.