T1204.001: Malicious Link
An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Link. Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via Exploitation for Client Execution. Links may also lead users to download files that require execution via Malicious File.
Security context for executives and security teams
Malicious Link is a user-execution behavior: the attacker’s plan depends on a person clicking a link that can lead to code execution, a browser or application exploit, or a downloaded file that later runs. For leaders, the business issue is not just phishing awareness; it is whether the organization can connect the click to suspicious outbound traffic, downloads, endpoint changes, and follow-on activity quickly enough to contain an incident.
Executive priority
Prioritize this technique as a resilience and readiness test for email, web, endpoint, and incident response controls across Windows, macOS, and Linux environments. ATT&CK relationships show use by many campaigns and groups, including campaigns involving government, energy, oil and gas, defense, hospitality, education, and other sectors, so risk owners should ask whether high-value users and operationally sensitive teams receive extra protection, reporting paths, and investigation support. Compliance and audit evidence should show not only user training, but also URL/content restrictions, network prevention, and telemetry retention sufficient to reconstruct a click-to-execution chain.
Technical view
MITRE provides no official detection text for T1204.001, so validation should be built around the related detection strategy DET0066: user click, suspicious egress, download or file write, and follow-on activity. SOC teams should confirm they can correlate web or email link interaction with DNS/proxy/network events, browser or application behavior, downloaded artifacts, endpoint process execution, and any subsequent suspicious activity. Because the technique is execution-focused and often follows Spearphishing Link or leads to Exploitation for Client Execution or Malicious File, investigations should avoid treating the click as the endpoint of the alert; the key question is what executed or changed after the click.
Likely telemetry
- Email security and message/link rewriting logs where available
- Web proxy, secure web gateway, URL filtering, and browser navigation logs
- DNS query and network egress metadata related to clicked URLs
- Network intrusion detection/prevention events at boundaries
- Endpoint telemetry for browser/application child processes, downloads, file writes, and execution
Detection direction
- Validate coverage against the click-to-egress-to-download/write-to-follow-on sequence described by DET0066.
- Tune detections to distinguish routine browsing from risky patterns such as uncommon destinations, suspicious downloads, unexpected browser-spawned processes, or activity shortly after a reported phishing message.
- Correlate with related behaviors: Spearphishing Link as a likely precursor, Exploitation for Client Execution when a browser/application vulnerability is involved, and Malicious File when the link delivers a file requiring execution.
- Account for blind spots where encrypted web traffic, unmanaged browsers, personal email, short-lived URLs, or limited endpoint logging prevent reconstruction of the chain.
- Use campaign and group relationships as threat-intelligence context for prioritization, not as proof of local targeting or active exploitation.
Mitigation priorities
- Start with M1017 User Training focused on recognizing and reporting social engineering that asks users to click links, with special attention to high-risk roles and contractors.
- Implement M1021 Restrict Web-Based Content through policy-based URL filtering, unsafe download restrictions, script or extension controls where appropriate, and consistent enforcement across supported platforms.
- Use M1031 Network Intrusion Prevention to block known malicious or policy-violating traffic at network boundaries where signatures or rules are available.
- Pair preventive controls with incident-response playbooks that preserve the clicked URL, user, device, downloaded content, and follow-on activity for triage.
Additional notes and limits
This object is a sub-technique of T1204 User Execution and applies to Linux, macOS, and Windows. The relationship set is broad, including multiple named campaigns and groups, which supports treating malicious links as a common operational pathway rather than a niche behavior. Some campaign descriptions include energy, oil and gas, petrochemical, SCADA-related, defense, government, education, hospitality, and private-sector contexts, making this relevant to both enterprise and cyber-physical risk discussions where those environments exist.
MITRE does not provide official detection guidance for this object, so detection recommendations rely on the supplied DET0066 relationship and the official technique description. The supplied data does not prove current activity, attribution against any specific organization, exploitability of a specific vulnerability, or guaranteed detection coverage. Local telemetry, control configuration, user population, and incident history are required to assess exposure.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Malicious Link
An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Link. Clicking on a link may also lead to other execution techniques such as exploitation of a browser or application vulnerability via Exploitation for Client Execution. Links may also lead users to download files that require execution via Malicious File.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
