Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.004 Unix Shell |
MalwareAnchor | Anchor can execute payloads via shell scripting. |
| T1059.004 Unix Shell |
MalwarePACEMAKER | PACEMAKER can use a simple bash script for execution. |
| T1059.004 Unix Shell |
MalwareBundlore | Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine. |
| T1059.004 Unix Shell |
MalwareBPFDoor | BPFDoor can create a reverse shell and supports vt100 emulator formatting. |
| T1059.004 Unix Shell |
MalwareDerusbi | Derusbi is capable of creating a remote Bash shell and executing commands. |
| T1059.004 Unix Shell |
MalwareDrovorub | Drovorub can execute arbitrary commands as root on a compromised system. |
| T1059.004 Unix Shell |
MalwarePULSECHECK | PULSECHECK can use Unix shell script for command execution. |
| T1059.004 Unix Shell |
MalwareKobalos | Kobalos can spawn a new pseudo-terminal and execute arbitrary commands at the command prompt. |
| T1059.004 Unix Shell |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the |
| T1059.004 Unix Shell |
MalwareNKAbuse | NKAbuse is initially installed and executed through an initial shell script. |
| T1059.004 Unix Shell |
MalwareMacMa | MacMa can execute supplied shell commands and uses bash scripts to perform additional actions. |
| T1059.004 Unix Shell |
MalwareProton | Proton uses macOS' .command file type to script actions. |
| T1059.004 Unix Shell |
MalwareCallMe | CallMe has the capability to create a reverse shell on victims. |
| T1059.004 Unix Shell |
MalwareRIFLESPINE | RIFLESPINE can execute commands with `/bin/sh`. |
| T1059.004 Unix Shell |
MalwareCoinTicker | CoinTicker executes a bash script to establish a reverse shell. |
| T1059.004 Unix Shell |
MalwarePenquin | Penquin can execute remote commands using bash scripts. |
| T1059.004 Unix Shell |
MalwareEbury | Ebury can use the commands `Xcsh` or `Xcls` to open a shell with Ebury level permissions and `Xxsh` to open a shell with root level. |
| T1059.004 Unix Shell |
MalwareKinsing | Kinsing has used Unix shell scripts to execute commands in the victim environment. |
| T1059.004 Unix Shell |
MalwarePITSTOP | PITSTOP has the ability to receive shell commands over a Unix domain socket. |
| T1059.004 Unix Shell |
MalwareZIPLINE | ZIPLINE can use `/bin/sh` to create a reverse shell and execute commands. |
| T1059.004 Unix Shell |
MalwareShai-Hulud | Shai-Hulud has utilized Linux shell commands to modify configuration files. |
| T1059.004 Unix Shell |
MalwareVIRTUALPITA | VIRTUALPITA has the ability to spawn a bash shell for script execution. |
| T1059.004 Unix Shell |
MalwareXCSSET | XCSSET uses a shell script to execute Mach-o files and |
| T1059.004 Unix Shell |
MalwareAppleJeus | AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms. |
| T1059.004 Unix Shell |
MalwareCookieMiner | CookieMiner has used a Unix shell script to run a series of commands targeting macOS. |
| T1059.004 Unix Shell |
MalwareOSX/Shlayer | OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command |
| T1059.004 Unix Shell |
MalwareLoudMiner | LoudMiner used shell scripts to launch various services and to start/stop the QEMU virtualization. |
| T1059.004 Unix Shell |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting. |
| T1059.004 Unix Shell |
MalwareCanisterWorm | CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence. |
| T1059.004 Unix Shell |
GroupTeamPCP | TeamPCP has leveraged malware capable of execution via the Linux CLI. |
| T1059.005 Visual Basic |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant. |
| T1059.005 Visual Basic |
CampaignFrankenstein | During Frankenstein, the threat actors used Word documents that prompted the victim to enable macros and run a Visual Basic script. |
| T1059.005 Visual Basic |
CampaignOperation Sharpshooter | During Operation Sharpshooter, the threat actors used a VBA macro to execute a simple downloader that installed Rising Sun. |
| T1059.005 Visual Basic |
CampaignOperation Honeybee | For Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant. |
| T1059.005 Visual Basic |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors used Visual Basic scripts. |
| T1059.005 Visual Basic |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a VBA script called `vba_macro.exe`. This macro dropped `FONTCACHE.DAT`, the primary BlackEnergy implant; `rundll32.exe`, for executing the malware; `NTUSER.log`, an empty file; and desktop.ini, the default file used to determine folder displays on Windows machines. |
| T1059.005 Visual Basic |
CampaignC0015 | During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code. |
| T1059.005 Visual Basic |
CampaignJuicy Mix | During Juicy Mix, OilRig used VBS droppers to deliver and establish persistence for the Mango backdoor. |
| T1059.005 Visual Basic |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 wrote malware such as Sibot in Visual Basic. |
| T1059.005 Visual Basic |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution. |
| T1059.005 Visual Basic |
CampaignFunnyDream | During FunnyDream, the threat actors used a Visual Basic script to run remote commands. |
| T1059.005 Visual Basic |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors executed an encoded VBScript file using `wscript` and wrote the decoded output to a text file. |
| T1059.005 Visual Basic |
CampaignOuter Space | During Outer Space, OilRig used VBS droppers to deploy malware. |
| T1059.005 Visual Basic |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server. |
| T1059.005 Visual Basic |
CampaignOperation Wocao | During Operation Wocao, threat actors used VBScript to conduct reconnaissance on targeted systems. |
| T1059.005 Visual Basic |
CampaignC0011 | For C0011, Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host. |
| T1059.005 Visual Basic |
GroupAPT38 | APT38 has used VBScript to execute commands and other operational tasks. |
| T1059.005 Visual Basic |
GroupSideCopy | SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`. |
| T1059.005 Visual Basic |
GroupKimsuky | Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT. |
| T1059.005 Visual Basic |
GroupPatchwork | Patchwork used Visual Basic Scripts (VBS) on victim machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.