Activity timeline
T1204.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 111 reports, and 445 of the 445 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1204.002 Malicious File is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of T1204 User Execution. Threadlinqs maps 445 of 2623 tracked threats (17%) to it; by severity that is 59 critical, 335 high, 49 medium, 2 low.
Threats that use T1204.002 most often also use T1071.001 Web Protocols (318 threats), T1027 Obfuscated Files or Information (272 threats), T1082 System Information Discovery (252 threats), T1036.005 Match Legitimate Resource Name or Location (248 threats), T1005 Data from Local System (234 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
113 tracked threat actors appear in the threats that use T1204.002; the most frequent are APT38 (16), Sapphire Sleet (13), Stardust Chollima (13), APT28 (11), Lazarus Group (9).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1204.002.
Data sources
Telemetry that can reveal T1204.002, per MITRE ATT&CK.
- File — File Creation
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 445 tracked threats that use T1204.002.
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- CloudSyncD macOS Backdoor Delivered via Fake Zoom Installerhigh
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishingmedium
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…high
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installershigh
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…high
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)high
- Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)high
- Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attackshigh
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…high
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvestershigh
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environmentshigh
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limitedhigh
- Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)high
- Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Usersmedium
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…high
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…critical
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…high
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…high
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- BigDiskBuster PoC Blocks Microsoft Defender Antivirus Updates via Disk-Space Exhaustionmedium
Detection coverage
Threadlinqs maintains 1351 detection rules mapped to T1204.002 (SPL 535, KQL 411, Sigma 405). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1204 User Execution — 571 tracked threats at the technique level.