If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1221 - Template Injection, Technique .

site address: attack.mitre.org/techniques/T1221 redirected to: attack.mitre.org/techniques/T1221

site title: Template Injection, Technique T1221 - Enterprise MITRE ATT&CK®

Our opinion (on Friday 28 August 2026 6:59:25 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

template, injection, procedure, examples, mitigations, detection, strategy, references,

Text of the page (most frequently used words):
retrieved (30), the (28), #template (24), malicious (24), and (19), 2018 (18), may (14), document (14), documents (14), used (13), injection (13), file (11), att (10), all (10), microsoft (10), july (10), 2021 (10), word (10), 2020 (9), rtf (9), techniques (8), office (8), gamaredon (8), group (8), remote (8), enterprise (7), files (7), with (7), from (7), 2022 (7), payloads (7), has (7), november (6), december (6), february (6), for (6), templates (6), that (6), authentication (6), ics (5), mobile (5), none (5), detection (5), october (5), june (5), open (5), into (5), docx (5), xml (5), can (5), via (5), 2026 (4), mitre (4), are (4), reference (4), enable (4), macros (4), operation (4), campaign (4), april (4), apt (4), threat (4), technique (4), executing (4), references (4), network (4), embedded (4), this (4), forced (4), version (4), adversaries (4), code (4), use (3), resources (3), campaigns (3), cti (3), data (3), mitigations (3), defenses (3), sub (3), september (3), tropic (3), trooper (3), august (3), dream (3), job (3), 2024 (3), january (3), inception (3), targeting (3), 2019 (3), actors (3), frankenstein (3), other (3), darkhydrus (3), phishery (3), confucius (3), chaes (3), inject (3), description (3), user (3), intrusion (3), prevention (3), systems (3), antivirus (3), prevent (3), within (3), retrieve (3), download (3), also (3), urls (3), url (3), payload (3), control (3), conceal (3), loaded (3), when (3), fetched (3), properties (3), corporation (2), website (2), domains (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), disable (2), 2016 (2), targets (2), government (2), north (2), research (2), team (2), widespread (2), analysis (2), target (2), ukraine (2), cert (2), together (2), source (2), march (2), critical (2), infrastructure (2), falcone (2), rat (2), novel (2), malware (2), 2017 (2), credential (2), raggi (2), decoy (2), through (2), wiltse (2), formats (2), dotm (2), windows (2), analytic (2), name (2), spearphishing (2), host (2), detonation (2), chambers (2), employed (2), fetching (2), content (2), been (2), warzonerat (2), delivered (2), xlsx (2), was (2), xls (2), during (2), mirrorface (2), load (2), present (2), compromised (2), injected (2), smb (2), dragonfly (2), then (2), weaponized (2), exploit (2), field (2), macro (2), apt28 (2), examples (2), t1221 (2), modify (2), resource (2), these (2), executed (2), detections (2), containing (2), shared (2), parts (2), example (2), ooxml (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, changelog, privacy, policy, terms, contact, reset, filters, ray, taiwanese, fossil, fuel, provider, poison, ivy, cashman, star, clearsky, korean, espionage, itochu, endless, struggle, against, apt10, insights, lodeinfo, lancaster, attackers, europe, year, old, vulnerability, rusnák, cyberespionage, way, toolset, spy, 2023, secureworks, ctu, iron, tilden, unit, russia, aka, primitive, bear, actively, intelligence, center, actinium, ukrainian, organizations, infection, dropper, entry, boutin, grows, its, game, kakara, maruyama, covid, lure, adamitis, alive, cobble, pieces, monstrous, alert, ta18, 074a, russian, cyber, activity, energy, sectors, uses, harvest, credentials, middle, east, uptycs, deploys, warzone, salem, latin, american, commerce, lee, dear, joohn, sofacy, global, hanson, baird, attack, leverages, intel_acquisition_team, harvesting, delivery, using, pedrero, decoding, new, black, poised, adoption, beyond, segura, delivers, hawkins, attacks, bypassing, security, controls, living, off, land, 2014, introducing, 2007, viewer, processes, winword, exe, initiating, connections, scripts, due, manipulated, followed, suspicious, child, process, creation, powershell, an1564, det0566, strategy, train, users, identify, social, engineering, emails, could, deliver, training, m1017, m1031, consider, disabling, active, execution, though, setting, not, mitigate, remove, feature, program, m1042, antimalware, m1049, mitigation, install, dll, s0670, extension, typically, openxml, but, itself, actually, ole, g0081, lazarus, c0022, g1054, http, g0100, dot, already, g0047, trojanized, adversary, controlled, c0001, attachments, initiate, g0035, tool, sent, them, victims, g0079, g0142, changed, settings, populated, downloaded, next, s0631, abusing, function, g0007, procedure, live, permalink, last, modified, created, brian, evalstrings, michael, artaggi, patrick, campbell, pjcampbe11, contributors, platforms, stealth, tactic, injecting, https, prompting, triggering, attempt, similarly, legitimate, value, intended, destination, opened, however, alter, bytes, existing, insert, include, abuse, initially, such, evade, static, since, typical, indicators, vba, script, etc, until, after, have, seen, wild, where, taint, phishing, public, accessed, online, serving, pre, formatted, blueprint, create, force, attempts, specification, defines, based, format, pptx, replace, older, binary, doc, ppt, packed, zip, archives, various, referred, collectively, define, how, rendered, home, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, get, started,


Text of the page (random words):
template injection technique t1221 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise template injection template injection adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts for example microsoft s office open xml ooxml specification defines an xml based format for office documents docx xlsx pptx to replace older binary formats doc xls ppt ooxml files are packed together zip archives compromised of various xml files referred to as parts containing properties that collectively define how a document is rendered 1 properties within parts may reference shared public resources accessed via online urls for example template properties may reference a file serving as a pre formatted document blueprint that is fetched when the document is loaded adversaries may abuse these templates to initially conceal malicious code to be executed via user documents template references injected into a document may enable malicious payloads to be fetched and executed when the document is loaded 2 these documents can be delivered via other techniques such as phishing and or taint shared content and may evade static detections since no typical indicators vba macro script etc are present until after the malicious payload is fetched 3 examples have been seen in the wild where template injection was used to load malicious code containing an exploit 4 adversaries may also modify the template control word within an rtf file to similarly conceal then download malicious code this legitimate control word value is intended to be a file destination of a template file resource that is retrieved and loaded when an rtf file is opened however adversaries may alter the bytes of an existing rtf file to insert a template control word field to include a url resource of a malicious payload 5 6 this technique may also enable forced authentication by injecting a smb https or other credential prompting url and triggering an authentication attempt 7 8 9 id t1221 sub techniques no sub techniques ⓘ tactic stealth ⓘ platforms windows contributors brian wiltse evalstrings michael raggi artaggi patrick campbell pjcampbe11 version 2 0 created 17 october 2018 last modified 12 may 2026 version permalink live version procedure examples id name description g0007 apt28 apt28 used weaponized microsoft word documents abusing the remote template function to retrieve a malicious macro 10 s0631 chaes chaes changed the template target of the settings xml file embedded in the word document and populated that field with the downloaded url of the next payload 11 g0142 confucius confucius has used a weaponized microsoft word document with an embedded rtf exploit 12 g0079 darkhydrus darkhydrus used an open source tool phishery to inject malicious remote template urls into microsoft word documents and then sent them to victims to enable forced authentication 13 g0035 dragonfly dragonfly has injected smb urls into malicious word spearphishing attachments to initiate forced authentication 14 c0001 frankenstein during frankenstein the threat actors used trojanized documents that retrieved remote templates from an adversary controlled website 15 g0047 gamaredon group gamaredon group has used docx files to download malicious dot document templates and has used rtf template injection to download malicious payloads 5 gamaredon group can also inject malicious macros or remote templates into documents already present on compromised systems 16 17 18 19 20 21 22 g0100 inception inception has used decoy documents to load malicious remote payloads via http 23 g1054 mirrorface mirrorface has used remote template injection to retrieve malicious payloads from the c2 24 c0022 operation dream job during operation dream job lazarus group used docx files to retrieve a malicious document template dotm file 25 26 g0081 tropic trooper tropic trooper delivered malicious documents with the xlsx extension typically used by openxml documents but the file itself was actually an ole xls document 27 s0670 warzonerat warzonerat has been install via template injection through a malicious dll embedded within a template rtf in a word document 12 mitigations id mitigation description m1049 antivirus antimalware network host intrusion prevention systems antivirus and detonation chambers can be employed to prevent documents from fetching and or executing malicious payloads 7 m1042 disable or remove feature or program consider disabling microsoft office macros active content to prevent the execution of malicious payloads in documents 28 though this setting may not mitigate the forced authentication use for this technique m1031 network intrusion prevention network host intrusion prevention systems antivirus and detonation chambers can be employed to prevent documents from fetching and or executing malicious payloads 7 m1017 user training train users to identify social engineering techniques and spearphishing emails that could be used to deliver malicious documents detection strategy id name analytic id analytic description det0566 template injection detection windows an1564 detection of office or document viewer processes e g winword exe initiating network connections to remote templates or executing scripts due to manipulated template references e g embedded in docx rtf or dotm files followed by suspicious child process creation e g powershell references microsoft 2014 july 9 introducing the office 2007 open xml file formats retrieved july 20 2018 wiltse b 2018 november 7 template injection attacks bypassing security controls by living off the land retrieved april 10 2019 hawkins j 2018 july 18 executing macros from a docx with remote template injection retrieved october 12 2018 segura j 2017 october 13 decoy microsoft word document delivers malware through a rat retrieved july 21 2018 raggi m 2021 december 1 injection is the new black novel rtf template inject technique poised for widespread adoption beyond apt actors retrieved december 9 2021 pedrero r 2021 july decoding malicious rtf files retrieved november 16 2021 intel_acquisition_team 2018 march 1 credential harvesting and malicious file delivery using microsoft office template injection retrieved july 20 2018 baird s et al 2017 july 7 attack on critical infrastructure leverages template injection retrieved july 21 2018 hanson r 2016 september 24 phishery retrieved july 21 2018 lee b falcone r 2018 december 12 dear joohn the sofacy group s global campaign retrieved april 19 2019 salem e 2020 november 17 chaes novel malware targeting latin american e commerce retrieved june 30 2021 uptycs threat research team 2021 january 12 confucius apt deploys warzone rat retrieved december 17 2021 falcone r 2018 august 07 darkhydrus uses phishery to harvest credentials in the middle east retrieved august 10 2018 us cert 2018 march 16 alert ta18 074a russian government cyber activity targeting energy and other critical infrastructure sectors retrieved june 6 2018 adamitis d et al 2019 june 4 it s alive threat actors cobble together open source pieces into monstrous frankenstein campaign retrieved may 11 2020 kakara h maruyama e 2020 april 17 gamaredon apt group use covid 19 lure in campaigns retrieved may 19 2020 boutin j 2020 june 11 gamaredon group grows its game retrieved june 16 2020 cert ee 2021 january 27 gamaredon infection from dropper to entry retrieved february 17 2022 microsoft threat intelligence center 2022 february 4 actinium targets ukrainian organizations retrieved february 18 2022 unit 42 2022 february 3 russia s gamaredon aka primitive bear apt group actively targeting ukraine retrieved february 21 2022 secureworks ctu n d iron tilden retrieved february 24 2022 rusnák z 2024 september 26 cyberespionage the gamaredon way analysis of toolset used to spy on ukraine in 2022 and 2023 retrieved october 30 2024 lancaster t 2018 november 5 inception attackers target europe with year old office vulnerability retrieved may 8 2020 itochu 2024 january 24 the endless struggle against apt10 insights from lodeinfo v0 6 6 v0 7 3 analysis retrieved april 17 2026 clearsky research team 2020 august 13 operation dream job widespread north korean espionage campaign retrieved december 20 2021 cashman m 2020 july 29 operation north star campaign retrieved december 20 2021 ray v 2016 november 22 tropic trooper targets taiwanese government and fossil fuel provider with poison ivy retrieved november 9 2018 microsoft n d enable or disable macros in office files retrieved september 13 2018 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 64 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-64


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1221
X-GitHub-Request-Id E93A:0A11:E6771:F4D13:6A9131CC
x-github-edge-region uksouth
Accept-Ranges bytes
Age 0
Date Fri, 28 Aug 2026 06:59:24 GMT
Via 1.1 varnish
X-Served-By cache-lcy-egml8630088-LCY
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787900365.755037,VS0,VE83
Vary Accept-Encoding
X-Fastly-Request-ID 86c47445155f9ec8ad39ad1cde6ecba59dbc7fa5
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1221/
access-control-allow-origin *
expires Fri, 28 Aug 2026 07:09:24 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id BAAA:39DB2D:24B53D2:250A64A:6A9131CC
x-github-edge-region fra
accept-ranges bytes
age 0
date Fri, 28 Aug 2026 06:59:24 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290043-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787900365.863996,VS0,VE103
vary Accept-Encoding
x-fastly-request-id ffb35d3df4ef1d98ceed42a562edc0e618f8cc3b
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:21 GMT
access-control-allow-origin *
etag W/ 6a75ea95-12660
expires Fri, 28 Aug 2026 07:09:25 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 105A:39DB2D:24B53FC:250A676:6A9131CC
x-github-edge-region fra
accept-ranges bytes
age 0
date Fri, 28 Aug 2026 06:59:25 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290043-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787900365.974826,VS0,VE111
vary Accept-Encoding
x-fastly-request-id 663612de2c238e1eadb53055f823303a5304fb95
content-length 12234

Meta Tags

title="Template Injection, Technique T1221 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size12234
load time (s)0.602649
redirect count2
speed download20322
server IP 185.199.111.153
* all occurrences of the string "http://" have been changed to "htt???/"