Real-world descriptions of how a group, tool or campaign used a technique.
85 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
GroupAPT38 | APT38 has used PowerShell to execute commands and other operational tasks. |
| T1059.001 PowerShell |
GroupIndrik Spider | Indrik Spider has used PowerShell Empire for execution of malware. |
| T1059.001 PowerShell |
GroupBlackByte | BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks. |
| T1059.001 PowerShell |
GroupGALLIUM | GALLIUM used PowerShell for execution to assist in lateral movement as well as for dumping credentials stored on compromised machines. |
| T1059.001 PowerShell |
GroupAPT3 | APT3 has used PowerShell on victim systems to download and run payloads after exploitation. |
| T1059.001 PowerShell |
GroupKimsuky | Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT. |
| T1059.001 PowerShell |
GroupVolt Typhoon | Volt Typhoon has used PowerShell including for remote system discovery. |
| T1059.001 PowerShell |
GroupPatchwork | Patchwork used PowerSploit to download payloads, run a reverse shell, and execute malware on the victim's machine. |
| T1059.001 PowerShell |
GroupAPT41 | APT41 leveraged PowerShell to deploy malware families in victims’ environments. |
| T1059.001 PowerShell |
GroupDragonfly | Dragonfly has used PowerShell scripts for execution. |
| T1059.001 PowerShell |
GroupGorgon Group | Gorgon Group malware can use PowerShell commands to download and execute a payload and open a decoy document on the victim’s machine. |
| T1059.001 PowerShell |
GroupmenuPass | menuPass uses PowerSploit to inject shellcode into PowerShell. |
| T1059.001 PowerShell |
GroupAPT32 | APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution. |
| T1059.001 PowerShell |
GroupHAFNIUM | HAFNIUM has used the Exchange Power Shell module |
| T1059.001 PowerShell |
GroupMuddyWater | MuddyWater has used PowerShell for execution. ClearSky MuddyWater Nov 2018DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018MuddyWater TrendMicro June 2018NaumaanProofpoint_GlobalClickFix_April2025Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Symantec MuddyWater Dec 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021 |
| T1059.001 PowerShell |
GroupFIN6 | FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener. |
| T1059.001 PowerShell |
GroupGamaredon Group | Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload. |
| T1059.001 PowerShell |
GroupGallmaker | Gallmaker used PowerShell to download additional payloads and for execution. |
| T1059.001 PowerShell |
GroupStorm-1811 | Storm-1811 has used PowerShell for multiple purposes, such as using PowerShell scripts executing in an infinite loop to create an SSH connection to a command and control server. |
| T1059.001 PowerShell |
GroupTeamTNT | TeamTNT has executed PowerShell commands in batch scripts. |
| T1059.001 PowerShell |
GroupFIN7 | FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH. |
| T1059.001 PowerShell |
GroupSandworm Team | Sandworm Team has used PowerShell scripts to run a credential harvesting tool in memory to evade defenses. |
| T1059.001 PowerShell |
GroupCURIUM | CURIUM has leveraged PowerShell scripts for initial process execution and data gathering in victim environments. |
| T1059.001 PowerShell |
GroupSidewinder | Sidewinder has used PowerShell to drop and execute malware loaders. |
| T1059.001 PowerShell |
GroupMustang Panda | Mustang Panda has used malicious PowerShell scripts to enable execution. |
| T1059.001 PowerShell |
GroupScattered Spider | Scattered Spider has used the PowerShell cmdlet Get-ADUser. |
| T1059.001 PowerShell |
GroupAPT39 | APT39 has used PowerShell to execute malicious code. |
| T1059.001 PowerShell |
GroupUNC3886 | UNC3886 has used a PowerShell script to search memory dumps for credentials. |
| T1059.001 PowerShell |
GroupTA2541 | TA2541 has used PowerShell to download files and to inject into various Windows processes. |
| T1059.001 PowerShell |
GroupAkira | Akira has used PowerShell scripts for credential harvesting and privilege escalation. |
| T1059.001 PowerShell |
GroupOilRig | OilRig has used PowerShell scripts for execution, including use of a macro to run a PowerShell command to decode file contents. |
| T1059.001 PowerShell |
GroupTA459 | TA459 has used PowerShell for execution of a payload. |
| T1059.001 PowerShell |
GroupAquatic Panda | Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell. |
| T1059.001 PowerShell |
GroupSaint Bear | Saint Bear relies extensively on PowerShell execution from malicious attachments and related content to retrieve and execute follow-on payloads. |
| T1059.001 PowerShell |
GroupDarkHydrus | DarkHydrus leveraged PowerShell to download and execute additional scripts for execution. |
| T1059.001 PowerShell |
GroupConfucius | Confucius has used PowerShell to execute malicious files and payloads. |
| T1059.001 PowerShell |
GroupLeviathan | Leviathan has used PowerShell for execution. |
| T1059.001 PowerShell |
GroupMoustachedBouncer | MoustachedBouncer has used plugins to execute PowerShell scripts. |
| T1059.001 PowerShell |
GroupBlue Mockingbird | Blue Mockingbird has used PowerShell reverse TCP shells to issue interactive commands over a network connection. |
| T1059.001 PowerShell |
GroupWinter Vivern | Winter Vivern passed execution from document macros to PowerShell scripts during initial access operations. Winter Vivern used batch scripts that called PowerShell commands as part of initial access and installation operations. |
| T1059.001 PowerShell |
GroupTurla | Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject. Turla has also used PowerShell scripts to load and execute malware in memory. |
| T1059.001 PowerShell |
GroupStorm-0501 | Storm-0501 has leveraged PowerShell to execute commands and scripts. |
| T1059.001 PowerShell |
GroupPoseidon Group | The Poseidon Group's Information Gathering Tool (IGT) includes PowerShell components. |
| T1059.001 PowerShell |
GroupTA505 | TA505 has used PowerShell to download and execute malware and reconnaissance scripts. |
| T1059.001 PowerShell |
GroupDarkVishnya | DarkVishnya used PowerShell to create shellcode loaders. |
| T1059.001 PowerShell |
GroupRedCurl | RedCurl has used PowerShell to execute commands and to download malware. |
| T1059.001 PowerShell |
GroupStealth Falcon | Stealth Falcon malware uses PowerShell commands to perform various functions, including gathering system information via WMI and executing commands from its C2 server. |
| T1059.001 PowerShell |
GroupAPT29 | APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. |
| T1059.001 PowerShell |
GroupCinnamon Tempest | Cinnamon Tempest has used PowerShell to communicate with C2, download files, and execute reconnaissance commands. |
| T1059.001 PowerShell |
GroupChimera | Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.