ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059.006
Python
MalwareSpeakUp

SpeakUp uses Python scripts.

T1059.006
Python
MalwareCobalt Strike

Cobalt Strike can use Python to perform execution.

T1059.006
Python
MalwareNeo-reGeorg

Neo-reGeorg is a Python-based web shell.

T1059.006
Python
MalwareFRAMESTING

FRAMESTING is a Python web shell that can embed in the Ivanti Connect Secure CAV Python package.

T1059.006
Python
MalwareLAMEHUG

LAMEHUG can use Python scripts for execution.

T1059.006
Python
MalwarePoetRAT

PoetRAT was executed with a Python script and worked in conjunction with additional Python-based post-exploitation tools.

T1059.006
Python
MalwareCoinTicker

CoinTicker executes a Python script to download its second stage.

T1059.006
Python
MalwareSPAWNCHIMERA

SPAWNCHIMERA has searched the contents of two Python files scanner.py and scanner_legacy.py by searching for specific lines and replacing them with values that reduce their ability to track mismatches or new files.

T1059.006
Python
MalwareEbury

Ebury has used Python to implement its DGA.

T1059.006
Python
MalwareVIRTUALPITA

VIRTUALPITA can call a Python script to run commands on a targeted guest virtual machine.

T1059.006
Python
MalwareMechaFlounder

MechaFlounder uses a python-based payload.

T1059.006
Python
MalwareDRYHOOK

DRYHOOK is a Python-based script that executes within the victim environment.

T1059.006
Python
MalwareCookieMiner

CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre.

T1059.006
Python
MalwareLizar

Lizar has used Python scripts (ps2x.py script and ps2p.py) to execute files on remote hosts using the Impacket library.

T1059.006
Python
MalwareSmall Sieve

Small Sieve can use Python scripts to execute commands.

T1059.006
Python
ToolSILENTTRINITY

SILENTTRINITY is written in Python and can use multiple Python scripts for execution on targeted systems.

T1059.006
Python
ToolRemcos

Remcos uses Python scripts.

T1059.006
Python
ToolDonut

Donut can generate shellcode outputs that execute via Python.

T1059.006
Python
ToolIronNetInjector

IronNetInjector can use IronPython scripts to load payloads with the help of a .NET injector.

T1059.006
Python
ToolPupy

Pupy can use an add on feature when creating payloads that allows you to create custom Python scripts (“scriptlets”) to perform tasks offline (without requiring a session) such as sandbox detection, adding persistence, etc.

T1059.006
Python
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has leveraged Python scripts to download additional payloads, engage in discovery, and to establish persistence.

T1059.006
Python
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Python scripts to execute payloads.

T1059.006
Python
MalwareCanisterWorm

CanisterWorm has used a Python script as a second-stage backdoor.

T1059.006
Python
GroupTeamPCP

TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection.

T1059.007
JavaScript
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used JavaScript code.

T1059.007
JavaScript
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution initial delivery included obfuscated JavaScript objects stored in password-protected ZIP archives.

T1059.007
JavaScript
CampaignC0015

During C0015, the threat actors used a malicious HTA file that contained a mix of encoded HTML and JavaScript/VBScript code.

T1059.007
JavaScript
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized obfuscated JavaScript files for initial Pikabot payload download.

T1059.007
JavaScript
CampaignC0017

During C0017, APT41 deployed JScript web shells on compromised systems.

T1059.007
JavaScript
GroupIndrik Spider

Indrik Spider has used malicious JavaScript files for several components of their attack.

T1059.007
JavaScript
GroupKimsuky

Kimsuky has used JScript for logging and downloading additional tools. Kimsuky has used TRANSLATEXT, which contained four Javascript files for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data.

T1059.007
JavaScript
GroupTA577

TA577 has used JavaScript to execute additional malicious payloads.

T1059.007
JavaScript
GroupEvilnum

Evilnum has used malicious JavaScript files on the victim's machine.

T1059.007
JavaScript
GroupAPT32

APT32 has used JavaScript for drive-by downloads and C2 communications.

T1059.007
JavaScript
GroupMuddyWater

MuddyWater has used JavaScript files to execute its POWERSTATS payload.

T1059.007
JavaScript
GroupFIN6

FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites.

T1059.007
JavaScript
GroupLeafminer

Leafminer infected victims using JavaScript code.

T1059.007
JavaScript
GroupFIN7

FIN7 used JavaScript scripts to help perform tasks on the victim's machine.

T1059.007
JavaScript
GroupSidewinder

Sidewinder has used JavaScript to drop and execute malware loaders.

T1059.007
JavaScript
GroupMustang Panda

Mustang Panda has executed a JavaScript payload utilizing wscript.exe on the endpoint.

T1059.007
JavaScript
GroupContagious Interview

Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js.

T1059.007
JavaScript
GroupHigaisa

Higaisa used JavaScript to execute additional files.

T1059.007
JavaScript
GroupSaint Bear

Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot.

T1059.007
JavaScript
GroupMoustachedBouncer

MoustachedBouncer has used JavaScript to deliver malware hosted on HTML pages.

T1059.007
JavaScript
GroupWinter Vivern

Winter Vivern delivered malicious JavaScript to exploit targets when exploiting Roundcube Webmail servers.

T1059.007
JavaScript
GroupTurla

Turla has used various JavaScript-based backdoors.

T1059.007
JavaScript
GroupTA505

TA505 has used JavaScript for code execution.

T1059.007
JavaScript
GroupStar Blizzard

Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework.

T1059.007
JavaScript
GroupTA578

TA578 has used JavaScript files in malware execution chains.

T1059.007
JavaScript
GroupLazyScripter

LazyScripter has used JavaScript in its attacks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.