MITRE ATT&CK Technique
T1204.001Malicious Link
- First Reported
- Sep 10, 2026
- Latest Reported
- Sep 25, 2026
Official Description
An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002). Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203). Links may also lead users to download files that require execution via [Malicious File](https://attack.mitre.org/techniques/T1204/002).
- Tactics
- Execution
- Platforms
- Linux, macOS, Windows
- Parent Technique
- T1204 · User Execution
- MITRE Version
- 1.2
- Last Modified
- May 12, 2026
Reported Context (3)
- Users clicking a malicious sponsored ad entered the redirect chain leading to the phishing page. Phishing Campaign Uses Google Ads to Steal Ledger Recovery Phrases
- Victims click a paid Google ad that takes them to the scam page. Google Ads Deliver Fake Tech-Support Lockers Impersonating Microsoft Defender and Apple
- The lures prompt recipients to click malicious links leading to the infection chain. FortiGuard Details Casbaneiro Banking Trojan Campaign Targeting Latin America
Malware (3)
MITRE ATT&CK (11)
Vendors (7)
Products (17)
Tools (1)
Industries (2)
Countries (7)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.