Sub-technique of T1204 User Execution.View on attack.mitre.org
An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Link. Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via Exploitation for Client Execution. Links may also lead users to download files that require execution via Malicious File.
Rules on DetectionCode tagged with T1204.001.
| Rule | Level | Log source |
|---|---|---|
| Potential ClickFix Execution Pattern - Registry | high | windows / registry_set |
| Suspicious ClickFix/FileFix Execution Pattern | high | windows / process_creation |
| Symlink Etc Passwd | high | linux / NULL |
| Suspicious Execution via macOS Script Editor | medium | macos / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows ISO LNK File Creation | Hunting | NULL | Sysmon EventID 11 |
| Windows PowerShell FakeCAPTCHA Clipboard Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has used malicious links in emails, often impersonating official notifications and documents, to direct users to execute malicious payloads. |
| GroupAPT28 | APT28 has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders. |
| GroupAPT29 | APT29 has used various forms of spearphishing attempting to get a user to click on a malicious link. |
| GroupAPT3 | APT3 has lured victims into clicking malicious links delivered through spearphishing. |
| GroupAPT32 | APT32 has lured targets to download a Cobalt Strike beacon by including a malicious link within spearphishing emails. |
| GroupAPT33 | APT33 has lured users to click links to malicious HTML applications delivered via spearphishing emails. |
| GroupAPT38 | APT38 has used links to execute a malicious Visual Basic script. |
| GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link. |
| Used by | Procedure example |
|---|---|
| MalwareAppleJeus | AppleJeus's spearphishing links required user interaction to navigate to the malicious website. |
| MalwareBackConfig | BackConfig has compromised victims via links to URLs hosting malicious content. |
| MalwareBazar | Bazar can gain execution after a user clicks on a malicious link to decoy landing pages hosted on Google Docs. |
| MalwareBumblebee | Bumblebee has relied upon a user downloading a file from a OneDrive link for execution. |
| MalwareEmotet | Emotet has relied upon users clicking on a malicious link delivered through spearphishing. |
| MalwareGootloader | Gootloader has been executed through malicious links presented to users as internet search results. |
| MalwareGrandoreiro | Grandoreiro has used malicious links to gain execution on victim machines. |
| MalwareGuLoader | GuLoader has relied upon users clicking on links to malicious documents. |
| Used by | Procedure example |
|---|---|
| CampaignC0011 | During C0011, Transparent Tribe relied on student targets to click on a malicious link sent via email. |
| CampaignC0021 | During C0021, the threat actors lured users into clicking a malicious link which led to the download of a ZIP archive containing a malicious .LNK file. |
| CampaignNight Dragon | During Night Dragon, threat actors enticed users to click on links in spearphishing emails to download malware. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace lured users into executing malicious payloads with links to resources hosted on OneDrive. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access. |
| CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors relied on a victim clicking on a malicious link sent via email. |
| CampaignOperation Spalax | During Operation Spalax, the threat actors relied on a victim to click on a malicious link distributed via phishing emails. |
| CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda distributed hyperlinks that would result in an MSC file running a PowerShell command to download and install a remotely-hosted MSI file during RedDelta Modified PlugX Infection Chain Operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.