Real-world descriptions of how a group, tool or campaign used a technique.
69 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.005 Visual Basic |
MalwareBumblebee | Bumblebee can create a Visual Basic script to enable persistence. |
| T1059.005 Visual Basic |
MalwareExaramel for Windows | Exaramel for Windows has a command to execute VBS scripts on the victim’s machine. |
| T1059.005 Visual Basic |
MalwareSmoke Loader | Smoke Loader adds a Visual Basic script in the Startup folder to deploy the payload. |
| T1059.005 Visual Basic |
MalwareTAMECAT | TAMECAT has used VBScript to query anti-virus products. |
| T1059.005 Visual Basic |
MalwareUrsnif | Ursnif droppers have used VBA macros to download and execute the malware's full executable payload. |
| T1059.005 Visual Basic |
MalwareNETWIRE | NETWIRE has been executed through use of VBScripts. |
| T1059.005 Visual Basic |
MalwareEmotet | Emotet has sent Microsoft Word documents with embedded macros that will invoke scripts to download additional payloads. |
| T1059.005 Visual Basic |
MalwareSystemBC | SystemBC has leveraged VBScript to execute malicious code. |
| T1059.005 Visual Basic |
MalwareSquirrelwaffle | Squirrelwaffle has used malicious VBA macros in Microsoft Word documents and Excel spreadsheets that execute an `AutoOpen` subroutine. |
| T1059.005 Visual Basic |
MalwareShrinkLocker | ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution. |
| T1059.005 Visual Basic |
MalwareSnip3 | Snip3 can use visual basic scripts for first-stage execution. |
| T1059.005 Visual Basic |
MalwareWhisperGate | WhisperGate can use a Visual Basic script to exclude the `C:\` drive from Windows Defender. |
| T1059.005 Visual Basic |
MalwareMispadu | Mispadu’s dropper uses VBS files to install payloads and perform execution. |
| T1059.005 Visual Basic |
MalwareIcedID | IcedID has used obfuscated VBA string expressions. |
| T1059.005 Visual Basic |
MalwarePowerShower | PowerShower has the ability to save and execute VBScript. |
| T1059.005 Visual Basic |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts. |
| T1059.005 Visual Basic |
MalwareFlagpro | Flagpro can execute malicious VBA macros embedded in .xlsm files. |
| T1059.005 Visual Basic |
MalwareKeyBoy | KeyBoy uses VBS scripts for installing files and performing execution. |
| T1059.005 Visual Basic |
MalwarePteranodon | Pteranodon can use a malicious VBS file for execution. |
| T1059.005 Visual Basic |
MalwareROKRAT | ROKRAT has used Visual Basic for execution. |
| T1059.005 Visual Basic |
MalwareJavali | Javali has used embedded VBScript to download malicious payloads from C2. |
| T1059.005 Visual Basic |
MalwareBisonal | Bisonal's dropper creates VBS scripts on the victim’s machine. |
| T1059.005 Visual Basic |
MalwareXbash | Xbash can execute malicious VBScript payloads on the victim’s machine. |
| T1059.005 Visual Basic |
MalwareDarkGate | DarkGate initial infection mechanisms include masquerading as pirated media that launches malicious VBScript on the victim. |
| T1059.005 Visual Basic |
MalwareNanHaiShu | NanHaiShu executes additional VBScript code on the victim's machine. |
| T1059.005 Visual Basic |
MalwareSVCReady | SVCReady has used VBA macros to execute shellcode. |
| T1059.005 Visual Basic |
MalwareFerocious | Ferocious has the ability to use Visual Basic scripts for execution. |
| T1059.005 Visual Basic |
MalwareSaint Bot | Saint Bot has used `.vbs` scripts for execution. |
| T1059.005 Visual Basic |
MalwareChaes | Chaes has used VBscript to execute malicious code. |
| T1059.005 Visual Basic |
MalwareTYPEFRAME | TYPEFRAME has used a malicious Word document for delivery with VBA macros for execution. |
| T1059.005 Visual Basic |
MalwareQUADAGENT | QUADAGENT uses VBScripts. |
| T1059.005 Visual Basic |
MalwareMetamorfo | Metamorfo has used VBS code on victims’ systems. |
| T1059.005 Visual Basic |
MalwareBandook | Bandook has used malicious VBA code against the target system. |
| T1059.005 Visual Basic |
MalwareKerrdown | Kerrdown can use a VBS base64 decoder function published by Motobit. |
| T1059.005 Visual Basic |
MalwareVBShower | VBShower has the ability to execute VBScript files. |
| T1059.005 Visual Basic |
MalwareStoneDrill | StoneDrill has several VBS scripts used throughout the malware's lifecycle. |
| T1059.005 Visual Basic |
MalwareOopsIE | OopsIE creates and uses a VBScript as part of its persistent execution. |
| T1059.005 Visual Basic |
MalwareGrandoreiro | Grandoreiro can use VBScript to execute malicious code. |
| T1059.005 Visual Basic |
MalwareSibot | Sibot executes commands using VBScript. |
| T1059.005 Visual Basic |
MalwareLunarMail | LunarMail has been installed using a VBA macro. |
| T1059.005 Visual Basic |
MalwareCobalt Strike | Cobalt Strike can use VBA to perform execution. |
| T1059.005 Visual Basic |
MalwareSUNBURST | SUNBURST used VBScripts to initiate the execution of payloads. |
| T1059.005 Visual Basic |
MalwareJCry | JCry has used VBS scripts. |
| T1059.005 Visual Basic |
MalwareREvil | REvil has used obfuscated VBA macros for execution. |
| T1059.005 Visual Basic |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses Word macros for execution. |
| T1059.005 Visual Basic |
MalwareNanoCore | NanoCore uses VBS files. |
| T1059.005 Visual Basic |
MalwareIPsec Helper | IPsec Helper can run arbitrary Visual Basic scripts and commands passed to it. |
| T1059.005 Visual Basic |
MalwareDanBot | DanBot can use a VBA macro embedded in an Excel file to drop the payload. |
| T1059.005 Visual Basic |
MalwareRamsay | Ramsay has included embedded Visual Basic scripts in malicious documents. |
| T1059.005 Visual Basic |
MalwareBackConfig | BackConfig has used VBS to install its downloader component and malicious documents with VBA macro code. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.