T1566.001 Spearphishing Attachment — ATT&CK Technique
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source. There are many options for the attachment such as Microsoft Office documents, executables, PDFs, or archived files. Upon opening the attachment (and potentially clicking past protections), the adversary's payload exploits a vulnerability or directly executes on the user's system. The text of the spearphishing email usually tries to give a plausible reason why the file should be opened, and may explain how to bypass system protections in order to do so. The email may also contain instructions on how to decrypt an attachment, such as a zip file password, in order to evade email boundary defenses. Adversaries frequently manipulate file extensions and icons in order to make attached executables appear to be document files, or files exploiting one application appear to be a file for a different one.
Detection coverage (50)
- HTML File Opened From Download Folder low
- Disk Image Mounting Via Hdiutil - MacOS medium
- Suspicious Email Delivered In Microsoft 365 medium
- ISO Image Mounted medium
- Password Protected ZIP File Opened (Email Attachment) high
- ISO or Image Mount Indicator in Recent Files medium
- ISO File Created Within Temp Folders high
- Potential Initial Access via DLL Search Order Hijacking medium
- Office Macro File Creation low
- Office Macro File Download low
- Office Macro File Creation From Suspicious Process high
- Suspicious File Created in Outlook Temporary Directory high
- HTML Help HH.EXE Suspicious Child Process high
- Suspicious HH.EXE Execution high
- Suspicious HWP Sub Processes high
- Suspicious Microsoft OneNote Child Process high
- Suspicious Execution From Outlook Temporary Folder high
- Arbitrary Shell Command Execution Via Settingcontent-Ms medium
- Suspicious Double Extension File Execution high
- Windows Registry Trust Record Modification medium
- Email Attachments With Lots Of Spaces
- Suspicious Email Attachment Extensions
- Gsuite Email With Known Abuse Web Service Link
- GSuite Email Suspicious Attachment
- Gsuite Email Suspicious Subject With Attachment
- Gsuite Suspicious Shared File Name
- O365 Email Reported By Admin Found Malicious
- O365 Email Reported By User Found Malicious
- O365 Safe Links Detection
- O365 Threat Intelligence Suspicious Email Delivered
- O365 ZAP Activity Detection
- Detect Outlook exe writing a zip file
- Windows CAB File on Disk
- Windows Defender ASR Audit Events
- Windows Defender ASR Block Events
- Windows Defender ASR Rules Stacking
- Windows ISO LNK File Creation
- Windows Office Product Dropped Cab or Inf File
- Windows Office Product Loaded MSHTML Module
- Windows Office Product Spawned Child Process For Download
- Windows Office Product Dropped Uncommon File
- Windows Office Product Loading VBE7 DLL
- Windows Office Product Spawned MSDT
- Windows Office Product Loading Taskschd DLL
- Windows Office Product Spawned Control
- Windows Office Product Spawned Uncommon Process
- Windows Office Product Spawned Rundll32 With No DLL
- Windows Phishing Recent ISO Exec Registry
- Windows Phishing PDF File Executes URL Link
- Exploit for CVE-2017-0261 medium
Malware using this technique
- TrickBot
- BLINDINGCAN
- Bumblebee
- Bandook
- KOPILUWAK
- ThreatNeedle
- Pony
- AppleSeed
- NETWIRE
- EnvyScout
- Emotet
- Clambling
- Woody RAT
- Squirrelwaffle
- Snip3
- Rifdoor
- DarkWatchman
- RustyWater
- IcedID
- Flagpro
- DarkTortilla
- ROKRAT
- Javali
- Bisonal
- Lumma Stealer
- DarkGate
- SVCReady
- Latrodectus
- Saint Bot
- Chaes
- LODEINFO
- Metamorfo
- KONNI
- Kerrdown
- RTM
- StrelaStealer
- ZxxZ
- XLoader
- REvil
- Valak
- Taidoor
- DanBot
- Ramsay
- OutSteel
- LAMEHUG
- Lokibot
- PoetRAT
- KOCTOPUS
- Octopus
- Qilin
Threat actors using this technique
- APT38
- Sidewinder
- Inception
- RedNovember
- APT30
- Rancor
- WIRTE
- PLATINUM
- Elderwood
- SideCopy
- Kimsuky
- EXOTIC LILY
- admin@338
- Star Blizzard
- Patchwork
- APT41
- Dragonfly
- Gorgon Group
- APT10
- APT32
- MuddyWater
- Naikon
- FIN6
- APT-C-36
- Tonto Team
- Lazarus Group
- Gamaredon Group
- Gallmaker
- FIN7
- Sandworm Team
- Machete
- Andariel
- CURIUM
- Mustang Panda
- APT39
- TA2541
- APT37
- OilRig
- Higaisa
- Tropic Trooper
- Ajax Security Team
- APT27
- TA459
- Ferocious Kitten
- The White Company
- Saint Bear
- APT1
- DarkHydrus
- Confucius
- BlackTech