ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059.004
Unix Shell
MalwareAnchor

Anchor can execute payloads via shell scripting.

T1059.004
Unix Shell
MalwarePACEMAKER

PACEMAKER can use a simple bash script for execution.

T1059.004
Unix Shell
MalwareBundlore

Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine.

T1059.004
Unix Shell
MalwareBPFDoor

BPFDoor can create a reverse shell and supports vt100 emulator formatting.

T1059.004
Unix Shell
MalwareDerusbi

Derusbi is capable of creating a remote Bash shell and executing commands.

T1059.004
Unix Shell
MalwareDrovorub

Drovorub can execute arbitrary commands as root on a compromised system.

T1059.004
Unix Shell
MalwarePULSECHECK

PULSECHECK can use Unix shell script for command execution.

T1059.004
Unix Shell
MalwareKobalos

Kobalos can spawn a new pseudo-terminal and execute arbitrary commands at the command prompt.

T1059.004
Unix Shell
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the /tmp folder.

T1059.004
Unix Shell
MalwareNKAbuse

NKAbuse is initially installed and executed through an initial shell script.

T1059.004
Unix Shell
MalwareMacMa

MacMa can execute supplied shell commands and uses bash scripts to perform additional actions.

T1059.004
Unix Shell
MalwareProton

Proton uses macOS' .command file type to script actions.

T1059.004
Unix Shell
MalwareCallMe

CallMe has the capability to create a reverse shell on victims.

T1059.004
Unix Shell
MalwareRIFLESPINE

RIFLESPINE can execute commands with `/bin/sh`.

T1059.004
Unix Shell
MalwareCoinTicker

CoinTicker executes a bash script to establish a reverse shell.

T1059.004
Unix Shell
MalwarePenquin

Penquin can execute remote commands using bash scripts.

T1059.004
Unix Shell
MalwareEbury

Ebury can use the commands `Xcsh` or `Xcls` to open a shell with Ebury level permissions and `Xxsh` to open a shell with root level.

T1059.004
Unix Shell
MalwareKinsing

Kinsing has used Unix shell scripts to execute commands in the victim environment.

T1059.004
Unix Shell
MalwarePITSTOP

PITSTOP has the ability to receive shell commands over a Unix domain socket.

T1059.004
Unix Shell
MalwareZIPLINE

ZIPLINE can use `/bin/sh` to create a reverse shell and execute commands.

T1059.004
Unix Shell
MalwareShai-Hulud

Shai-Hulud has utilized Linux shell commands to modify configuration files.

T1059.004
Unix Shell
MalwareVIRTUALPITA

VIRTUALPITA has the ability to spawn a bash shell for script execution.

T1059.004
Unix Shell
MalwareXCSSET

XCSSET uses a shell script to execute Mach-o files and osacompile commands such as, osacompile -x -o xcode.app main.applescript.

T1059.004
Unix Shell
MalwareAppleJeus

AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms.

T1059.004
Unix Shell
MalwareCookieMiner

CookieMiner has used a Unix shell script to run a series of commands targeting macOS.

T1059.004
Unix Shell
MalwareOSX/Shlayer

OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command sh -c tail -c +1381... to extract bytes at an offset from a specified file. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.

T1059.004
Unix Shell
MalwareLoudMiner

LoudMiner used shell scripts to launch various services and to start/stop the QEMU virtualization.

T1059.004
Unix Shell
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting.

T1059.004
Unix Shell
MalwareCanisterWorm

CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence.

T1059.004
Unix Shell
GroupTeamPCP

TeamPCP has leveraged malware capable of execution via the Linux CLI.

T1059.005
Visual Basic
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant.

T1059.005
Visual Basic
CampaignFrankenstein

During Frankenstein, the threat actors used Word documents that prompted the victim to enable macros and run a Visual Basic script.

T1059.005
Visual Basic
CampaignOperation Sharpshooter

During Operation Sharpshooter, the threat actors used a VBA macro to execute a simple downloader that installed Rising Sun.

T1059.005
Visual Basic
CampaignOperation Honeybee

For Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant.

T1059.005
Visual Basic
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used Visual Basic scripts.

T1059.005
Visual Basic
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a VBA script called `vba_macro.exe`. This macro dropped `FONTCACHE.DAT`, the primary BlackEnergy implant; `rundll32.exe`, for executing the malware; `NTUSER.log`, an empty file; and desktop.ini, the default file used to determine folder displays on Windows machines.

T1059.005
Visual Basic
CampaignC0015

During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code.

T1059.005
Visual Basic
CampaignJuicy Mix

During Juicy Mix, OilRig used VBS droppers to deliver and establish persistence for the Mango backdoor.

T1059.005
Visual Basic
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 wrote malware such as Sibot in Visual Basic.

T1059.005
Visual Basic
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution.

T1059.005
Visual Basic
CampaignFunnyDream

During FunnyDream, the threat actors used a Visual Basic script to run remote commands.

T1059.005
Visual Basic
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors executed an encoded VBScript file using `wscript` and wrote the decoded output to a text file.

T1059.005
Visual Basic
CampaignOuter Space

During Outer Space, OilRig used VBS droppers to deploy malware.

T1059.005
Visual Basic
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server.

T1059.005
Visual Basic
CampaignOperation Wocao

During Operation Wocao, threat actors used VBScript to conduct reconnaissance on targeted systems.

T1059.005
Visual Basic
CampaignC0011

For C0011, Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host.

T1059.005
Visual Basic
GroupAPT38

APT38 has used VBScript to execute commands and other operational tasks.

T1059.005
Visual Basic
GroupSideCopy

SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`.

T1059.005
Visual Basic
GroupKimsuky

Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT.

T1059.005
Visual Basic
GroupPatchwork

Patchwork used Visual Basic Scripts (VBS) on victim machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.