Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1204/T1204.001
MITRE ATT&CK Sub-Technique

T1204.001: Malicious Link

ShareXLinkedInRedditHN

An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002). Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203). Links may also lead users to download files that require execution via [Malicious File](https://attack.mitre.org/techniques/T1204/002).

Tactics
Execution
Platforms
Linux, macOS, Windows

▪Parent technique

T1204: User Execution

▪Mitigations (3)

M1031Network Intrusion Prevention

Use intrusion detection signatures to block traffic at network boundaries.

M1017User Training

User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures: Create Comprehensive Training Programs: - Design training modules tailored to the organization's risk profile, covering topics such as phishing, password management, and incident reporting. - Provide role-specific training for high-risk employees, such as helpdesk staff or executives. Use Simulated Exercises: - Conduct phishing simulations to measure user susceptibility and provide targeted follow-up training. - Run social engineering drills to evaluate employee responses and reinforce protocols. Leverage Gamification and Engagement: - Introduce interactive learning methods such as quizzes, gamified challenges, and rewards for successful detection and reporting of threats. Incorporate Security Policies into Onboarding: - Include cybersecurity training as part of the onboarding process for new employees. - Provide easy-to-understand materials outlining acceptable use policies and reporting procedures. Regular Refresher Courses: - Update training materials to include emerging threats and techniques used by adversaries. - Ensure all employees complete periodic refresher courses to stay informed. Emphasize Real-World Scenarios: - Use case studies of recent attacks to demonstrate the consequences of successful phishing or social engineering. - Discuss how specific employee actions can prevent or mitigate such attacks.

M1021Restrict Web-Based Content

Restricting web-based content involves enforcing policies and technologies that limit access to potentially malicious websites, unsafe downloads, and unauthorized browser behaviors. This can include URL filtering, download restrictions, script blocking, and extension control to protect against exploitation, phishing, and malware delivery. This mitigation can be implemented through the following measures: Deploy Web Proxy Filtering: - Use solutions to filter web traffic based on categories, reputation, and content types. - Enforce policies that block unsafe websites or file types at the gateway level. Enable DNS-Based Filtering: - Implement tools to restrict access to domains associated with malware or phishing campaigns. - Use public DNS filtering services to enhance protection. Enforce Content Security Policies (CSP): - Configure CSP headers on internal and external web applications to restrict script execution, iframe embedding, and cross-origin requests. Control Browser Features: - Disable unapproved browser features like automatic downloads, developer tools, or unsafe scripting. - Enforce policies through tools like Group Policy Management to control browser settings. Monitor and Alert on Web-Based Threats: - Use SIEM tools to collect and analyze web proxy logs for signs of anomalous or malicious activity. - Configure alerts for access attempts to blocked domains or repeated file download failures.

▪Used by groups (49)

G0007APT28G0010TurlaG0016APT29G0021MoleratsG0022APT3G0034Sandworm TeamG0040PatchworkG0046FIN7G0047Gamaredon GroupG0049OilRigG0050APT32G0059Magic HoundG0061FIN8G0064APT33G0065LeviathanG0066ElderwoodG0069MuddyWaterG0080Cobalt GroupG0082APT38G0085FIN4G0087APT39G0090WIRTEG0092TA505G0094KimsukyG0095MacheteG0098BlackTechG0099APT-C-36G0102Wizard SpiderG0103MofangG0112WindshiftG0120EvilnumG0121SidewinderG0128ZIRCONIUMG0129Mustang PandaG0134Transparent TribeG0140LazyScripterG0142ConfuciusG1006Earth LuscaG1011EXOTIC LILYG1014LuminousMothG1018TA2541G1020Mustard TempestG1031Saint BearG1034DaggerflyG1035Winter VivernG1037TA577G1038TA578G1039RedCurlG1052Contagious Interview

▪Software using this technique (29)

S0198NETWIREmalwareS0367EmotetmalwareS0435PLEADmalwareS0436TSCookiemalwareS0453PonymalwareS0475BackConfigmalwareS0499HancitormalwareS0528JavalimalwareS0530MelcozmalwareS0531GrandoreiromalwareS0534BazarmalwareS0561GuLoadermalwareS0584AppleJeusmalwareS0585KerrdownmalwareS0644ObliqueRATmalwareS0646SpicyOmelettemalwareS0649SMOKEDHAMmalwareS0650QakBotmalwareS0669KOCTOPUSmalwareS1017OutSteelmalwareS1018Saint BotmalwareS1030SquirrelwafflemalwareS1039BumblebeemalwareS1086Snip3malwareS1124SocGholishmalwareS1138GootloadermalwareS1160LatrodectusmalwareS1242QilinmalwareS9026ROAMINGHOUSEmalware

▪Reference

T1204.001on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.