ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.003×

295 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwarePyDCrypt

PyDCrypt has used `cmd.exe` for execution.

T1059.003
Windows Command Shell
MalwareEnvyScout

EnvyScout can use cmd.exe to execute malicious files on compromised hosts.

T1059.003
Windows Command Shell
MalwareGreyEnergy

GreyEnergy uses cmd.exe to execute itself in-memory.

T1059.003
Windows Command Shell
MalwareEmotet

Emotet has used cmd.exe to run a PowerShell script.

T1059.003
Windows Command Shell
MalwareSNUGRIDE

SNUGRIDE is capable of executing commands and spawning a reverse shell.

T1059.003
Windows Command Shell
MalwareCrimson

Crimson has the ability to execute commands with the COMSPEC environment variable.

T1059.003
Windows Command Shell
MalwareDUSTTRAP

DUSTTRAP can execute commands via `cmd.exe`.

T1059.003
Windows Command Shell
MalwareTurian

Turian can create a remote shell and execute commands using cmd.

T1059.003
Windows Command Shell
MalwareBADHATCH

BADHATCH can use `cmd.exe` to execute commands on a compromised host.

T1059.003
Windows Command Shell
MalwareAction RAT

Action RAT can use `cmd.exe` to execute commands on an infected host.

T1059.003
Windows Command Shell
MalwarePUBLOAD

PUBLOAD has used several commands executed in sequence via `cmd`.

T1059.003
Windows Command Shell
MalwareSystemBC

SystemBC has used `cmd.exe` to execute VBS scripts, BAT scripts and CMD scripts.

T1059.003
Windows Command Shell
MalwarePingPull

PingPull can use `cmd.exe` to run various commands as a reverse shell.

T1059.003
Windows Command Shell
MalwareWellMess

WellMess can execute command line scripts received from C2.

T1059.003
Windows Command Shell
MalwareDropBook

DropBook can execute arbitrary shell commands on the victims' machines.

T1059.003
Windows Command Shell
MalwareWoody RAT

Woody RAT can execute commands using `cmd.exe`.

T1059.003
Windows Command Shell
MalwareMafalda

Mafalda can execute shell commands using `cmd.exe`.

T1059.003
Windows Command Shell
MalwareSquirrelwaffle

Squirrelwaffle has used `cmd.exe` for execution.

T1059.003
Windows Command Shell
MalwareUmbreon

Umbreon provides access using both standard facilities like SSH and additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet

T1059.003
Windows Command Shell
MalwareAuTo Stealer

AuTo Stealer can use `cmd.exe` to execute a created batch file.

T1059.003
Windows Command Shell
MalwareODAgent

ODAgent can execute a specified command line passed via API.

T1059.003
Windows Command Shell
MalwareFlawedAmmyy

FlawedAmmyy has used `cmd` to execute commands on a compromised host.

T1059.003
Windows Command Shell
MalwareSUGARUSH

SUGARUSH has used `cmd` for execution on an infected host.

T1059.003
Windows Command Shell
MalwareHOPLIGHT

HOPLIGHT can launch cmd.exe to execute commands on the system.

T1059.003
Windows Command Shell
MalwareWastedLocker

WastedLocker has used cmd to execute commands on the system.

T1059.003
Windows Command Shell
MalwareInvisiMole

InvisiMole can launch a remote shell to execute commands.

T1059.003
Windows Command Shell
MalwareVolgmer

Volgmer can execute commands on the victim's machine.

T1059.003
Windows Command Shell
MalwareWhisperGate

WhisperGate can use `cmd.exe` to execute commands.

T1059.003
Windows Command Shell
MalwareRDAT

RDAT has executed commands using cmd.exe /c.

T1059.003
Windows Command Shell
MalwareOkrum

Okrum's backdoor has used cmd.exe to execute arbitrary commands as well as batch scripts to update itself to a newer version.

T1059.003
Windows Command Shell
MalwareSamSam

SamSam uses custom batch scripts to execute some of its components.

T1059.003
Windows Command Shell
MalwareConti

Conti can utilize command line options to allow an attacker control over how it scans and encrypts files.

T1059.003
Windows Command Shell
MalwareRaspberry Robin

Raspberry Robin uses cmd.exe to read and execute a file stored on an infected USB device as part of initial installation.

T1059.003
Windows Command Shell
MalwareMegazord

Megazord can execute multiple commands post infection via `cmd.exe`.

T1059.003
Windows Command Shell
MalwareTEXTMATE

TEXTMATE executes cmd.exe to provide a reverse shell to adversaries.

T1059.003
Windows Command Shell
MalwareSiloscape

Siloscape can run cmd through an IRC channel.

T1059.003
Windows Command Shell
MalwareBlackCat

BlackCat can execute commands on a compromised network with the use of `cmd.exe`.

T1059.003
Windows Command Shell
MalwareUBoatRAT

UBoatRAT can start a command shell.

T1059.003
Windows Command Shell
MalwareNightdoor

Nightdoor creates a cmd.exe shell to send and receive commands from the command and control server via open pipes.

T1059.003
Windows Command Shell
MalwareHTTPTroy

HTTPTroy has the ability to generate a reverse shell using the command `conn <IP_ADDRESS> <PORT>`.

T1059.003
Windows Command Shell
MalwareMarkiRAT

MarkiRAT can utilize cmd.exe to execute commands in a victim's environment.

T1059.003
Windows Command Shell
MalwareKazuar

Kazuar uses cmd.exe to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareNavRAT

NavRAT leverages cmd.exe to perform discovery techniques. NavRAT loads malicious shellcode and executes it in memory.

T1059.003
Windows Command Shell
MalwareDarkComet

DarkComet can launch a remote shell to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareNETEAGLE

NETEAGLE allows adversaries to execute shell commands on the infected host.

T1059.003
Windows Command Shell
MalwareRagnar Locker

Ragnar Locker has used cmd.exe and batch scripts to execute commands.

T1059.003
Windows Command Shell
MalwareLucifer

Lucifer can issue shell commands to download and execute additional payloads.

T1059.003
Windows Command Shell
MalwarezwShell

zwShell can launch command-line shells.

T1059.003
Windows Command Shell
MalwareRising Sun

Rising Sun has executed commands using `cmd.exe /c “<command> > <%temp%>\AM<random>. tmp” 2>&1`.

T1059.003
Windows Command Shell
MalwareShimRat

ShimRat can be issued a command shell function from the C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.