MITRE ATT&CK Technique
T1204.002Malicious File
- First Reported
- Aug 3, 2026
- Latest Reported
- Sep 30, 2026
Official Description
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001). Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.(Citation: Mandiant Trojanized Windows 10)
Adversaries may employ various forms of [Masquerading](https://attack.mitre.org/techniques/T1036) and [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it.(Citation: Password Protected Word Docs)
While [Malicious File](https://attack.mitre.org/techniques/T1204/002) frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after [Internal Spearphishing](https://attack.mitre.org/techniques/T1534).
Adversaries may employ various forms of [Masquerading](https://attack.mitre.org/techniques/T1036) and [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it.(Citation: Password Protected Word Docs)
While [Malicious File](https://attack.mitre.org/techniques/T1204/002) frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after [Internal Spearphishing](https://attack.mitre.org/techniques/T1534).
- Tactics
- Execution
- Platforms
- Linux, macOS, Windows
- Parent Technique
- T1204 · User Execution
- MITRE Version
- 1.6
- Last Modified
- May 12, 2026
Reported Context (8)
- The intrusion began with the user's execution of KMS Auto on the affected system. KMS Auto Abuse Led to Mining, Remote Access Tools and Ransomware-Themed Scareware; APT36 Link Unconfirmed
- Users were induced to run a BAT or PKG file presented as a cryptocurrency exchange installer. JSCEAL Malware Spread Through Fake Cryptocurrency Exchange Ads on Facebook
- The infection chain depended on a recipient opening the HTML file inside the ZIP attachment. MintsLoader Campaign Uses Compromised Certified Email Accounts to Deliver Malware
- The fake SSN page relies on users downloading and running an Android APK or Windows BAT file. Fake National Health Service Site Delivers StreamRat on Android and XWorm on Windows
- Counterfeit viewer instructions prompted victims to open downloaded scripts or installers. CSuite Campaign Uses Phishing, M365 Session Theft and Remote-Access Tools Against US and EU Organizations
Malware (5)
Threat Actors (7)
MITRE ATT&CK (62)
Vendors (12)
Products (29)
Tools (14)
Industries (10)
Countries (11)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.