Adversaries may rely on a targeted organizations user interaction for the execution of malicious code. User interaction may consist of installing applications, opening email attachments, or granting higher permissions to documents. Adversaries may embed malicious code or visual basic code into files such as Microsoft Word and Excel documents or software installers. (Citation: Booz Allen Hamilton) Execution of this code requires that the user enable scripting or write access within the document. Embedded code may not always be noticeable to the user especially in cases of trojanized software. (Citation: Daavid Hentunen, Antti Tikkanen June 2014) A Chinese spearphishing campaign running from December 9, 2011 through February 29, 2012 delivered malware through spearphishing attachments which required user action to achieve execution. (Citation: CISA AA21-201A Pipeline Intrusion July 2021)

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Jump Host
is related to Human-Machine Interface (HMI)
is related to Workstation
is blocked by Execution Prevention
is blocked by Detection of User Execution
is blocked by Restrict Web-Based Content
is blocked by User Training
is blocked by Network Intrusion Prevention
is blocked by Antivirus/Antimalware
is blocked by Code Signing
Impressum Deutsch Englisch