1200KM / simulation
T1204.001 Malicious Link — Attack Simulation
An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Link. Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via Exploitation for Client…
Technique description
An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Link. Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via Exploitation for Client…
No compatible procedure was found in the pinned Atomic index. This is a support gap, not a finding of technical impossibility.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
No compatible documented candidate in the pinned snapshot. This is a support gap, not technical impossibility.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Turla · G0010
- APT29 · G0016
- Molerats · G0021
- APT3 · G0022
- Sandworm Team · G0034
- Patchwork · G0040
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- FIN8 · G0061
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- MuddyWater · G0069
- Cobalt Group · G0080
- APT38 · G0082
- FIN4 · G0085
- APT39 · G0087
- WIRTE · G0090
- TA505 · G0092
- Kimsuky · G0094
- Machete · G0095
- BlackTech · G0098
- APT-C-36 · G0099
- Wizard Spider · G0102
- Mofang · G0103
- Windshift · G0112
- Evilnum · G0120
- Sidewinder · G0121
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- Transparent Tribe · G0134
- LazyScripter · G0140
- Confucius · G0142
- Earth Lusca · G1006
- EXOTIC LILY · G1011
- LuminousMoth · G1014
- TA2541 · G1018
- Mustard Tempest · G1020
- Saint Bear · G1031
- Daggerfly · G1034
- Winter Vivern · G1035
- TA577 · G1037
- TA578 · G1038
- RedCurl · G1039
- Contagious Interview · G1052
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.