ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.005×

69 examples

TechniqueUsed byProcedure example
T1059.005
Visual Basic
MalwareBumblebee

Bumblebee can create a Visual Basic script to enable persistence.

T1059.005
Visual Basic
MalwareExaramel for Windows

Exaramel for Windows has a command to execute VBS scripts on the victim’s machine.

T1059.005
Visual Basic
MalwareSmoke Loader

Smoke Loader adds a Visual Basic script in the Startup folder to deploy the payload.

T1059.005
Visual Basic
MalwareTAMECAT

TAMECAT has used VBScript to query anti-virus products.

T1059.005
Visual Basic
MalwareUrsnif

Ursnif droppers have used VBA macros to download and execute the malware's full executable payload.

T1059.005
Visual Basic
MalwareNETWIRE

NETWIRE has been executed through use of VBScripts.

T1059.005
Visual Basic
MalwareEmotet

Emotet has sent Microsoft Word documents with embedded macros that will invoke scripts to download additional payloads.

T1059.005
Visual Basic
MalwareSystemBC

SystemBC has leveraged VBScript to execute malicious code.

T1059.005
Visual Basic
MalwareSquirrelwaffle

Squirrelwaffle has used malicious VBA macros in Microsoft Word documents and Excel spreadsheets that execute an `AutoOpen` subroutine.

T1059.005
Visual Basic
MalwareShrinkLocker

ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution.

T1059.005
Visual Basic
MalwareSnip3

Snip3 can use visual basic scripts for first-stage execution.

T1059.005
Visual Basic
MalwareWhisperGate

WhisperGate can use a Visual Basic script to exclude the `C:\` drive from Windows Defender.

T1059.005
Visual Basic
MalwareMispadu

Mispadu’s dropper uses VBS files to install payloads and perform execution.

T1059.005
Visual Basic
MalwareIcedID

IcedID has used obfuscated VBA string expressions.

T1059.005
Visual Basic
MalwarePowerShower

PowerShower has the ability to save and execute VBScript.

T1059.005
Visual Basic
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts.

T1059.005
Visual Basic
MalwareFlagpro

Flagpro can execute malicious VBA macros embedded in .xlsm files.

T1059.005
Visual Basic
MalwareKeyBoy

KeyBoy uses VBS scripts for installing files and performing execution.

T1059.005
Visual Basic
MalwarePteranodon

Pteranodon can use a malicious VBS file for execution.

T1059.005
Visual Basic
MalwareROKRAT

ROKRAT has used Visual Basic for execution.

T1059.005
Visual Basic
MalwareJavali

Javali has used embedded VBScript to download malicious payloads from C2.

T1059.005
Visual Basic
MalwareBisonal

Bisonal's dropper creates VBS scripts on the victim’s machine.

T1059.005
Visual Basic
MalwareXbash

Xbash can execute malicious VBScript payloads on the victim’s machine.

T1059.005
Visual Basic
MalwareDarkGate

DarkGate initial infection mechanisms include masquerading as pirated media that launches malicious VBScript on the victim.

T1059.005
Visual Basic
MalwareNanHaiShu

NanHaiShu executes additional VBScript code on the victim's machine.

T1059.005
Visual Basic
MalwareSVCReady

SVCReady has used VBA macros to execute shellcode.

T1059.005
Visual Basic
MalwareFerocious

Ferocious has the ability to use Visual Basic scripts for execution.

T1059.005
Visual Basic
MalwareSaint Bot

Saint Bot has used `.vbs` scripts for execution.

T1059.005
Visual Basic
MalwareChaes

Chaes has used VBscript to execute malicious code.

T1059.005
Visual Basic
MalwareTYPEFRAME

TYPEFRAME has used a malicious Word document for delivery with VBA macros for execution.

T1059.005
Visual Basic
MalwareQUADAGENT

QUADAGENT uses VBScripts.

T1059.005
Visual Basic
MalwareMetamorfo

Metamorfo has used VBS code on victims’ systems.

T1059.005
Visual Basic
MalwareBandook

Bandook has used malicious VBA code against the target system.

T1059.005
Visual Basic
MalwareKerrdown

Kerrdown can use a VBS base64 decoder function published by Motobit.

T1059.005
Visual Basic
MalwareVBShower

VBShower has the ability to execute VBScript files.

T1059.005
Visual Basic
MalwareStoneDrill

StoneDrill has several VBS scripts used throughout the malware's lifecycle.

T1059.005
Visual Basic
MalwareOopsIE

OopsIE creates and uses a VBScript as part of its persistent execution.

T1059.005
Visual Basic
MalwareGrandoreiro

Grandoreiro can use VBScript to execute malicious code.

T1059.005
Visual Basic
MalwareSibot

Sibot executes commands using VBScript.

T1059.005
Visual Basic
MalwareLunarMail

LunarMail has been installed using a VBA macro.

T1059.005
Visual Basic
MalwareCobalt Strike

Cobalt Strike can use VBA to perform execution.

T1059.005
Visual Basic
MalwareSUNBURST

SUNBURST used VBScripts to initiate the execution of payloads.

T1059.005
Visual Basic
MalwareJCry

JCry has used VBS scripts.

T1059.005
Visual Basic
MalwareREvil

REvil has used obfuscated VBA macros for execution.

T1059.005
Visual Basic
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses Word macros for execution.

T1059.005
Visual Basic
MalwareNanoCore

NanoCore uses VBS files.

T1059.005
Visual Basic
MalwareIPsec Helper

IPsec Helper can run arbitrary Visual Basic scripts and commands passed to it.

T1059.005
Visual Basic
MalwareDanBot

DanBot can use a VBA macro embedded in an Excel file to drop the payload.

T1059.005
Visual Basic
MalwareRamsay

Ramsay has included embedded Visual Basic scripts in malicious documents.

T1059.005
Visual Basic
MalwareBackConfig

BackConfig has used VBS to install its downloader component and malicious documents with VBA macro code.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.