Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.005 Visual Basic |
MalwareGoopy | Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2. |
| T1059.005 Visual Basic |
MalwareRemexi | Remexi uses AutoIt and VBS scripts throughout its execution process. |
| T1059.005 Visual Basic |
MalwareAstaroth | Astaroth has used malicious VBS e-mail attachments for execution. |
| T1059.005 Visual Basic |
MalwareQakBot | QakBot can use VBS to download and execute malicious files. |
| T1059.005 Visual Basic |
MalwarejRAT | jRAT has been distributed as HTA files with VBScript. |
| T1059.005 Visual Basic |
MalwareHelminth | One version of Helminth consists of VBScript scripts. |
| T1059.005 Visual Basic |
MalwareComnie | Comnie executes VBS scripts. |
| T1059.005 Visual Basic |
MalwareJSS Loader | JSS Loader can download and execute VBScript files. |
| T1059.005 Visual Basic |
ToolRemcos | Remcos can execute VBS remotely. |
| T1059.005 Visual Basic |
ToolDonut | Donut can generate shellcode outputs that execute via VBScript. |
| T1059.005 Visual Basic |
ToolKoadic | Koadic performs most of its operations using Windows Script Host (VBScript) and runs arbitrary shellcode . |
| T1059.006 Python |
CampaignCutting Edge | During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool. |
| T1059.006 Python |
CampaignShadowRay | During ShadowRay, threat actors used the Python `pty` module to open reverse shells. |
| T1059.006 Python |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used custom applications developed in python. |
| T1059.006 Python |
CampaignOperation Wocao | During Operation Wocao, threat actors' backdoors were written in Python and compiled with py2exe. |
| T1059.006 Python |
GroupKimsuky | Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data. |
| T1059.006 Python |
GroupDragonfly | Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim. |
| T1059.006 Python |
GroupMuddyWater | MuddyWater has developed tools in Python including Out1. |
| T1059.006 Python |
GroupMachete | Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python. |
| T1059.006 Python |
GroupZIRCONIUM | ZIRCONIUM has used Python-based implants to interact with compromised hosts. |
| T1059.006 Python |
GroupRocke | Rocke has used Python-based malware to install and spread their coinminer. |
| T1059.006 Python |
GroupAPT39 | APT39 has used a command line utility and a network scanner written in python. |
| T1059.006 Python |
GroupUNC3886 | UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs. |
| T1059.006 Python |
GroupContagious Interview | Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules. |
| T1059.006 Python |
GroupAPT37 | APT37 has used Python scripts to execute payloads. |
| T1059.006 Python |
GroupTurla | Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads. |
| T1059.006 Python |
GroupRedCurl | RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445. |
| T1059.006 Python |
GroupAPT29 | APT29 has developed malware variants written in Python. |
| T1059.006 Python |
GroupCinnamon Tempest | Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files. |
| T1059.006 Python |
GroupBRONZE BUTLER | BRONZE BUTLER has made use of Python-based remote access tools. |
| T1059.006 Python |
GroupTonto Team | Tonto Team has used Python-based tools for execution. |
| T1059.006 Python |
GroupEarth Lusca | Earth Lusca used Python scripts for port scanning or building reverse shells. |
| T1059.006 Python |
GroupVOID MANTICORE | VOID MANTICORE has utilized Python scripts to execute its malicious payloads. |
| T1059.006 Python |
MalwarereGeorg | reGeorg is a Python-based web shell. |
| T1059.006 Python |
MalwareInvisibleFerret | InvisibleFerret is written in Python and has used Python scripts for execution. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1059.006 Python |
MalwareUPSTYLE | UPSTYLE is a Python-based application. |
| T1059.006 Python |
MalwarePyDCrypt | PyDCrypt, along with its functions, is written in Python. |
| T1059.006 Python |
MalwareTurian | Turian has the ability to use Python to spawn a Unix shell. |
| T1059.006 Python |
MalwareTHINCRUST | THINCRUST can use Python scripts for command execution. |
| T1059.006 Python |
MalwareMachete | Machete is written in Python and is used in conjunction with additional Python scripts. |
| T1059.006 Python |
MalwareDropBook | DropBook is a Python-based backdoor compiled with PyInstaller. |
| T1059.006 Python |
MalwareKeydnap | Keydnap uses Python for scripting to execute additional commands. |
| T1059.006 Python |
MalwarePUNCHBUGGY | PUNCHBUGGY has used python scripts. |
| T1059.006 Python |
MalwareKeyBoy | KeyBoy uses Python scripts for installing files and performing execution. |
| T1059.006 Python |
MalwareLumma Stealer | Lumma Stealer has used malicious Python scripts to execute payloads. |
| T1059.006 Python |
MalwareChaes | Chaes has used Python scripts for execution and the installation of additional files. |
| T1059.006 Python |
MalwareBundlore | Bundlore has used Python scripts to execute payloads. |
| T1059.006 Python |
MalwareVIRTUALPIE | VIRTUALPIE is a Python-based backdoor malware. |
| T1059.006 Python |
MalwareBandook | Bandook can support commands to execute Python-based payloads. |
| T1059.006 Python |
MalwarePysa | Pysa has used Python scripts to deploy ransomware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.