MITRE ATT&CK technique
T1203 — Exploitation for Client Execution
Last fetched
T1203 (Exploitation for Client Execution) is a MITRE ATT&CK technique tracked in WhisperGraph, serving the Execution tactic.
Description
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility. Several types exist: ### Browser-based Exploitation Web browsers are a common target through [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) and [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002). Endpoint systems may be compromised through normal web browsing or from certain users being targeted by links in spearphishing emails to adversary controlled sites used to exploit the web browser. These often do not require an action by the user for the exploit to be executed. ### Office Applications Common office and productivity applications such as Microsoft Office are also targeted through [Phishing](https://attack.mitre.org/techniques/T1566). Malicious files will be transmitted directly as attachments or through links to download them. These require the user to open the document or file for the exploit to run. ### Common Third-party Applications Other applications that are commonly seen or are part of the software deployed in a target network may also be used for exploitation. Applications such as Adobe Reader and Flash, which are common in enterprise environments, have been routinely targeted by adversaries attempting to gain access to systems. Depending on the software and nature of the vulnerability, some may be exploited in the browser or require the user to open a file. For instance, some Flash exploits have been delivered as objects within Microsoft Office documents.
Tactics
Threat actors observed using this technique
- APT41
- TA459
- ShinyHunters
- Elderwood
- EXOTIC LILY
- BRONZE BUTLER
- Transparent Tribe
- Inception
- Threat Group-3390
- UNC3886
- APT3
- Cobalt Group
- Higaisa
- Mustang Panda
- Ember Bear
- Axiom
- BITTER
- Confucius
- BlackTech
- Dragonfly
- Aoqin Dragon
- Lazarus Group
- Saint Bear
- Tonto Team
- Patchwork
- Darkhotel
- admin@338
- APT12
- Sidewinder
- Andariel
- Sea Turtle
- Leviathan
- Tropic Trooper
- OilRig
- APT28
- APT29
- APT32
- APT33
- Sandworm Team
- APT37
- MuddyWater
- The White Company
- MUSTANG PANDA
- DarkHotel
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from T1203 into its tactic, related techniques and the actors that use it.
Queries
Resolves the segment to this technique or tactic.
MATCH (t:ATTACK_PATTERN {name: $id})
RETURN t.id AS id, t.name AS name, t.kind AS kind, t.description AS descriptionRun yourself →The tactic(s) this technique serves.
MATCH (t:ATTACK_PATTERN {name: $id})-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN tac.id AS id, tac.name AS name
LIMIT 10Run yourself →This id's parent technique, if it is a sub-technique.
MATCH (p:ATTACK_PATTERN {name: $parentId})
RETURN p.id AS id, p.name AS name
LIMIT 1Run yourself →Sub-techniques of this technique, if any.
MATCH (c:ATTACK_PATTERN) WHERE c.id STARTS WITH $subPrefix
RETURN c.id AS id, c.name AS name
ORDER BY c.id
LIMIT 25Run yourself →Threat actors observed using this technique.
MATCH (a:ACTOR)-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN {name: $id})
RETURN a.name AS name
LIMIT 100Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.