Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.006 Python |
MalwareSpeakUp | SpeakUp uses Python scripts. |
| T1059.006 Python |
MalwareCobalt Strike | Cobalt Strike can use Python to perform execution. |
| T1059.006 Python |
MalwareNeo-reGeorg | Neo-reGeorg is a Python-based web shell. |
| T1059.006 Python |
MalwareFRAMESTING | FRAMESTING is a Python web shell that can embed in the Ivanti Connect Secure CAV Python package. |
| T1059.006 Python |
MalwareLAMEHUG | LAMEHUG can use Python scripts for execution. |
| T1059.006 Python |
MalwarePoetRAT | PoetRAT was executed with a Python script and worked in conjunction with additional Python-based post-exploitation tools. |
| T1059.006 Python |
MalwareCoinTicker | CoinTicker executes a Python script to download its second stage. |
| T1059.006 Python |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has searched the contents of two Python files scanner.py and scanner_legacy.py by searching for specific lines and replacing them with values that reduce their ability to track mismatches or new files. |
| T1059.006 Python |
MalwareEbury | Ebury has used Python to implement its DGA. |
| T1059.006 Python |
MalwareVIRTUALPITA | VIRTUALPITA can call a Python script to run commands on a targeted guest virtual machine. |
| T1059.006 Python |
MalwareMechaFlounder | MechaFlounder uses a python-based payload. |
| T1059.006 Python |
MalwareDRYHOOK | DRYHOOK is a Python-based script that executes within the victim environment. |
| T1059.006 Python |
MalwareCookieMiner | CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre. |
| T1059.006 Python |
MalwareLizar | Lizar has used Python scripts (ps2x.py script and ps2p.py) to execute files on remote hosts using the Impacket library. |
| T1059.006 Python |
MalwareSmall Sieve | Small Sieve can use Python scripts to execute commands. |
| T1059.006 Python |
ToolSILENTTRINITY | SILENTTRINITY is written in Python and can use multiple Python scripts for execution on targeted systems. |
| T1059.006 Python |
ToolRemcos | Remcos uses Python scripts. |
| T1059.006 Python |
ToolDonut | Donut can generate shellcode outputs that execute via Python. |
| T1059.006 Python |
ToolIronNetInjector | IronNetInjector can use IronPython scripts to load payloads with the help of a .NET injector. |
| T1059.006 Python |
ToolPupy | Pupy can use an add on feature when creating payloads that allows you to create custom Python scripts (“scriptlets”) to perform tasks offline (without requiring a session) such as sandbox detection, adding persistence, etc. |
| T1059.006 Python |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has leveraged Python scripts to download additional payloads, engage in discovery, and to establish persistence. |
| T1059.006 Python |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized Python scripts to execute payloads. |
| T1059.006 Python |
MalwareCanisterWorm | CanisterWorm has used a Python script as a second-stage backdoor. |
| T1059.006 Python |
GroupTeamPCP | TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection. |
| T1059.007 JavaScript |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors used JavaScript code. |
| T1059.007 JavaScript |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution initial delivery included obfuscated JavaScript objects stored in password-protected ZIP archives. |
| T1059.007 JavaScript |
CampaignC0015 | During C0015, the threat actors used a malicious HTA file that contained a mix of encoded HTML and JavaScript/VBScript code. |
| T1059.007 JavaScript |
CampaignPikabot Distribution February 2024 | Pikabot Distribution February 2024 utilized obfuscated JavaScript files for initial Pikabot payload download. |
| T1059.007 JavaScript |
CampaignC0017 | During C0017, APT41 deployed JScript web shells on compromised systems. |
| T1059.007 JavaScript |
GroupIndrik Spider | Indrik Spider has used malicious JavaScript files for several components of their attack. |
| T1059.007 JavaScript |
GroupKimsuky | Kimsuky has used JScript for logging and downloading additional tools. Kimsuky has used TRANSLATEXT, which contained four Javascript files for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data. |
| T1059.007 JavaScript |
GroupTA577 | TA577 has used JavaScript to execute additional malicious payloads. |
| T1059.007 JavaScript |
GroupEvilnum | Evilnum has used malicious JavaScript files on the victim's machine. |
| T1059.007 JavaScript |
GroupAPT32 | APT32 has used JavaScript for drive-by downloads and C2 communications. |
| T1059.007 JavaScript |
GroupMuddyWater | MuddyWater has used JavaScript files to execute its POWERSTATS payload. |
| T1059.007 JavaScript |
GroupFIN6 | FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites. |
| T1059.007 JavaScript |
GroupLeafminer | Leafminer infected victims using JavaScript code. |
| T1059.007 JavaScript |
GroupFIN7 | FIN7 used JavaScript scripts to help perform tasks on the victim's machine. |
| T1059.007 JavaScript |
GroupSidewinder | Sidewinder has used JavaScript to drop and execute malware loaders. |
| T1059.007 JavaScript |
GroupMustang Panda | Mustang Panda has executed a JavaScript payload utilizing wscript.exe on the endpoint. |
| T1059.007 JavaScript |
GroupContagious Interview | Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js. |
| T1059.007 JavaScript |
GroupHigaisa | Higaisa used JavaScript to execute additional files. |
| T1059.007 JavaScript |
GroupSaint Bear | Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot. |
| T1059.007 JavaScript |
GroupMoustachedBouncer | MoustachedBouncer has used JavaScript to deliver malware hosted on HTML pages. |
| T1059.007 JavaScript |
GroupWinter Vivern | Winter Vivern delivered malicious JavaScript to exploit targets when exploiting Roundcube Webmail servers. |
| T1059.007 JavaScript |
GroupTurla | Turla has used various JavaScript-based backdoors. |
| T1059.007 JavaScript |
GroupTA505 | TA505 has used JavaScript for code execution. |
| T1059.007 JavaScript |
GroupStar Blizzard | Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework. |
| T1059.007 JavaScript |
GroupTA578 | TA578 has used JavaScript files in malware execution chains. |
| T1059.007 JavaScript |
GroupLazyScripter | LazyScripter has used JavaScript in its attacks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.