1200KM / simulation
T1566.001 Spearphishing Attachment — Attack Simulation
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In…
Technique description
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Download Macro-Enabled Phishing Attachment
Procedure 114ccff9-ae6d-4547-9ead-4cd69f687306; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Word spawned a command shell and used an IP address in the command line
Procedure cbb6799a-425c-4f83-9194-5447a909d67f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT12 · G0005
- APT1 · G0006
- APT28 · G0007
- Darkhotel · G0012
- APT30 · G0013
- APT29 · G0016
- admin@338 · G0018
- Naikon · G0019
- Molerats · G0021
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- RTM · G0048
- OilRig · G0049
- APT32 · G0050
- BRONZE BUTLER · G0060
- FIN8 · G0061
- TA459 · G0062
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- APT37 · G0067
- PLATINUM · G0068
- MuddyWater · G0069
- APT19 · G0073
- Rancor · G0075
- Gorgon Group · G0078
- DarkHydrus · G0079
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- Gallmaker · G0084
- FIN4 · G0085
- APT39 · G0087
- The White Company · G0089
- WIRTE · G0090
- Silence · G0091
- TA505 · G0092
- Kimsuky · G0094
- Machete · G0095
- APT41 · G0096
- BlackTech · G0098
- APT-C-36 · G0099
- Inception · G0100
- Wizard Spider · G0102
- Mofang · G0103
- Windshift · G0112
- Sidewinder · G0121
- Higaisa · G0126
- TA551 · G0127
- Mustang Panda · G0129
- Ajax Security Team · G0130
- Tonto Team · G0131
- Nomadic Octopus · G0133
- Transparent Tribe · G0134
- IndigoZebra · G0136
- Ferocious Kitten · G0137
- Andariel · G0138
- LazyScripter · G0140
- Confucius · G0142
- BITTER · G1002
- SideCopy · G1008
- EXOTIC LILY · G1011
- CURIUM · G1012
- TA2541 · G1018
- Malteiro · G1026
- Saint Bear · G1031
- Star Blizzard · G1033
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- RedCurl · G1039
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.