TACTIC: INITIAL ACCESS
Spearphishing Attachment (T1566.001): real cases
MITRE Definition ↗ Adversaries send spearphishing emails with malicious attachments to gain initial access to victim systems.
Key Facts
Technique ID
T1566.001
Initial Access
Mapped Cases
6
Primary sources
Related Laws
4
Criminal statutes
- ATT&CK Technique Identifier: T1566.001.
- Tactical Phase: Initial Access.
- Substantiated in 6 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)
fugitive 2020-10-15
Primary Source Evidence Excerpt: Indictment ¶ 15, Page 7
"Spearphishing emails containing weaponized Microsoft Word documents executing malicious macros were sent to Ukrainian electrical substation operators."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)
sentenced 2018-03-27
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 8
"FIN7 members sent spearphishing emails with malicious Microsoft Word attachments to restaurant managers disguised as catering orders or customer complaints."
U.S. District Court for the Western District of Washington
View full case dossier →
U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)
fugitive 2019-11-14
Primary Source Evidence Excerpt: Indictment ¶ 19, Page 11
"Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)
fugitive 2014-05-01
Primary Source Evidence Excerpt: Indictment ¶ 15, Page 7
"Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)
sentenced 2021-02-18
Primary Source Evidence Excerpt: Indictment ¶ 14, Page 7
"Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros."
U.S. District Court for the Northern District of Ohio
View full case dossier →
U.S. & International Action: Dmitry Badin (German Bundestag Hack)
fugitive 2020-05-05
Primary Source Evidence Excerpt: BKA Investigation Summary
"Attackers sent spearphishing emails with malicious attachments disguised as United Nations newsletters to German members of parliament."
Federal Court of Justice (Germany) & U.S. District Court for the District of Columbia
View full case dossier →
Commonly Charged Criminal Statutes
18 U.S.C. § 1030(a)(2)
Unauthorized Access to Obtain Protected Information
Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.
18 U.S.C. § 1030(a)(5)(A)
Intentional Damage to a Protected Computer
Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.
18 U.S.C. § 1030(a)(7)
Extortion in Connection with Computers
Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.
18 U.S.C. § 1030(b)
Conspiracy to Commit Computer Fraud
Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.