# T1204.002 Malicious File

> As of 2026-10-05, T1204.002 (Malicious File) appears in 445 tracked threats, first reported 2026-01-01 and most recently 2026-10-02, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 445 (59 critical, 335 high, 49 medium, 2 low)
- **First seen:** 2026-01-01
- **Last seen:** 2026-10-02
- **Threat actors:** 113
- **Detection rules:** 1351 (counts only; Blue tier and above)

## Key facts

- **ID:** T1204.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Parent:** T1204
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1204/002/

## Activity timeline

T1204.002 first appeared in tracked threats on 2026-01-01 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 111 reports, and 445 of the 445 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1204.002 Malicious File is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of [T1204 User Execution](https://intel.threadlinqs.com/technique/T1204). Threadlinqs maps 445 of 2623 tracked threats (17%) to it; by severity that is 59 critical, 335 high, 49 medium, 2 low.

Threats that use T1204.002 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (318 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (272 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (252 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (248 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (234 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

113 tracked threat actors appear in the threats that use T1204.002; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (16), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (13), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (13), [APT28](https://intel.threadlinqs.com/actor/APT28) (11), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (9).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1204.002.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)

## Data sources

Telemetry that can reveal T1204.002, per MITRE ATT&CK.

- File — File Creation
- Process — Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 16
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 13
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 13
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 11
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 9
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 8
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 8
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 8
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 7
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 7
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 6
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 6

## Tracked threats

The 30 most recent of 445 tracked threats that use T1204.002.

- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer](https://intel.threadlinqs.com/threat/TL-2026-2840) — high — 2026-10-02
- [ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing](https://intel.threadlinqs.com/threat/TL-2026-2826) — medium — 2026-10-01
- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…](https://intel.threadlinqs.com/threat/TL-2026-2802) — high — 2026-09-30
- [AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…](https://intel.threadlinqs.com/threat/TL-2026-2800) — high — 2026-09-30
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — high — 2026-09-29
- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…](https://intel.threadlinqs.com/threat/TL-2026-2773) — high — 2026-09-29
- [OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers](https://intel.threadlinqs.com/threat/TL-2026-2767) — high — 2026-09-29
- [Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…](https://intel.threadlinqs.com/threat/TL-2026-2764) — high — 2026-09-28
- [Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)](https://intel.threadlinqs.com/threat/TL-2026-2757) — high — 2026-09-28
- [Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)](https://intel.threadlinqs.com/threat/TL-2026-2752) — high — 2026-09-28
- [Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks](https://intel.threadlinqs.com/threat/TL-2026-2745) — high — 2026-09-28
- [MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…](https://intel.threadlinqs.com/threat/TL-2026-2723) — high — 2026-09-27
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — high — 2026-09-27
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — high — 2026-09-27
- [PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistence](https://intel.threadlinqs.com/threat/TL-2026-2674) — high — 2026-09-26
- [BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limited](https://intel.threadlinqs.com/threat/TL-2026-2667) — high — 2026-09-26
- [Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)](https://intel.threadlinqs.com/threat/TL-2026-2659) — high — 2026-09-26
- [Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users](https://intel.threadlinqs.com/threat/TL-2026-2655) — medium — 2026-09-25
- [Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…](https://intel.threadlinqs.com/threat/TL-2026-2654) — high — 2026-09-25
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…](https://intel.threadlinqs.com/threat/TL-2026-2650) — critical — 2026-09-25
- [Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…](https://intel.threadlinqs.com/threat/TL-2026-2647) — high — 2026-09-25
- [SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…](https://intel.threadlinqs.com/threat/TL-2026-2646) — high — 2026-09-25
- [Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…](https://intel.threadlinqs.com/threat/TL-2026-2645) — high — 2026-09-25
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [BigDiskBuster PoC Blocks Microsoft Defender Antivirus Updates via Disk-Space Exhaustion](https://intel.threadlinqs.com/threat/TL-2026-2618) — medium — 2026-09-22

## Related CVEs

CVEs referenced by the tracked threats that use T1204.002, most frequent first.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-25592](https://intel.threadlinqs.com/cve/CVE-2026-25592)
- [CVE-2026-26030](https://intel.threadlinqs.com/cve/CVE-2026-26030)
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2026-34621](https://intel.threadlinqs.com/cve/CVE-2026-34621)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)
- [CVE-2012-1854](https://intel.threadlinqs.com/cve/CVE-2012-1854)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2017-8291](https://intel.threadlinqs.com/cve/CVE-2017-8291)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-16040](https://intel.threadlinqs.com/cve/CVE-2020-16040)
- [CVE-2020-9715](https://intel.threadlinqs.com/cve/CVE-2020-9715)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)

## Detection coverage

Threadlinqs maintains 1351 detection rules mapped to T1204.002 (SPL 535, KQL 411, Sigma 405). Rule content is available to Blue tier accounts and above; this page shows counts only.

1351 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1204 User Execution](https://intel.threadlinqs.com/technique/T1204) — 571 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1204.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
