1200KM / simulation
T1204.002 Malicious File — Attack Simulation
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.…
Technique description
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Potentially Unwanted Applications (PUA)
Procedure 02f35d62-9fdc-4a97-b899-a5d9a876d295; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Maldoc choice flags command execution
Procedure 0330a5d2-a45a-4272-a9ee-e364411c4b18; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Simulate Click-Fix via Downloaded BAT File
Procedure 22386853-f68d-4b50-a362-de235127c443; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Mirror Blast Emulation
Procedure 24fd9719-7419-42dd-bce6-ab3463110b3c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- ClickFix Campaign - Abuse RunMRU to Launch mshta via PowerShell
Procedure 3f3120f0-7e50-4be2-88ae-54c61230cb9f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- OSTap Payload Download
Procedure 3f3af983-118a-4fa1-85d3-ba4daa739d80; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Excel 4 Macro
Procedure 4ea1fc97-8a46-4b4e-ba48-af43d2a98052; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Office Generic Payload Download
Procedure 5202ee05-c420-4148-bf5e-fd7f7d24850c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- LNK Payload Download
Procedure 581d7521-9c4b-420e-9695-2aec5241167f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- OSTap Style Macro Execution
Procedure 8bebc690-18c7-4549-bc98-210f7019efff; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Office launching .bat file from AppData
Procedure 9215ea92-1ded-41b7-9cd6-79f9a78397aa; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Headless Chrome code execution via VBA
Procedure a19ee671-ed98-4e9d-b19c-d1954a51585a; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- OSTAP JS version
Procedure add560ef-20d6-4011-a937-2c340f930911; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT12 · G0005
- APT28 · G0007
- Darkhotel · G0012
- APT30 · G0013
- APT29 · G0016
- admin@338 · G0018
- Naikon · G0019
- Molerats · G0021
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- RTM · G0048
- OilRig · G0049
- APT32 · G0050
- PROMETHIUM · G0056
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- TA459 · G0062
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- APT37 · G0067
- PLATINUM · G0068
- MuddyWater · G0069
- Dark Caracal · G0070
- APT19 · G0073
- Rancor · G0075
- Gorgon Group · G0078
- DarkHydrus · G0079
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- Gallmaker · G0084
- FIN4 · G0085
- APT39 · G0087
- The White Company · G0089
- WIRTE · G0090
- Silence · G0091
- TA505 · G0092
- Kimsuky · G0094
- Machete · G0095
- BlackTech · G0098
- APT-C-36 · G0099
- Inception · G0100
- Wizard Spider · G0102
- Mofang · G0103
- Whitefly · G0107
- Windshift · G0112
- Indrik Spider · G0119
- Sidewinder · G0121
- Higaisa · G0126
- TA551 · G0127
- Mustang Panda · G0129
- Ajax Security Team · G0130
- Tonto Team · G0131
- Nomadic Octopus · G0133
- Transparent Tribe · G0134
- IndigoZebra · G0136
- Ferocious Kitten · G0137
- Andariel · G0138
- LazyScripter · G0140
- Confucius · G0142
- HEXANE · G1001
- BITTER · G1002
- Earth Lusca · G1006
- Aoqin Dragon · G1007
- SideCopy · G1008
- EXOTIC LILY · G1011
- CURIUM · G1012
- TA2541 · G1018
- Malteiro · G1026
- Saint Bear · G1031
- Star Blizzard · G1033
- Moonstone Sleet · G1036
- RedCurl · G1039
- Storm-1811 · G1046
- Contagious Interview · G1052
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.