Spearphishing Attachment

T1566.001

Sub-technique of T1566 Phishing.View on attack.mitre.org

About this technique

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

There are many options for the attachment such as Microsoft Office documents, executables, PDFs, or archived files. Upon opening the attachment (and potentially clicking past protections), the adversary's payload exploits a vulnerability or directly executes on the user's system. The text of the spearphishing email usually tries to give a plausible reason why the file should be opened, and may explain how to bypass system protections in order to do so. The email may also contain instructions on how to decrypt an attachment, such as a zip file password, in order to evade email boundary defenses. Adversaries frequently manipulate file extensions and icons in order to make attached executables appear to be document files, or files exploiting one application appear to be a file for a different one.

Detection rules71

Rules on DetectionCode tagged with T1566.001.

Sigma19

RuleLevelLog source
HTML Help HH.EXE Suspicious Child Processhighwindows / process_creation
ISO File Created Within Temp Foldershighwindows / file_event
Office Macro File Creation From Suspicious Processhighwindows / file_event
Password Protected ZIP File Opened (Email Attachment)highwindows / NULL
Suspicious Double Extension File Executionhighwindows / process_creation
Suspicious Execution From Outlook Temporary Folderhighwindows / process_creation
Suspicious File Created in Outlook Temporary Directoryhighwindows / file_event
Suspicious HH.EXE Executionhighwindows / process_creation
Suspicious HWP Sub Processeshighwindows / process_creation
Suspicious Microsoft OneNote Child Processhighwindows / process_creation
Arbitrary Shell Command Execution Via Settingcontent-Msmediumwindows / process_creation
Disk Image Mounting Via Hdiutil - MacOSmediummacos / process_creation
ISO Image Mountedmediumwindows / NULL
ISO or Image Mount Indicator in Recent Filesmediumwindows / file_event
Potential Initial Access via DLL Search Order Hijackingmediumwindows / file_event

Splunk52

RuleTypeRiskData source
Detect Outlook exe writing a zip fileAnomalyNULLSysmon EventID 1 AND Sysmon EventID 11
Email Attachments With Lots Of SpacesAnomalyNULL
GSuite Email Suspicious AttachmentAnomalyNULLG Suite Gmail
Gsuite Email Suspicious Subject With AttachmentAnomalyNULLG Suite Gmail
Gsuite Email With Known Abuse Web Service LinkAnomalyNULLG Suite Gmail
Gsuite Suspicious Shared File NameAnomalyNULLG Suite Drive
MSHTML Module Load in Office ProductTTPNULLSysmon EventID 7
O365 Email Reported By Admin Found MaliciousTTPNULLOffice 365 Universal Audit Log
O365 Email Reported By User Found MaliciousTTPNULLOffice 365 Universal Audit Log
O365 Safe Links DetectionTTPNULLOffice 365 Universal Audit Log
O365 Threat Intelligence Suspicious Email DeliveredAnomalyNULLOffice 365 Universal Audit Log
O365 ZAP Activity DetectionAnomalyNULLOffice 365 Universal Audit Log
Office Application Drop ExecutableTTPNULLSysmon EventID 1 AND Sysmon EventID 11
Office Application Spawn Regsvr32 processTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Office Application Spawn rundll32 processTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups78

Show 54 more

Software61

Show 37 more

Campaigns10

Procedure examples149

Groups78

Used byProcedure example
Groupadmin@338

admin@338 has sent emails with malicious Microsoft Office documents attached.

GroupAjax Security Team

Ajax Security Team has used personalized spearphishing attachments.

GroupAndariel

Andariel has conducted spearphishing campaigns that included malicious Word or Excel attachments.

GroupAPT-C-36

APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway.

GroupAPT1

APT1 has sent spearphishing emails containing malicious attachments.

GroupAPT12

APT12 has sent emails with malicious Microsoft Office documents and PDFs attached.

GroupAPT19

APT19 sent spearphishing emails with malicious attachments in RTF and XLSM formats to deliver initial exploits.

GroupAPT28

APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments.

View all 78 groups examples

Software61

Used byProcedure example
MalwareAgent Tesla

The primary delivered mechanism for Agent Tesla is through email phishing messages.

MalwareAppleSeed

AppleSeed has been distributed to victims through malicious e-mail attachments.

MalwareAstaroth

Astaroth has been delivered via malicious e-mail attachments.

ToolAsyncRAT

AsyncRAT has been delivered via malicious email attachments.

MalwareBADFLICK

BADFLICK has been distributed via spearphishing campaigns containing malicious Microsoft Word documents.

MalwareBandook

Bandook is delivered via a malicious Word document inside a zip file.

MalwareBisonal

Bisonal has been delivered as malicious email attachments.

MalwareBLINDINGCAN

BLINDINGCAN has been delivered by phishing emails containing malicious Microsoft Office documents.

View all 61 software examples

Campaigns10

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team obtained their initial foothold into many IT systems using Microsoft Office attachments delivered through phishing emails.

CampaignC0011

During C0011, Transparent Tribe sent malicious attachments via email to student targets in India.

CampaignC0015

For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims.

CampaignFrankenstein

During Frankenstein, the threat actors likely used spearphishing emails to send malicious Microsoft Word documents.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers.

CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document.

CampaignOperation Spalax

During Operation Spalax, the threat actors sent phishing emails that included a PDF document that in some cases led to the download and execution of malware.

View all 10 campaigns examples

References1

  1. Unit 42 DarkHydrus July 2018 Open source
    Falcone, R., et al. (2018, July 27). New Threat Actor Group DarkHydrus Targets Middle East Government. Retrieved August 2, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.