Malicious Link

T1204.001

Sub-technique of T1204 User Execution.View on attack.mitre.org

About this technique

An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Link. Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via Exploitation for Client Execution. Links may also lead users to download files that require execution via Malicious File.

Detection rules6

Rules on DetectionCode tagged with T1204.001.

Sigma4

RuleLevelLog source
Potential ClickFix Execution Pattern - Registryhighwindows / registry_set
Suspicious ClickFix/FileFix Execution Patternhighwindows / process_creation
Symlink Etc Passwdhighlinux / NULL
Suspicious Execution via macOS Script Editormediummacos / process_creation

Splunk2

RuleTypeRiskData source
Windows ISO LNK File CreationHuntingNULLSysmon EventID 11
Windows PowerShell FakeCAPTCHA Clipboard ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data

Groups49

Show 25 more

Software30

Show 6 more

Campaigns9

Procedure examples88

Groups49

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used malicious links in emails, often impersonating official notifications and documents, to direct users to execute malicious payloads.

GroupAPT28

APT28 has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders.

GroupAPT29

APT29 has used various forms of spearphishing attempting to get a user to click on a malicious link.

GroupAPT3

APT3 has lured victims into clicking malicious links delivered through spearphishing.

GroupAPT32

APT32 has lured targets to download a Cobalt Strike beacon by including a malicious link within spearphishing emails.

GroupAPT33

APT33 has lured users to click links to malicious HTML applications delivered via spearphishing emails.

GroupAPT38

APT38 has used links to execute a malicious Visual Basic script.

GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link.

View all 49 groups examples

Software30

Used byProcedure example
MalwareAppleJeus

AppleJeus's spearphishing links required user interaction to navigate to the malicious website.

MalwareBackConfig

BackConfig has compromised victims via links to URLs hosting malicious content.

MalwareBazar

Bazar can gain execution after a user clicks on a malicious link to decoy landing pages hosted on Google Docs.

MalwareBumblebee

Bumblebee has relied upon a user downloading a file from a OneDrive link for execution.

MalwareEmotet

Emotet has relied upon users clicking on a malicious link delivered through spearphishing.

MalwareGootloader

Gootloader has been executed through malicious links presented to users as internet search results.

MalwareGrandoreiro

Grandoreiro has used malicious links to gain execution on victim machines.

MalwareGuLoader

GuLoader has relied upon users clicking on links to malicious documents.

View all 30 software examples

Campaigns9

Used byProcedure example
CampaignC0011

During C0011, Transparent Tribe relied on student targets to click on a malicious link sent via email.

CampaignC0021

During C0021, the threat actors lured users into clicking a malicious link which led to the download of a ZIP archive containing a malicious .LNK file.

CampaignNight Dragon

During Night Dragon, threat actors enticed users to click on links in spearphishing emails to download malware.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace lured users into executing malicious payloads with links to resources hosted on OneDrive.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access.

CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors relied on a victim clicking on a malicious link sent via email.

CampaignOperation Spalax

During Operation Spalax, the threat actors relied on a victim to click on a malicious link distributed via phishing emails.

CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda distributed hyperlinks that would result in an MSC file running a PowerShell command to download and install a remotely-hosted MSI file during RedDelta Modified PlugX Infection Chain Operations.

View all 9 campaigns examples

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.