FORENSIA

ATT&CK · T1204.002 · sub-technique

Malicious File

Tactics: execution

About

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso. Adversaries may employ various forms of Masquerading and Obfuscated Files or Information to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it. While Malicious File frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing.

Platforms: Linux, macOS, WindowsParent: T1204 User ExecutionMITRE ATT&CK ↗

Used by actors

86 known groups

Software

98 malware/tools implement this

TaidoorPlugXRTMNETWIREBandookROKRATInvisiMoleTYPEFRAMETrickBotBisonalAgent TeslaRemcosOctopusCardinal RATKONNIEmotetAstarothDridexJCrySQLRatOSX/ShlayerPoetRATRifdoorPLEADLokibotPonyMetamorfoRamsaySYSCONCARROTBALLValakBundloreIcedIDStrongPityREvilHancitorBLINDINGCANKGH_SPYCSPY DownloaderJavaliGrandoreiroGuLoaderAppleJeusKerrdownBad RabbitAppleSeedChaesEnvyScoutBoomBoxNativeZoneBADFLICKJSS LoaderQakBotClamblingThreatNeedleKOCTOPUSWarzoneRATFlagproZxxZDanBotOutSteelSaint BotDnsSystemMongallHeyoka BackdoorSquirrelwaffleSTARWHALEBumblebeeSUGARDUMPBrute Ratel C4SVCReadyWoody RATDarkTortillaBlack BastaKOPILUWAKSnip3AsyncRATDiscoNinjaDarkGateMispaduLunarMailLatrodectusMangoStrelaStealerLumma StealerHavocHIUPANCLAIMLOADERSTATICPLUGINRedLine StealerQilinBeaverTailLODEINFOROAMINGHOUSEAshTagLAMEHUGRustyWater

Corpus indicators tagged with this technique

2,964 indicators in the corpus carry T1204.002.

IndicatorTypeFamilySevSrc
cve-2026-3102cve853
cve-2025-68670cve852
c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2sha256supply_chain801
e4ccb2328c06710a7f0254cb6315e1b106396b0ff525f9cf3eada6e85d285c1csha256801
282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990sha256supply_chain801
50ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdfsha256supply_chain801
771a47120b935e218322046e838347d722d265b91f1afdef91194a5bec86a97asha256phishing802
55d6238b01a177e25eb7d53c943f3abea64ec073hashphishing802
62a879b0d1c1649cc72b2b6f61a8f6bd888625ce6e8a7aefe0a0461e4f27c525sha256phishing802
107b5aa3c4ef30b9b832e0a10b1efb1dcf433158bc6af8d890d66c0c9ed50d21sha256801
9758e76b601798a30d903bf05052a53df80451e5c156548ce9da828f608b6470sha256801
7b297f18ece81e87608e158288cc9c06cb9f4a8f1b2d2256aecf7bba8d7be2absha256phishing802
a7bd8869293212e1671df90d2d41b96d4933eb9408b1111bd830e111a91bb202hashphishing802
7aa76237a7686583cc526b9d1a8486a52bd44a448d75ced51e1df4ba29ddb163sha256phishing802
23b37d2ebe683cec3b145b6f2234ee728b99228cf3774399fcfad9502daab9a9sha256phishing802
221a39856b37e3c682f62427f1e6b965b36a2405764689c914672770a01a1fa9sha256801
60972abf5425c191c81bae117f1dedaea13d39bc52f367d5dff9ad1aa4b9c5casha256phishing802
5ab41cf20315d2ea1385967d588159873a65ef5581a0b78de06c0d8617894194sha256phishing802
248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51dbsha256phishing802
5272917261d7091a59e00f9d09cd7eb1d3e111115a5b367f79a66d0d7c7b01f4sha256phishing802
6c6cbed6aad96564ed87094785be07a1hashphishing802
669002654c264191d4660fbf757860d930175649735f81370b9f1af3658a304csha256phishing802
22de84e8f29cba932cf65cf4dc1d333cb8b2e468204f97030712bee32691ac3bsha256phishing802
44a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695fsha256phishing802
7900c2772680523cadc9fe4e07300d45500191ba64ff5b91573531b133840b14sha256phishing802
61e9d76f07334843df561fe4bac449fb6fdaed5e5eb91480bded225f3d265c5fhashphishing802
50ebf107d522326c9a9db8821fe3263aa5136964faaf5dd183657bbb52725f84sha256phishing802
43d597783af656a35184021f5e20686896463a1712f9216e0217a2ca740e3935sha256phishing802
5115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35dsha256phishing802
164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3sha256supply_chain801

Showing the top 30 by severity of 2,964.