ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1566.001×

61 examples

TechniqueUsed byProcedure example
T1566.001
Spearphishing Attachment
MalwareTrickBot

TrickBot has used an email with an Excel sheet containing a malicious macro to deploy the malware

T1566.001
Spearphishing Attachment
MalwareBLINDINGCAN

BLINDINGCAN has been delivered by phishing emails containing malicious Microsoft Office documents.

T1566.001
Spearphishing Attachment
MalwareBumblebee

Bumblebee has gained execution through luring users into opening malicious attachments.

T1566.001
Spearphishing Attachment
MalwareKOPILUWAK

KOPILUWAK has been delivered to victims as a malicious email attachment.

T1566.001
Spearphishing Attachment
MalwareThreatNeedle

ThreatNeedle has been distributed via a malicious Word document within a spearphishing email.

T1566.001
Spearphishing Attachment
MalwarePony

Pony has been delivered via spearphishing attachments.

T1566.001
Spearphishing Attachment
MalwareOceanSalt

OceanSalt has been delivered via spearphishing emails with Microsoft Office attachments.

T1566.001
Spearphishing Attachment
MalwareAppleSeed

AppleSeed has been distributed to victims through malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareNETWIRE

NETWIRE has been spread via e-mail campaigns utilizing malicious attachments.

T1566.001
Spearphishing Attachment
MalwareEnvyScout

EnvyScout has been distributed via spearphishing as an email attachment.

T1566.001
Spearphishing Attachment
MalwareEmotet

Emotet has been delivered by phishing emails containing attachments.

T1566.001
Spearphishing Attachment
MalwareWoody RAT

Woody RAT has been delivered via malicious Word documents and archive files.

T1566.001
Spearphishing Attachment
MalwareSquirrelwaffle

Squirrelwaffle has been distributed via malicious Microsoft Office documents within spam emails.

T1566.001
Spearphishing Attachment
MalwareSnip3

Snip3 has been delivered to victims through malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareRifdoor

Rifdoor has been distributed in e-mails with malicious Excel or Word documents.

T1566.001
Spearphishing Attachment
MalwareRustyWater

RustyWater has sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primary payload for the next stage.

T1566.001
Spearphishing Attachment
MalwareIcedID

IcedID has been delivered via phishing e-mails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareFlagpro

Flagpro has been distributed via spearphishing as an email attachment.

T1566.001
Spearphishing Attachment
MalwareDarkTortilla

DarkTortilla has been distributed via spearphishing emails containing archive attachments, with file types such as .iso, .zip, .img, .dmg, and .tar, as well as through malicious documents.

T1566.001
Spearphishing Attachment
MalwareROKRAT

ROKRAT has been delivered via spearphishing emails that contain a malicious Hangul Office or Microsoft Word document.

T1566.001
Spearphishing Attachment
MalwareDarkWatchman

DarkWatchman has been delivered via spearphishing emails that contain a malicious zip file.

T1566.001
Spearphishing Attachment
MalwareJavali

Javali has been delivered as malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareBisonal

Bisonal has been delivered as malicious email attachments.

T1566.001
Spearphishing Attachment
MalwareLumma Stealer

Lumma Stealer has been delivered through phishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareClambling

Clambling has been delivered to victim's machines through malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareDarkGate

DarkGate can be distributed through emails with malicious attachments from a spoofed email address.

T1566.001
Spearphishing Attachment
MalwareSVCReady

SVCReady has been distributed via spearphishing campaigns containing malicious Mircrosoft Word documents.

T1566.001
Spearphishing Attachment
MalwareLatrodectus

Latrodectus has been distributed through reply-chain phishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareSaint Bot

Saint Bot has been distributed as malicious attachments within spearphishing emails.

T1566.001
Spearphishing Attachment
MalwareChaes

Chaes has been delivered by sending victims a phishing email containing a malicious .docx file.

T1566.001
Spearphishing Attachment
MalwareLODEINFO

LODEINFO has been distributed to targeted victims via malicious email attachments.

T1566.001
Spearphishing Attachment
MalwareMetamorfo

Metamorfo has been delivered to victims via emails with malicious HTML attachments.

T1566.001
Spearphishing Attachment
MalwareBandook

Bandook is delivered via a malicious Word document inside a zip file.

T1566.001
Spearphishing Attachment
MalwareKONNI

KONNI has been delivered via spearphishing campaigns through a malicious Word document.

T1566.001
Spearphishing Attachment
MalwareKerrdown

Kerrdown has been distributed through malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareRTM

RTM has been delivered via spearphishing attachments disguised as PDF documents.

T1566.001
Spearphishing Attachment
MalwareStrelaStealer

StrelaStealer has been distributed as a spearphishing attachment.

T1566.001
Spearphishing Attachment
MalwareZxxZ

ZxxZ has been distributed via spearphishing emails, usually containing a malicious RTF or Excel attachment.

T1566.001
Spearphishing Attachment
MalwareXLoader

XLoader has been delivered as a phishing attachment, including PDFs with embedded links, Word and Excel files, and various archive files (ZIP, RAR, ACE, and ISOs) containing EXE payloads.

T1566.001
Spearphishing Attachment
MalwareREvil

REvil has been distributed via malicious e-mail attachments including MS Word Documents.

T1566.001
Spearphishing Attachment
MalwareValak

Valak has been delivered via spearphishing e-mails with password protected ZIP files.

T1566.001
Spearphishing Attachment
MalwareTaidoor

Taidoor has been delivered through spearphishing emails.

T1566.001
Spearphishing Attachment
MalwareDanBot

DanBot has been distributed within a malicious Excel attachment via spearphishing emails.

T1566.001
Spearphishing Attachment
MalwareRamsay

Ramsay has been distributed through spearphishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareOutSteel

OutSteel has been distributed as a malicious attachment within a spearphishing email.

T1566.001
Spearphishing Attachment
MalwareLAMEHUG

LAMEHUG has been distributed through spearphishing emails with various AI-themed malicious attachments.

T1566.001
Spearphishing Attachment
MalwareLokibot

Lokibot is delivered via a malicious XLS attachment contained within a spearhpishing email.

T1566.001
Spearphishing Attachment
MalwarePoetRAT

PoetRAT was distributed via malicious Word documents.

T1566.001
Spearphishing Attachment
MalwareKOCTOPUS

KOCTOPUS has been distributed via spearphishing emails with malicious attachments.

T1566.001
Spearphishing Attachment
MalwareOctopus

Octopus has been delivered via spearsphishing emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.