ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.003×

73 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
GroupLazyScripter

LazyScripter has used batch files to deploy open-source and multi-stage RATs.

T1059.003
Windows Command Shell
GroupToddyCat

ToddyCat has used .bat scripts and `cmd` for execution on compromised hosts.

T1059.003
Windows Command Shell
GroupAgrius

Agrius uses ASPXSpy web shells to enable follow-on command execution via cmd.exe.

T1059.003
Windows Command Shell
GroupAPT28

An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads.

T1059.003
Windows Command Shell
GroupMetador

Metador has used the Windows command line to execute commands.

T1059.003
Windows Command Shell
GroupAPT5

APT5 has used cmd.exe for execution on compromised systems.

T1059.003
Windows Command Shell
GroupFox Kitten

Fox Kitten has used cmd.exe likely as a password changing mechanism.

T1059.003
Windows Command Shell
GroupLazarus Group

Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system.

T1059.003
Windows Command Shell
GroupINC Ransom

INC Ransom has used `cmd.exe` to launch malicious payloads.

T1059.003
Windows Command Shell
GroupSilence

Silence has used Windows command-line to run commands.

T1059.003
Windows Command Shell
GroupSowbug

Sowbug has used command line during its intrusions.

T1059.003
Windows Command Shell
GroupThreat Group-1314

Threat Group-1314 actors spawned shells on remote systems on a victim network to execute commands.

T1059.003
Windows Command Shell
GroupCobalt Group

Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files.

T1059.003
Windows Command Shell
GroupWizard Spider

Wizard Spider has used `cmd.exe` to execute commands on a victim's machine.

T1059.003
Windows Command Shell
GroupPlay

Play has used a batch script to remove indicators of its presence on compromised hosts.

T1059.003
Windows Command Shell
GroupRancor

Rancor has used cmd.exe to execute commmands.

T1059.003
Windows Command Shell
GroupWIRTE

WIRTE has used the Windows command line as part of infection chains to open documents.

T1059.003
Windows Command Shell
GroupMagic Hound

Magic Hound has used the command-line interface for code execution.

T1059.003
Windows Command Shell
GroupThreat Group-3390

Threat Group-3390 has used command-line interfaces for execution.

T1059.003
Windows Command Shell
GroupFIN10

FIN10 has executed malicious .bat files containing PowerShell commands.

T1059.003
Windows Command Shell
GroupFIN8

FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`.

T1059.003
Windows Command Shell
GroupFIN13

FIN13 has leveraged `xp_cmdshell` and Windows Command Shell to execute commands on a compromised machine. FIN13 has also attempted to leverage the ‘xp_cmdshell’ SQL procedure to execute remote commands on internal MS-SQL servers.

T1059.003
Windows Command Shell
GroupNomadic Octopus

Nomadic Octopus used cmd.exe /c within a malicious macro.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.