ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.003×

73 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
GroupAPT38

APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts.

T1059.003
Windows Command Shell
GroupIndrik Spider

Indrik Spider has used batch scripts on victim's machines.

T1059.003
Windows Command Shell
GroupBlackByte

BlackByte executed ransomware using the Windows command shell.

T1059.003
Windows Command Shell
GroupGALLIUM

GALLIUM used the Windows command shell to execute commands.

T1059.003
Windows Command Shell
GroupAPT3

An APT3 downloader uses the Windows command "cmd.exe" /C whoami. The group also uses a tool to execute commands on remote computers.

T1059.003
Windows Command Shell
GroupKimsuky

Kimsuky has executed Windows commands by using `cmd` and running batch scripts. Kimsuky has also used `cmd.exe` to automatically open downloaded decoy pdf documents with the system’s default PDF viewer. Kimsuky has utilized malicious payloads to create reverse shells within the victim environment. Kimsuky has also used batch scripts to eventually run QuasarRAT.

T1059.003
Windows Command Shell
GroupTA577

TA577 has used BAT files in malware execution chains.

T1059.003
Windows Command Shell
Groupadmin@338

Following exploitation with LOWBALL malware, admin@338 actors created a file containing a list of commands to be executed on the compromised computer.

T1059.003
Windows Command Shell
GroupVolt Typhoon

Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery.

T1059.003
Windows Command Shell
GroupPatchwork

Patchwork ran a reverse shell with Meterpreter. Patchwork used JavaScript code and .SCT files on victim machines.

T1059.003
Windows Command Shell
GroupAPT41

APT41 used cmd.exe /c to execute commands on remote machines.
APT41 used a batch file to install persistence for the Cobalt Strike BEACON loader.

T1059.003
Windows Command Shell
GroupDragonfly

Dragonfly has used various types of scripting to perform operations, including batch scripts.

T1059.003
Windows Command Shell
GroupGorgon Group

Gorgon Group malware can use cmd.exe to download and execute payloads and to execute commands on the system.

T1059.003
Windows Command Shell
GroupmenuPass

menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files.

T1059.003
Windows Command Shell
GroupAPT32

APT32 has used cmd.exe for execution.

T1059.003
Windows Command Shell
GroupHAFNIUM

HAFNIUM has used `cmd.exe` to execute commands on the victim's machine.

T1059.003
Windows Command Shell
GroupMuddyWater

MuddyWater has used a custom tool for creating reverse shells.

T1059.003
Windows Command Shell
GroupFIN6

FIN6 has used kill.bat script to disable security tools.

T1059.003
Windows Command Shell
GroupGamaredon Group

Gamaredon Group has used various batch scripts to establish C2 and download additional files. Gamaredon Group's backdoor malware has also been written to a batch file.

T1059.003
Windows Command Shell
GroupStorm-1811

Storm-1811 has used multiple batch scripts during initial access and subsequent actions on victim machines.

T1059.003
Windows Command Shell
GroupTeamTNT

TeamTNT has used batch scripts to download tools and executing cryptocurrency miners.

T1059.003
Windows Command Shell
GroupFIN7

FIN7 used the command prompt to launch commands on the victim’s machine. Additionally, FIN7 has used cmd.exe to open the Run dialog by sending the “Windows + R” keys through malicious USBs acting as virtual keyboards.

T1059.003
Windows Command Shell
GroupMachete

Machete has used batch files to initiate additional downloads of malicious files.

T1059.003
Windows Command Shell
GroupAPT18

APT18 uses cmd.exe to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
GroupMustang Panda

Mustang Panda has executed HTA files via cmd.exe, and used batch scripts for collection. Mustang Panda has also utilized cmd.exe to execute commands on an infected host such as `cmd.exe /c ping.exe 8.8.8.8 -n 70&&"%temp%\FontEDL.exe"`.

T1059.003
Windows Command Shell
GroupZIRCONIUM

ZIRCONIUM has used a tool to open a Windows Command Shell on a remote host.

T1059.003
Windows Command Shell
GroupUNC3886

UNC3886 has executed Windows commands on guest virtual machines through `vmtoolsd.exe`.

T1059.003
Windows Command Shell
GroupContagious Interview

Contagious Interview has utilized VBS scripts to open cmd.exe and run commands to include the go_batch.bat batch file.

T1059.003
Windows Command Shell
GroupAPT37

APT37 has used the command-line interface.

T1059.003
Windows Command Shell
GroupOilRig

OilRig has used macros to deliver malware such as QUADAGENT and OopsIE. OilRig has used batch scripts.

T1059.003
Windows Command Shell
GroupHigaisa

Higaisa used cmd.exe for execution.

T1059.003
Windows Command Shell
GroupTropic Trooper

Tropic Trooper has used Windows command scripts.

T1059.003
Windows Command Shell
GroupSuckfly

Several tools used by Suckfly have been command-line driven.

T1059.003
Windows Command Shell
GroupAquatic Panda

Aquatic Panda has attempted and failed to run Bash commands on a Windows host by passing them to cmd /C.

T1059.003
Windows Command Shell
GroupKe3chang

Ke3chang has used batch scripts in its malware to install persistence mechanisms.

T1059.003
Windows Command Shell
GroupSaint Bear

Saint Bear initial loaders will also drop a malicious Windows batch file, available via open source GitHub repositories, that disables Microsoft Defender functionality.

T1059.003
Windows Command Shell
GroupAPT1

APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution.

T1059.003
Windows Command Shell
GroupBlue Mockingbird

Blue Mockingbird has used batch script files to automate execution and deployment of payloads.

T1059.003
Windows Command Shell
GroupWinter Vivern

Winter Vivern distributed Windows batch scripts disguised as virus scanners to prompt download of malicious payloads using built-in system tools.

T1059.003
Windows Command Shell
GroupTurla

Turla RPC backdoors have used cmd.exe to execute commands.

T1059.003
Windows Command Shell
GroupTA505

TA505 has executed commands using cmd.exe.

T1059.003
Windows Command Shell
GroupRedCurl

RedCurl has used the Windows Command Prompt to execute commands.

T1059.003
Windows Command Shell
GroupDark Caracal

Dark Caracal has used macros in Word documents that would download a second stage if executed.

T1059.003
Windows Command Shell
GroupCinnamon Tempest

Cinnamon Tempest has executed ransomware using batch scripts deployed via GPO.

T1059.003
Windows Command Shell
GroupChimera

Chimera has used the Windows Command Shell and batch scripts for execution on compromised hosts.

T1059.003
Windows Command Shell
GroupMirrorFace

MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation.

T1059.003
Windows Command Shell
GroupMedusa Group

Medusa Group has used Windows Command Prompt to control and execute commands on the system to include ingress, network, and filesystem enumeration activities.

T1059.003
Windows Command Shell
GroupBRONZE BUTLER

BRONZE BUTLER has used batch scripts and the command-line interface for execution.

T1059.003
Windows Command Shell
GroupTA551

TA551 has used cmd.exe to execute commands.

T1059.003
Windows Command Shell
GroupDarkhotel

Darkhotel has dropped an mspaint.lnk shortcut to disk which launches a shell script that downloads and executes a file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.