Sub-technique of T1566 Phishing.View on attack.mitre.org
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
There are many options for the attachment such as Microsoft Office documents, executables, PDFs, or archived files. Upon opening the attachment (and potentially clicking past protections), the adversary's payload exploits a vulnerability or directly executes on the user's system. The text of the spearphishing email usually tries to give a plausible reason why the file should be opened, and may explain how to bypass system protections in order to do so. The email may also contain instructions on how to decrypt an attachment, such as a zip file password, in order to evade email boundary defenses. Adversaries frequently manipulate file extensions and icons in order to make attached executables appear to be document files, or files exploiting one application appear to be a file for a different one.
Rules on DetectionCode tagged with T1566.001.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect Outlook exe writing a zip file | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 11 |
| Email Attachments With Lots Of Spaces | Anomaly | NULL | |
| GSuite Email Suspicious Attachment | Anomaly | NULL | G Suite Gmail |
| Gsuite Email Suspicious Subject With Attachment | Anomaly | NULL | G Suite Gmail |
| Gsuite Email With Known Abuse Web Service Link | Anomaly | NULL | G Suite Gmail |
| Gsuite Suspicious Shared File Name | Anomaly | NULL | G Suite Drive |
| MSHTML Module Load in Office Product | TTP | NULL | Sysmon EventID 7 |
| O365 Email Reported By Admin Found Malicious | TTP | NULL | Office 365 Universal Audit Log |
| O365 Email Reported By User Found Malicious | TTP | NULL | Office 365 Universal Audit Log |
| O365 Safe Links Detection | TTP | NULL | Office 365 Universal Audit Log |
| O365 Threat Intelligence Suspicious Email Delivered | Anomaly | NULL | Office 365 Universal Audit Log |
| O365 ZAP Activity Detection | Anomaly | NULL | Office 365 Universal Audit Log |
| Office Application Drop Executable | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 11 |
| Office Application Spawn Regsvr32 process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Office Application Spawn rundll32 process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Office Document Creating Schedule Task | TTP | NULL | Sysmon EventID 7 |
| Office Document Executing Macro Code | TTP | NULL | Sysmon EventID 7 |
| Office Document Spawned Child Process To Download | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Office Product Spawn CMD Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Office Product Spawning BITSAdmin | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Office Product Spawning CertUtil | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Office Product Spawning MSHTA | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Office Product Spawning Rundll32 with no DLL | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Office Product Spawning Windows Script Host | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Office Product Spawning Wmic | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Office Product Writing cab or inf | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Sysmon EventID 11 |
| Office Spawning Control | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious Email Attachment Extensions | Anomaly | NULL | |
| Windows CAB File on Disk | Anomaly | NULL | Sysmon EventID 11 |
| Windows Defender ASR Audit Events | Anomaly | NULL | Windows Event Log Defender 1122, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1132, Windows Event Log Defender 1134 |
| Windows Defender ASR Block Events | Anomaly | NULL | Windows Event Log Defender 1121, Windows Event Log Defender 1126, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1133 |
| Windows Defender ASR Rules Stacking | Hunting | NULL | Windows Event Log Defender 1121, Windows Event Log Defender 1122, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1133, Windows Event Log Defender 1134, Windows Event Log Defender 5007 |
| Windows ISO LNK File Creation | Hunting | NULL | Sysmon EventID 11 |
| Windows Office Product Dropped Cab or Inf File | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 11, Windows Event Log Security 4688 AND Sysmon EventID 11 |
| Windows Office Product Dropped Uncommon File | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 11 |
| Windows Office Product Loaded MSHTML Module | Anomaly | NULL | Sysmon EventID 7 |
| Windows Office Product Loading Taskschd DLL | Anomaly | NULL | Sysmon EventID 7 |
| Windows Office Product Loading VBE7 DLL | Anomaly | NULL | Sysmon EventID 7 |
| Windows Office Product Spawned Child Process For Download | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Office Product Spawned Control | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Office Product Spawned MSDT | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Office Product Spawned Rundll32 With No DLL | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Office Product Spawned Uncommon Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Office Product Spawning MSDT | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Phishing PDF File Executes URL Link | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Phishing Recent ISO Exec Registry | Hunting | NULL | Sysmon EventID 13 |
| Windows Spearphishing Attachment Connect To None MS Office Domain | Hunting | NULL | Sysmon EventID 22 |
| Windows Spearphishing Attachment Onenote Spawn Mshta | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Universal Data Link File Creation | Anomaly | NULL | Sysmon EventID 11 |
| Winword Spawning Cmd | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Winword Spawning PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Winword Spawning Windows Script Host | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| Groupadmin@338 | admin@338 has sent emails with malicious Microsoft Office documents attached. |
| GroupAjax Security Team | Ajax Security Team has used personalized spearphishing attachments. |
| GroupAndariel | Andariel has conducted spearphishing campaigns that included malicious Word or Excel attachments. |
| GroupAPT-C-36 | APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway. |
| GroupAPT1 | APT1 has sent spearphishing emails containing malicious attachments. |
| GroupAPT12 | APT12 has sent emails with malicious Microsoft Office documents and PDFs attached. |
| GroupAPT19 | APT19 sent spearphishing emails with malicious attachments in RTF and XLSM formats to deliver initial exploits. |
| GroupAPT28 | APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments. |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | The primary delivered mechanism for Agent Tesla is through email phishing messages. |
| MalwareAppleSeed | AppleSeed has been distributed to victims through malicious e-mail attachments. |
| MalwareAstaroth | Astaroth has been delivered via malicious e-mail attachments. |
| ToolAsyncRAT | AsyncRAT has been delivered via malicious email attachments. |
| MalwareBADFLICK | BADFLICK has been distributed via spearphishing campaigns containing malicious Microsoft Word documents. |
| MalwareBandook | Bandook is delivered via a malicious Word document inside a zip file. |
| MalwareBisonal | Bisonal has been delivered as malicious email attachments. |
| MalwareBLINDINGCAN | BLINDINGCAN has been delivered by phishing emails containing malicious Microsoft Office documents. |
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team obtained their initial foothold into many IT systems using Microsoft Office attachments delivered through phishing emails. |
| CampaignC0011 | During C0011, Transparent Tribe sent malicious attachments via email to student targets in India. |
| CampaignC0015 | For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims. |
| CampaignFrankenstein | During Frankenstein, the threat actors likely used spearphishing emails to send malicious Microsoft Word documents. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers. |
| CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document. |
| CampaignOperation Spalax | During Operation Spalax, the threat actors sent phishing emails that included a PDF document that in some cases led to the download and execution of malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.