ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.001×

131 examples

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwareCuba

Cuba has been dropped onto systems and used for lateral movement via obfuscated PowerShell scripts.

T1059.001
PowerShell
MalwareClambling

The Clambling dropper can use PowerShell to download the malware.

T1059.001
PowerShell
MalwarePureCrypter

PureCrypter can execute PowerShell commands to exclude files from EDR and to self-delete.

T1059.001
PowerShell
MalwareAkira

Akira will execute PowerShell commands to delete system volume shadow copies.

T1059.001
PowerShell
MalwareDarkGate

DarkGate has used PowerShell to create a remote shell.

T1059.001
PowerShell
MalwareLockBit 3.0

LockBit 3.0 can use PowerShell to apply Group Policy changes.

T1059.001
PowerShell
MalwareSHARPSTATS

SHARPSTATS has the ability to employ a custom PowerShell script.

T1059.001
PowerShell
MalwareFerocious

Ferocious can use PowerShell scripts for execution.

T1059.001
PowerShell
MalwareCreepyDrive

CreepyDrive can use Powershell for execution, including the cmdlets `Invoke-WebRequest` and `Invoke-Expression`.

T1059.001
PowerShell
MalwareNetwalker

Netwalker has been written in PowerShell and executed directly in memory, avoiding detection.

T1059.001
PowerShell
MalwareSaint Bot

Saint Bot has used PowerShell for execution.

T1059.001
PowerShell
MalwareCharmPower

CharmPower can use PowerShell for payload execution and C2 communication.

T1059.001
PowerShell
MalwareMuddyViper

MuddyViper has used PowerShell.exe to launch a reverse shell.

T1059.001
PowerShell
MalwareSMOKEDHAM

SMOKEDHAM can execute Powershell commands sent from its C2 server.

T1059.001
PowerShell
MalwareQUADAGENT

QUADAGENT uses PowerShell scripts for execution.

T1059.001
PowerShell
MalwareLP-Notes

LP-Notes has been downloaded and executed by PowerShell’s`Invoke-WebRequest` and `Invoke-Expression` cmdlets.

T1059.001
PowerShell
MalwareSpica

Spica can use an obfuscated PowerShell command to create a scheduled task for persistence.

T1059.001
PowerShell
MalwareBandook

Bandook has used PowerShell loaders as part of execution.

T1059.001
PowerShell
MalwareKONNI

KONNI used PowerShell to download and execute a specific 64-bit version of the malware.

T1059.001
PowerShell
MalwareMoleNet

MoleNet can use PowerShell to set persistence.

T1059.001
PowerShell
MalwareKGH_SPY

KGH_SPY can execute PowerShell commands on the victim's machine.

T1059.001
PowerShell
MalwareBlack Basta

Black Basta has used PowerShell scripts for discovery and to execute files over the network.

T1059.001
PowerShell
MalwareRogueRobin

RogueRobin uses a command prompt to run a PowerShell script from Excel. To assist in establishing persistence, RogueRobin creates %APPDATA%\OneDrive.bat and saves the following string to it:powershell.exe -WindowStyle Hidden -exec bypass -File “%APPDATA%\OneDrive.ps1”.

T1059.001
PowerShell
MalwareSQLRat

SQLRat has used PowerShell to create a Meterpreter session.

T1059.001
PowerShell
MalwareLitePower

LitePower can use a PowerShell script to execute commands.

T1059.001
PowerShell
MalwareMosquito

Mosquito can launch PowerShell Scripts.

T1059.001
PowerShell
MalwareStrelaStealer

StrelaStealer variants have used PowerShell scripts to download or drop payloads, including obfuscated variants to connect to a WebDAV server to download and executed an encrypted DLL for installation.

T1059.001
PowerShell
MalwareBazar

Bazar can execute a PowerShell script received from C2.

T1059.001
PowerShell
MalwareRATANKBA

There is a variant of RATANKBA that uses a PowerShell script instead of the traditional PE form.

T1059.001
PowerShell
MalwarePysa

Pysa has used Powershell scripts to deploy its ransomware.

T1059.001
PowerShell
MalwareLockBit 2.0

LockBit 2.0 can use the PowerShell module `InvokeGPUpdate` to modify Group Policy.

T1059.001
PowerShell
MalwareCobalt Strike

Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution.

T1059.001
PowerShell
MalwareServHelper

ServHelper has the ability to execute a PowerShell script to get information from the infected host.

T1059.001
PowerShell
MalwareJCry

JCry has used PowerShell to execute payloads.

T1059.001
PowerShell
MalwareREvil

REvil has used PowerShell to delete volume shadow copies and download files.

T1059.001
PowerShell
MalwareValak

Valak has used PowerShell to download additional modules.

T1059.001
PowerShell
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses PowerShell scripts.

T1059.001
PowerShell
MalwareIPsec Helper

IPsec Helper can run arbitrary PowerShell commands passed to it.

T1059.001
PowerShell
MalwarePillowmint

Pillowmint has used a PowerShell script to install a shim database.

T1059.001
PowerShell
MalwareRevenge RAT

Revenge RAT uses the PowerShell command Reflection.Assembly to load itself into memory to aid in execution.

T1059.001
PowerShell
MalwarePowGoop

PowGoop has the ability to use PowerShell scripts to execute commands.

T1059.001
PowerShell
MalwareLokibot

Lokibot has used PowerShell commands embedded inside batch scripts.

T1059.001
PowerShell
MalwareEgregor

Egregor has used an encoded PowerShell command by a service created by Cobalt Strike for lateral movement.

T1059.001
PowerShell
MalwareCreepySnail

CreepySnail can use PowerShell for execution, including the cmdlets `Invoke-WebRequst` and `Invoke-Expression`.

T1059.001
PowerShell
MalwarePowerPunch

PowerPunch has the ability to execute through PowerShell.

T1059.001
PowerShell
MalwareBONDUPDATER

BONDUPDATER is written in PowerShell.

T1059.001
PowerShell
MalwareTroll Stealer

Troll Stealer creates and executes a PowerShell script to delete itself.

T1059.001
PowerShell
MalwareMeteor

Meteor can use PowerShell commands to disable the network adapters on a victim machines.

T1059.001
PowerShell
MalwarenjRAT

njRAT has executed PowerShell commands via auto-run registry key persistence.

T1059.001
PowerShell
MalwareComRAT

ComRAT has used PowerShell to load itself every time a user logs in to the system. ComRAT can execute PowerShell scripts loaded into memory or from the file system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.