Exploitation for Client Execution

T1203

Technique.View on attack.mitre.org

About this technique

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

Several types exist:

### Browser-based Exploitation

Web browsers are a common target through Drive-by Compromise and Spearphishing Link. Endpoint systems may be compromised through normal web browsing or from certain users being targeted by links in spearphishing emails to adversary controlled sites used to exploit the web browser. These often do not require an action by the user for the exploit to be executed.

### Office Applications

Common office and productivity applications such as Microsoft Office are also targeted through Phishing. Malicious files will be transmitted directly as attachments or through links to download them. These require the user to open the document or file for the exploit to run.

### Common Third-party Applications

Other applications that are commonly seen or are part of the software deployed in a target network may also be used for exploitation. Applications such as Adobe Reader and Flash, which are common in enterprise environments, have been routinely targeted by adversaries attempting to gain access to systems. Depending on the software and nature of the vulnerability, some may be exploited in the browser or require the user to open a file. For instance, some Flash exploits have been delivered as objects within Microsoft Office documents.

Detection rules32

Rules on DetectionCode tagged with T1203.

Sigma20

RuleLevelLog source
Antivirus - APT Malware SignaturecriticalNULL / antivirus
Antivirus - Exploitation Framework SignaturecriticalNULL / antivirus
Antivirus - Remote Access Tools SignaturecriticalNULL / antivirus
Audit CVE Eventcriticalwindows / NULL
Network Connection Initiated By Eqnedt32.EXEhighwindows / network_connection
OMIGOD HTTP No Authentication RCEhighzeek / NULL
OMIGOD SCX RunAsProvider ExecuteScripthighlinux / process_creation
OMIGOD SCX RunAsProvider ExecuteShellCommandhighlinux / process_creation
Suspicious ArcSOC.exe Child Processhighwindows / process_creation
Suspicious Download and Execute Pattern via Curl/Wgethighlinux / process_creation
Suspicious HWP Sub Processeshighwindows / process_creation
Suspicious Invocation of Shell via Rsynchighlinux / process_creation
Suspicious Spool Service Child Processhighwindows / process_creation
Java Running with Remote Debuggingmediumwindows / process_creation
Office Application Initiated Network Connection To Non-Local IPmediumwindows / network_connection

Splunk12

RuleTypeRiskData source
Cisco Secure Firewall - Binary File Type DownloadAnomalyNULLCisco Secure Firewall Threat Defense File Event
Cisco Secure Firewall - Blocked ConnectionAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - Citrix NetScaler Memory Overread AttemptTTPNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - High Priority Intrusion ClassificationTTPNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - Malware File DownloadedAnomalyNULLCisco Secure Firewall Threat Defense File Event
Cisco Secure Firewall - Possibly Compromised HostAnomalyNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - Repeated Blocked ConnectionsAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Detect Windows DNS SIGRed via Splunk StreamTTPNULL
Detect Windows DNS SIGRed via ZeekTTPNULL
Sunburst Correlation DLL and Network EventTTPNULLSysmon EventID 7, Sysmon EventID 22
Windows MSC EvilTwin Directory Path ManipulationTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Remote Image LoadAnomalyNULLSysmon EventID 7

Groups42

Show 18 more

Software14

Campaigns5

Procedure examples61

Groups42

Used byProcedure example
Groupadmin@338

admin@338 has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158.

GroupAndariel

Andariel has exploited numerous ActiveX vulnerabilities, including zero-days.

GroupAoqin Dragon

Aoqin Dragon has exploited CVE-2012-0158 and CVE-2010-3333 for execution against targeted systems.

GroupAPT12

APT12 has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities (CVE-2009-3129, CVE-2012-0158) and vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611).

GroupAPT28

APT28 has exploited Microsoft Office vulnerability CVE-2017-0262 for execution.

GroupAPT29

APT29 has used multiple software exploits for common client software, like Microsoft Word, Exchange, and Adobe Reader, to gain code execution.

GroupAPT3

APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113 and Internet Explorer vulnerability CVE-2014-1776.

GroupAPT32

APT32 has used RTF document that includes an exploit to execute malicious code. (CVE-2017-11882)

View all 42 groups examples

Software14

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery.

MalwareBankshot

Bankshot leverages a known zero-day vulnerability in Adobe Flash to execute the implant into the victims’ machines.

MalwareCobalt Strike

Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460.

MalwareDealersChoice

DealersChoice leverages vulnerable versions of Flash to perform execution.

MalwareEvilBunny

EvilBunny has exploited CVE-2011-4369, a vulnerability in the PRC component in Adobe Reader.

MalwareHAWKBALL

HAWKBALL has exploited Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2018-0802 to deliver the payload.

MalwareInvisiMole

InvisiMole has installed legitimate but vulnerable Total Video Player software and wdigest.dll library drivers on compromised hosts to exploit stack overflow and input validation vulnerabilities for code execution.

MalwareRamsay

Ramsay has been embedded in documents exploiting CVE-2017-0199, CVE-2017-11882, and CVE-2017-8570.

View all 14 software examples

Campaigns5

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website.

CampaignFrankenstein

During Frankenstein, the threat actors exploited CVE-2017-11882 to execute code on the victim's machine.

CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors exploited Adobe Flash vulnerability CVE-2011-0611, Microsoft Windows Help vulnerability CVE-2010-1885, and several Internet Explorer vulnerabilities, including CVE-2011-1255, CVE-2012-1889, and CVE-2014-0322.

CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used the GrimResource exploitation technique via specially crafted MSC files for arbitrary code execution during RedDelta Modified PlugX Infection Chain Operations.

CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.