Malicious File

T1204.002

Sub-technique of T1204 User Execution.View on attack.mitre.org

About this technique

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Adversaries may employ various forms of Masquerading and Obfuscated Files or Information to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it.

While Malicious File frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing.

Detection rules57

Rules on DetectionCode tagged with T1204.002.

Sigma30

RuleLevelLog source
File With Uncommon Extension Created By An Office Applicationhighwindows / file_event
Flash Player Update from Suspicious LocationhighNULL / proxy
GAC DLL Loaded Via Office Applicationshighwindows / image_load
HackTool - LittleCorporal Generated Maldoc Injectionhighwindows / process_access
MMC Executing Files with Reversed Extensions Using RTLO Abusehighwindows / process_creation
Suspicious Binary In User Directory Spawned From Office Applicationhighwindows / process_creation
Suspicious LNK Command-Line Padding with Whitespace Charactershighwindows / process_creation
Suspicious Microsoft Office Child Processhighwindows / process_creation
Suspicious Microsoft Office Child Process - MacOShighmacos / process_creation
Suspicious Outlook Child Processhighwindows / process_creation
Suspicious Startup Folder Persistencehighwindows / file_event
Suspicious WMIC Execution Via Office Processhighwindows / process_creation
Suspicious WmiPrvSE Child Processhighwindows / process_creation
VBA DLL Loaded Via Office Applicationhighwindows / image_load
Active Directory Kerberos DLL Loaded Via Office Applicationmediumwindows / image_load

Splunk27

RuleTypeRiskData source
Batch File Write to System32AnomalyNULLSysmon EventID 11
Cisco NVM - Susp Script From Archive Triggering Network ActivityAnomalyNULLCisco Network Visibility Module Flow Data
Drop IcedID License datHuntingNULLSysmon EventID 11
Linux Ghostscript ExploitationTTPNULLSysmon for Linux EventID 1
O365 SharePoint Malware DetectionTTPNULLOffice 365 Universal Audit Log
O365 Threat Intelligence Suspicious File DetectedTTPNULLOffice 365 Universal Audit Log
Single Letter Process On EndpointTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious Process Executed From Container FileTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Uncommon Processes On EndpointHuntingNULLSysmon EventID 1
Windows Advanced Installer MSIX with AI_STUBS ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows AppX Deployment Full Trust Package InstallationHuntingNULLWindows Event Log AppXDeployment-Server 400
Windows AppX Deployment Package Installation SuccessAnomalyNULLWindows Event Log AppXDeployment-Server 854
Windows AppX Deployment Unsigned Package InstallationTTPNULLWindows Event Log AppXDeployment-Server 855
Windows Binary Execution from an ArchiveAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Windows Default Cobalt Strike PowerShell BeaconTTPNULLPowershell Script Block Logging 4104

Groups86

Show 62 more

Software98

Show 74 more

Campaigns12

Procedure examples196

Groups86

Used byProcedure example
Groupadmin@338

admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails.

GroupAjax Security Team

Ajax Security Team has lured victims into executing malicious files.

GroupAndariel

Andariel has attempted to lure victims into enabling malicious macros within email attachments.

GroupAoqin Dragon

Aoqin Dragon has lured victims into opening weaponized documents, fake external drives, and fake antivirus to execute malicious payloads.

GroupAPT-C-36

APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware.

GroupAPT12

APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing.

GroupAPT19

APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails.

GroupAPT28

APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts.

View all 86 groups examples

Software98

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has been executed through malicious e-mail attachments

MalwareAppleJeus

AppleJeus has required user execution of a malicious MSI installer.

MalwareAppleSeed

AppleSeed can achieve execution through users running malicious file attachments distributed via email.

MalwareAshTag

AshTag has been executed through victims downloading and opening malicious RAR archive files.

MalwareAstaroth

Astaroth has used malicious files including VBS, LNK, and HTML for execution.

ToolAsyncRAT

AsyncRAT has been executed through victims opening malicious file attachments.

MalwareBad Rabbit

Bad Rabbit has been executed through user installation of an executable disguised as a flash installer.

MalwareBADFLICK

BADFLICK has relied upon users clicking on a malicious attachment delivered through spearphishing.

View all 98 software examples

Campaigns12

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them.

CampaignC0011

During C0011, Transparent Tribe relied on a student target to open a malicious document delivered via email.

CampaignC0015

During C0015, the threat actors relied on users to enable macros within a malicious Microsoft Word document.

CampaignFrankenstein

During Frankenstein, the threat actors relied on a victim to enable macros within a malicious Microsoft Word document likely sent via email.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace lured victims into executing malicious payloads by opening email attachments.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors.

CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors relied on potential victims to open a malicious Microsoft Word document sent via email.

CampaignOperation Honeybee

During Operation Honeybee, threat actors relied on a victim to enable macros within a malicious Word document.

View all 12 campaigns examples

References2

  1. Mandiant Trojanized Windows 10 Open source
    Mandiant Intelligence. (2022, December 15). Trojanized Windows 10 Operating System Installers Targeted Ukrainian Government. Retrieved September 26, 2025.
  2. Password Protected Word Docs Open source
    Lawrence Abrams. (2017, July 12). PSA: Don't Open SPAM Containing Password Protected Word Docs. Retrieved January 5, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.