Malicious File
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, and .reg. Adversaries may employ various forms of Masquerading and Obfuscated Files or Information to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it. While Malicious File frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing.
Open detection, hunting, mitigation, and evidence workspace
Detection logic
Monitor the execution of and command-line arguments for applications that may be used by an adversary to gain initial access that require user interaction. This includes compression applications, such as those for zip files, that can be used to Deobfuscate/Decode Files or Information in payloads. Anti-virus can potentially detect malicious documents and files that are downloaded and executed on the user's computer. Endpoint sensing or network sensing can potentially detect malicious events once the file is opened (such as a Microsoft Word document or PDF reaching out to the internet or spawning powershell.exe).
Observed actors
G0082Indrik Spider
G0119Elderwood
G0066SideCopy
G1008Kimsuky
G0094EXOTIC LILY
G1011admin@338
G0018Patchwork
G0040Dragonfly
G0035Gorgon Group
G0078menuPass
G0045APT32
G0050MuddyWater
G0069Naikon
G0019FIN6
G0037Gamaredon Group
G0047Gallmaker
G0084FIN7
G0046Sandworm Team
G0034Machete
G0095Andariel
G0138CURIUM
G1012Sidewinder
G0121Mustang Panda
G0129APT39
G0087TA2541
G1018APT37
G0067OilRig
G0049Higaisa
G0126Tropic Trooper
G0081TA459
G0062Aoqin Dragon
G1007Ferocious Kitten
G0137The White Company
G0089Saint Bear
G1031DarkHydrus
G0079Confucius
G0142BlackTech
G0098Leviathan
G0065TA505
G0092BITTER
G1002RedCurl
G1039Mofang
G0103APT29
G0016Dark Caracal
G0070BRONZE BUTLER
G0060TA551
G0127Star Blizzard
G1033Darkhotel
G0012Ember Bear
G1003LazyScripter
G0140Windshift
G0112Whitefly
G0107APT28
G0007Malteiro
G1026RTM
G0048APT12
G0005APT-C-36
G0099Tonto Team
G0131Lazarus Group
G0032Earth Lusca
G1006FIN4
G0085Silence
G0091Cobalt Group
G0080Wizard Spider
G0102Molerats
G0021Transparent Tribe
G0134IndigoZebra
G0136Moonstone Sleet
G1036Inception
G0100PROMETHIUM
G0056APT30
G0013HEXANE
G1001Rancor
G0075WIRTE
G0090PLATINUM
G0068Magic Hound
G0059Ajax Security Team
G0130Threat Group-3390
G0027APT33
G0064FIN8
G0061APT19
G0073Nomadic Octopus
G0133
Correlated CTI and IR reports
ESET Research · direct source mappingMalware Spotlight: A Deep-Dive Analysis of WezRat
Check Point Research · direct source mapping1. Executive Summary
Israel Threat Actors CTI · explicit report mentionAPT39 (Chafer / Remix Kitten)
Israel Threat Actors CTI · explicit report mentionATT&CK as a Working Tool: Theory and Hands-On Practical Usage
1200km CTI repository · explicit report mentionCTI Research: MuddyWater / Seedworm (Mango Sandstorm)
1200km CTI repository · explicit report mentionCTI Research: MuddyWater / Seedworm (Mango Sandstorm)
1200km CTI repository · explicit report mentionDefensive Cyber Threat Intelligence Report: Israeli Critical Infrastructure and Geopolitical Escalation (2024-2026)
Israel Threat Actors CTI · explicit report mentionExecutive Summary
Israel Threat Actors CTI · explicit report mentionFrom Threat Intelligence to Detection: A Practitioner's Guide
1200km CTI repository · explicit report mentionATT CK as a Working Tool Theory and Hands On Practical Usage
1200km Medium · authored report mentionCTI Research MuddyWater Seedworm Mango Sandstorm
1200km Medium · authored report mentionCorrelation Based Detection Rules in Cybersecurity From Atomic Events to Behavioral Insight
1200km Medium · authored report mentionFrom Threat Intelligence to Detection A Practitioner s Guide
1200km Medium · authored report mention