ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059.005
Visual Basic
MalwareGoopy

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

T1059.005
Visual Basic
MalwareRemexi

Remexi uses AutoIt and VBS scripts throughout its execution process.

T1059.005
Visual Basic
MalwareAstaroth

Astaroth has used malicious VBS e-mail attachments for execution.

T1059.005
Visual Basic
MalwareQakBot

QakBot can use VBS to download and execute malicious files.

T1059.005
Visual Basic
MalwarejRAT

jRAT has been distributed as HTA files with VBScript.

T1059.005
Visual Basic
MalwareHelminth

One version of Helminth consists of VBScript scripts.

T1059.005
Visual Basic
MalwareComnie

Comnie executes VBS scripts.

T1059.005
Visual Basic
MalwareJSS Loader

JSS Loader can download and execute VBScript files.

T1059.005
Visual Basic
ToolRemcos

Remcos can execute VBS remotely.

T1059.005
Visual Basic
ToolDonut

Donut can generate shellcode outputs that execute via VBScript.

T1059.005
Visual Basic
ToolKoadic

Koadic performs most of its operations using Windows Script Host (VBScript) and runs arbitrary shellcode .

T1059.006
Python
CampaignCutting Edge

During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool.

T1059.006
Python
CampaignShadowRay

During ShadowRay, threat actors used the Python `pty` module to open reverse shells.

T1059.006
Python
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used custom applications developed in python.

T1059.006
Python
CampaignOperation Wocao

During Operation Wocao, threat actors' backdoors were written in Python and compiled with py2exe.

T1059.006
Python
GroupKimsuky

Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data.

T1059.006
Python
GroupDragonfly

Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim.

T1059.006
Python
GroupMuddyWater

MuddyWater has developed tools in Python including Out1.

T1059.006
Python
GroupMachete

Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python.

T1059.006
Python
GroupZIRCONIUM

ZIRCONIUM has used Python-based implants to interact with compromised hosts.

T1059.006
Python
GroupRocke

Rocke has used Python-based malware to install and spread their coinminer.

T1059.006
Python
GroupAPT39

APT39 has used a command line utility and a network scanner written in python.

T1059.006
Python
GroupUNC3886

UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs.

T1059.006
Python
GroupContagious Interview

Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules.

T1059.006
Python
GroupAPT37

APT37 has used Python scripts to execute payloads.

T1059.006
Python
GroupTurla

Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads.

T1059.006
Python
GroupRedCurl

RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445.

T1059.006
Python
GroupAPT29

APT29 has developed malware variants written in Python.

T1059.006
Python
GroupCinnamon Tempest

Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files.

T1059.006
Python
GroupBRONZE BUTLER

BRONZE BUTLER has made use of Python-based remote access tools.

T1059.006
Python
GroupTonto Team

Tonto Team has used Python-based tools for execution.

T1059.006
Python
GroupEarth Lusca

Earth Lusca used Python scripts for port scanning or building reverse shells.

T1059.006
Python
GroupVOID MANTICORE

VOID MANTICORE has utilized Python scripts to execute its malicious payloads.

T1059.006
Python
MalwarereGeorg

reGeorg is a Python-based web shell.

T1059.006
Python
MalwareInvisibleFerret

InvisibleFerret is written in Python and has used Python scripts for execution.

T1059.006
Python
MalwareUPSTYLE

UPSTYLE is a Python-based application.

T1059.006
Python
MalwarePyDCrypt

PyDCrypt, along with its functions, is written in Python.

T1059.006
Python
MalwareTurian

Turian has the ability to use Python to spawn a Unix shell.

T1059.006
Python
MalwareTHINCRUST

THINCRUST can use Python scripts for command execution.

T1059.006
Python
MalwareMachete

Machete is written in Python and is used in conjunction with additional Python scripts.

T1059.006
Python
MalwareDropBook

DropBook is a Python-based backdoor compiled with PyInstaller.

T1059.006
Python
MalwareKeydnap

Keydnap uses Python for scripting to execute additional commands.

T1059.006
Python
MalwarePUNCHBUGGY

PUNCHBUGGY has used python scripts.

T1059.006
Python
MalwareKeyBoy

KeyBoy uses Python scripts for installing files and performing execution.

T1059.006
Python
MalwareLumma Stealer

Lumma Stealer has used malicious Python scripts to execute payloads.

T1059.006
Python
MalwareChaes

Chaes has used Python scripts for execution and the installation of additional files.

T1059.006
Python
MalwareBundlore

Bundlore has used Python scripts to execute payloads.

T1059.006
Python
MalwareVIRTUALPIE

VIRTUALPIE is a Python-based backdoor malware.

T1059.006
Python
MalwareBandook

Bandook can support commands to execute Python-based payloads.

T1059.006
Python
MalwarePysa

Pysa has used Python scripts to deploy ransomware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.