MITRE ATT&CK sub-technique
T1204.002 — Malicious File
Last fetched
T1204.002 (Malicious File) is a MITRE ATT&CK sub-technique tracked in WhisperGraph, serving the Execution tactic.
Description
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001). Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.(Citation: Mandiant Trojanized Windows 10) Adversaries may employ various forms of [Masquerading](https://attack.mitre.org/techniques/T1036) and [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it.(Citation: Password Protected Word Docs) While [Malicious File](https://attack.mitre.org/techniques/T1204/002) frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after [Internal Spearphishing](https://attack.mitre.org/techniques/T1534).
Tactics
Related techniques
Parent technique: T1204 · User Execution
Threat actors observed using this technique
- Aoqin Dragon
- Dragonfly
- Naikon
- BlackTech
- Confucius
- BITTER
- DarkHydrus
- RTM
- Mustang Panda
- Whitefly
- Indrik Spider
- TA505
- Contagious Interview
- Higaisa
- Mofang
- APT-C-36
- Earth Lusca
- Cobalt Group
- Threat Group-3390
- Nomadic Octopus
- HEXANE
- Gamaredon Group
- Inception
- Transparent Tribe
- Malteiro
- BRONZE BUTLER
- MirrorFace
- EXOTIC LILY
- Elderwood
- menuPass
- Gallmaker
- Molerats
- Star Blizzard
- Wizard Spider
- SideCopy
- Storm-1811
- LazyScripter
- TA459
- Rancor
- CURIUM
- Silence
- Ferocious Kitten
- The White Company
- PROMETHIUM
- MuddyWater
- WIRTE
- PLATINUM
- APT39
- APT38
- APT37
- Sandworm Team
- APT33
- APT32
- APT30
- Magic Hound
- APT29
- APT28
- VOID MANTICORE
- Kimsuky
- OilRig
- Gorgon Group
- FIN4
- Tropic Trooper
- Leviathan
- FIN6
- FIN7
- FIN8
- Andariel
- APT19
- Sidewinder
- APT12
- admin@338
- TA551
- Darkhotel
- Windshift
- Patchwork
- IndigoZebra
- Tonto Team
- TA2541
- Moonstone Sleet
- Ajax Security Team
- Dark Caracal
- Saint Bear
- Machete
- RedCurl
- Lazarus Group
- WIZARD SPIDER
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from T1204.002 into its tactic, related techniques and the actors that use it.
Queries
Resolves the segment to this technique or tactic.
MATCH (t:ATTACK_PATTERN {name: $id})
RETURN t.id AS id, t.name AS name, t.kind AS kind, t.description AS descriptionRun yourself →The tactic(s) this technique serves.
MATCH (t:ATTACK_PATTERN {name: $id})-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN tac.id AS id, tac.name AS name
LIMIT 10Run yourself →This id's parent technique, if it is a sub-technique.
MATCH (p:ATTACK_PATTERN {name: $parentId})
RETURN p.id AS id, p.name AS name
LIMIT 1Run yourself →Sub-techniques of this technique, if any.
MATCH (c:ATTACK_PATTERN) WHERE c.id STARTS WITH $subPrefix
RETURN c.id AS id, c.name AS name
ORDER BY c.id
LIMIT 25Run yourself →Threat actors observed using this technique.
MATCH (a:ACTOR)-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN {name: $id})
RETURN a.name AS name
LIMIT 100Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.