Real-world descriptions of how a group, tool or campaign used a technique.
73 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
GroupAPT38 | APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts. |
| T1059.003 Windows Command Shell |
GroupIndrik Spider | Indrik Spider has used batch scripts on victim's machines. |
| T1059.003 Windows Command Shell |
GroupBlackByte | BlackByte executed ransomware using the Windows command shell. |
| T1059.003 Windows Command Shell |
GroupGALLIUM | GALLIUM used the Windows command shell to execute commands. |
| T1059.003 Windows Command Shell |
GroupAPT3 | An APT3 downloader uses the Windows command |
| T1059.003 Windows Command Shell |
GroupKimsuky | Kimsuky has executed Windows commands by using `cmd` and running batch scripts. Kimsuky has also used `cmd.exe` to automatically open downloaded decoy pdf documents with the system’s default PDF viewer. Kimsuky has utilized malicious payloads to create reverse shells within the victim environment. Kimsuky has also used batch scripts to eventually run QuasarRAT. |
| T1059.003 Windows Command Shell |
GroupTA577 | TA577 has used BAT files in malware execution chains. |
| T1059.003 Windows Command Shell |
Groupadmin@338 | Following exploitation with LOWBALL malware, admin@338 actors created a file containing a list of commands to be executed on the compromised computer. |
| T1059.003 Windows Command Shell |
GroupVolt Typhoon | Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery. |
| T1059.003 Windows Command Shell |
GroupPatchwork | Patchwork ran a reverse shell with Meterpreter. Patchwork used JavaScript code and .SCT files on victim machines. |
| T1059.003 Windows Command Shell |
GroupAPT41 | APT41 used |
| T1059.003 Windows Command Shell |
GroupDragonfly | Dragonfly has used various types of scripting to perform operations, including batch scripts. |
| T1059.003 Windows Command Shell |
GroupGorgon Group | Gorgon Group malware can use cmd.exe to download and execute payloads and to execute commands on the system. |
| T1059.003 Windows Command Shell |
GroupmenuPass | menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files. |
| T1059.003 Windows Command Shell |
GroupAPT32 | APT32 has used cmd.exe for execution. |
| T1059.003 Windows Command Shell |
GroupHAFNIUM | HAFNIUM has used `cmd.exe` to execute commands on the victim's machine. |
| T1059.003 Windows Command Shell |
GroupMuddyWater | MuddyWater has used a custom tool for creating reverse shells. |
| T1059.003 Windows Command Shell |
GroupFIN6 | FIN6 has used |
| T1059.003 Windows Command Shell |
GroupGamaredon Group | Gamaredon Group has used various batch scripts to establish C2 and download additional files. Gamaredon Group's backdoor malware has also been written to a batch file. |
| T1059.003 Windows Command Shell |
GroupStorm-1811 | Storm-1811 has used multiple batch scripts during initial access and subsequent actions on victim machines. |
| T1059.003 Windows Command Shell |
GroupTeamTNT | TeamTNT has used batch scripts to download tools and executing cryptocurrency miners. |
| T1059.003 Windows Command Shell |
GroupFIN7 | FIN7 used the command prompt to launch commands on the victim’s machine. Additionally, FIN7 has used cmd.exe to open the Run dialog by sending the “Windows + R” keys through malicious USBs acting as virtual keyboards. |
| T1059.003 Windows Command Shell |
GroupMachete | Machete has used batch files to initiate additional downloads of malicious files. |
| T1059.003 Windows Command Shell |
GroupAPT18 | APT18 uses cmd.exe to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
GroupMustang Panda | Mustang Panda has executed HTA files via cmd.exe, and used batch scripts for collection. Mustang Panda has also utilized cmd.exe to execute commands on an infected host such as `cmd.exe /c ping.exe 8.8.8.8 -n 70&&"%temp%\FontEDL.exe"`. |
| T1059.003 Windows Command Shell |
GroupZIRCONIUM | ZIRCONIUM has used a tool to open a Windows Command Shell on a remote host. |
| T1059.003 Windows Command Shell |
GroupUNC3886 | UNC3886 has executed Windows commands on guest virtual machines through `vmtoolsd.exe`. |
| T1059.003 Windows Command Shell |
GroupContagious Interview | Contagious Interview has utilized VBS scripts to open cmd.exe and run commands to include the go_batch.bat batch file. |
| T1059.003 Windows Command Shell |
GroupAPT37 | APT37 has used the command-line interface. |
| T1059.003 Windows Command Shell |
GroupOilRig | OilRig has used macros to deliver malware such as QUADAGENT and OopsIE. OilRig has used batch scripts. |
| T1059.003 Windows Command Shell |
GroupHigaisa | Higaisa used |
| T1059.003 Windows Command Shell |
GroupTropic Trooper | Tropic Trooper has used Windows command scripts. |
| T1059.003 Windows Command Shell |
GroupSuckfly | Several tools used by Suckfly have been command-line driven. |
| T1059.003 Windows Command Shell |
GroupAquatic Panda | Aquatic Panda has attempted and failed to run Bash commands on a Windows host by passing them to |
| T1059.003 Windows Command Shell |
GroupKe3chang | Ke3chang has used batch scripts in its malware to install persistence mechanisms. |
| T1059.003 Windows Command Shell |
GroupSaint Bear | Saint Bear initial loaders will also drop a malicious Windows batch file, available via open source GitHub repositories, that disables Microsoft Defender functionality. |
| T1059.003 Windows Command Shell |
GroupAPT1 | APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. |
| T1059.003 Windows Command Shell |
GroupBlue Mockingbird | Blue Mockingbird has used batch script files to automate execution and deployment of payloads. |
| T1059.003 Windows Command Shell |
GroupWinter Vivern | Winter Vivern distributed Windows batch scripts disguised as virus scanners to prompt download of malicious payloads using built-in system tools. |
| T1059.003 Windows Command Shell |
GroupTurla | Turla RPC backdoors have used cmd.exe to execute commands. |
| T1059.003 Windows Command Shell |
GroupTA505 | TA505 has executed commands using |
| T1059.003 Windows Command Shell |
GroupRedCurl | RedCurl has used the Windows Command Prompt to execute commands. |
| T1059.003 Windows Command Shell |
GroupDark Caracal | Dark Caracal has used macros in Word documents that would download a second stage if executed. |
| T1059.003 Windows Command Shell |
GroupCinnamon Tempest | Cinnamon Tempest has executed ransomware using batch scripts deployed via GPO. |
| T1059.003 Windows Command Shell |
GroupChimera | Chimera has used the Windows Command Shell and batch scripts for execution on compromised hosts. |
| T1059.003 Windows Command Shell |
GroupMirrorFace | MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation. |
| T1059.003 Windows Command Shell |
GroupMedusa Group | Medusa Group has used Windows Command Prompt to control and execute commands on the system to include ingress, network, and filesystem enumeration activities. |
| T1059.003 Windows Command Shell |
GroupBRONZE BUTLER | BRONZE BUTLER has used batch scripts and the command-line interface for execution. |
| T1059.003 Windows Command Shell |
GroupTA551 | TA551 has used |
| T1059.003 Windows Command Shell |
GroupDarkhotel | Darkhotel has dropped an mspaint.lnk shortcut to disk which launches a shell script that downloads and executes a file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.