FORENSIA

ATT&CK · T1566.001 · sub-technique

Spearphishing Attachment

Tactics: initial-access

About

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source. There are many options for the attachment such as Microsoft Office documents, executables, PDFs, or archived files. Upon opening the attachment (and potentially clicking past protections), the adversary's payload exploits a vulnerability or directly executes on the user's system. The text of the spearphishing email usually tries to give a plausible reason why the file should be opened, and may explain how to bypass system protections in order to do so. The email may also contain instructions on how to decrypt an attachment, such as a zip file password, in order to evade email boundary defenses. Adversaries frequently manipulate file extensions and icons in order to make attached executables appear to be document files, or files exploiting one application appear to be a file for a different one.

Platforms: Linux, macOS, WindowsParent: T1566 PhishingMITRE ATT&CK ↗

Used by actors

78 known groups

Software

60 malware/tools implement this

TaidoorRTMNETWIREBandookROKRATTrickBotBisonalAgent TeslaRemcosOctopusOceanSaltKONNIEmotetAstarothPoetRATRifdoorLokibotPonyMetamorfoRamsayValakIcedIDREvilHancitorBLINDINGCANJavaliKerrdownAppleSeedChaesEnvyScoutBADFLICKJSS LoaderQakBotClamblingThreatNeedleKOCTOPUSWarzoneRATDarkWatchmanFlagproZxxZDanBotOutSteelSaint BotSquirrelwaffleBumblebeeSVCReadyWoody RATDarkTortillaKOPILUWAKSnip3AsyncRATDarkGateLatrodectusStrelaStealerXLoaderLumma StealerQilinLODEINFOLAMEHUGRustyWater

Corpus indicators tagged with this technique

1,220 indicators in the corpus carry T1566.001.

IndicatorTypeFamilySevSrc
cve-2025-68670cve852
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801
50ebf107d522326c9a9db8821fe3263aa5136964faaf5dd183657bbb52725f84sha256phishing802
7aa76237a7686583cc526b9d1a8486a52bd44a448d75ced51e1df4ba29ddb163sha256phishing802
adcd15f3d6b87f84d106ea426fa824fd20c9d64f6d199ce92580884290785f30sha256phishing801
7b7981c99d59595fe15377df84695bb72ce0b85560a3935f930657b2d162e5efsha256phishing801
62a879b0d1c1649cc72b2b6f61a8f6bd888625ce6e8a7aefe0a0461e4f27c525sha256phishing802
7900c2772680523cadc9fe4e07300d45500191ba64ff5b91573531b133840b14sha256phishing802
771a47120b935e218322046e838347d722d265b91f1afdef91194a5bec86a97asha256phishing802
5864a697bd7b339f56b05405f29a097cd027cafdcc4e63c2aaeccccbf930605fsha256801
248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51dbsha256phishing802
7b297f18ece81e87608e158288cc9c06cb9f4a8f1b2d2256aecf7bba8d7be2absha256phishing802
ad10ff9043d6f327045943635fcbd0c5918acb79dc998db92ee4c7dee5224710sha256801
c099f965144bccd0b590f946659fc3c0747c54aef505b6caaca9078712f455fbsha256801
64c7dd0a3a3ae49977ac05913d3878000cce14e5d8c1ee05b782bdfd648bde91sha256801
23b37d2ebe683cec3b145b6f2234ee728b99228cf3774399fcfad9502daab9a9sha256phishing802
60972abf5425c191c81bae117f1dedaea13d39bc52f367d5dff9ad1aa4b9c5casha256phishing802
5ab41cf20315d2ea1385967d588159873a65ef5581a0b78de06c0d8617894194sha256phishing802
22de84e8f29cba932cf65cf4dc1d333cb8b2e468204f97030712bee32691ac3bsha256phishing802
669002654c264191d4660fbf757860d930175649735f81370b9f1af3658a304csha256phishing802
5115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35dsha256phishing802
6c6cbed6aad96564ed87094785be07a1hashphishing802
a7bd8869293212e1671df90d2d41b96d4933eb9408b1111bd830e111a91bb202hashphishing802
5272917261d7091a59e00f9d09cd7eb1d3e111115a5b367f79a66d0d7c7b01f4sha256phishing802
55d6238b01a177e25eb7d53c943f3abea64ec073hashphishing802
4c9f271242f61f1a31b8146305e9a7ed512c521445d4f7a7a901e301307add3dsha256801
61e9d76f07334843df561fe4bac449fb6fdaed5e5eb91480bded225f3d265c5fhashphishing802
43d597783af656a35184021f5e20686896463a1712f9216e0217a2ca740e3935sha256phishing802
44a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695fsha256phishing802
d7d2f0ee187549f3f4a114d716be12521fbf62d6d26e2ac23d2a32d521d08fd8sha256phishing801

Showing the top 30 by severity of 1,220.