Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.005 Mshta |
GroupEarth Lusca | Earth Lusca has used `mshta.exe` to load an HTA script within a malicious .LNK file. |
| T1218.005 Mshta |
GroupInception | Inception has used malicious HTA files to drop and execute malware. |
| T1218.005 Mshta |
MalwarePteranodon | Pteranodon can use mshta.exe to execute an HTA file hosted on a remote server. |
| T1218.005 Mshta |
MalwareLumma Stealer | Lumma Stealer has used mshta.exe to execute additional content. |
| T1218.005 Mshta |
MalwareXbash | Xbash can use mshta for executing scripts. |
| T1218.005 Mshta |
MalwareNanHaiShu | NanHaiShu uses mshta.exe to load its program and files. |
| T1218.005 Mshta |
MalwareMetamorfo | Metamorfo has used mshta.exe to execute a HTA payload. |
| T1218.005 Mshta |
MalwareSibot | Sibot has been executed via MSHTA application. |
| T1218.005 Mshta |
MalwareRevenge RAT | Revenge RAT uses mshta.exe to run malicious scripts on the system. |
| T1218.005 Mshta |
MalwareBabyShark | BabyShark has used mshta.exe to download and execute applications from a remote server. |
| T1218.005 Mshta |
MalwarePOWERSTATS | POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts. |
| T1218.005 Mshta |
ToolCovenant | Covenant can create HTA files to install Grunt listeners. |
| T1218.005 Mshta |
ToolKoadic | Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence. |
| T1218.007 Msiexec |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda initial payloads downloaded a Windows Installer MSI file that in turn dropped follow-on files leading to installation of PlugX during RedDelta Modified PlugX Infection Chain Operations. |
| T1218.007 Msiexec |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus delivered components using a Windows Installer package (.msi). The MSI installer extracted several files and executed the 3CXDesktopApp.exe, which loaded the malicious library file ffmpeg.dll. |
| T1218.007 Msiexec |
GroupAPT38 | APT38 has used `msiexec.exe` to execute malicious files. |
| T1218.007 Msiexec |
GroupMachete | |
| T1218.007 Msiexec |
GroupZIRCONIUM | ZIRCONIUM has used the msiexec.exe command-line utility to download and execute malicious MSI files. |
| T1218.007 Msiexec |
GroupTA505 | TA505 has used |
| T1218.007 Msiexec |
GroupMolerats | Molerats has used msiexec.exe to execute an MSI payload. |
| T1218.007 Msiexec |
GroupRancor | Rancor has used |
| T1218.007 Msiexec |
MalwareRCSession | RCSession has the ability to execute inside the msiexec.exe process. |
| T1218.007 Msiexec |
MalwareTsundere Botnet | Tsundere Botnet has been distributed via an MSI installer. |
| T1218.007 Msiexec |
MalwareFlawedAmmyy | FlawedAmmyy has been installed via `msiexec.exe`. |
| T1218.007 Msiexec |
MalwareRaspberry Robin | Raspberry Robin uses msiexec.exe for post-installation communication to command and control infrastructure. Msiexec.exe is executed referencing a remote resource for second-stage payload retrieval and execution. |
| T1218.007 Msiexec |
MalwareMispadu | Mispadu has been installed via MSI installer. |
| T1218.007 Msiexec |
MalwareIcedID | IcedID can inject itself into a suspended msiexec.exe process to send beacons to C2 while appearing as a normal msi application. IcedID has also used msiexec.exe to deploy the IcedID loader. |
| T1218.007 Msiexec |
MalwareRagnar Locker | Ragnar Locker has been delivered as an unsigned MSI package that was executed with |
| T1218.007 Msiexec |
MalwareJavali | Javali has used the MSI installer to download and execute malicious payloads. |
| T1218.007 Msiexec |
MalwareLatrodectus | Latrodectus has called `msiexec` to install remotely-hosted MSI files. |
| T1218.007 Msiexec |
MalwareChaes | Chaes has used .MSI files as an initial way to start the infection chain. |
| T1218.007 Msiexec |
MalwareMetamorfo | Metamorfo has used MsiExec.exe to automatically execute files. |
| T1218.007 Msiexec |
MalwareRedLine Stealer | RedLine Stealer has been installed via MSI Installer. |
| T1218.007 Msiexec |
MalwareGrandoreiro | Grandoreiro can use MSI files to execute DLLs. |
| T1218.007 Msiexec |
MalwareDEADEYE | DEADEYE can use `msiexec.exe` for execution of malicious DLL. |
| T1218.007 Msiexec |
MalwareClop | Clop can use msiexec.exe to disable security tools on the system. |
| T1218.007 Msiexec |
MalwareMelcoz | Melcoz can use MSI files with embedded VBScript for execution. |
| T1218.007 Msiexec |
MalwareMaze | Maze has delivered components for its ransomware attacks using MSI files, some of which have been executed from the command-line using |
| T1218.007 Msiexec |
MalwareAppleJeus | AppleJeus has been installed via MSI installer. |
| T1218.007 Msiexec |
MalwareQakBot | QakBot can use MSIExec to spawn multiple cmd.exe processes. |
| T1218.007 Msiexec |
MalwareDOWNIISSA | DOWNIISSA can create an instance of msiexec.exe and inject LODEINFO shellcode into the memory of the process. |
| T1218.007 Msiexec |
MalwareLoudMiner | LoudMiner used an MSI installer to install the virtualization software. |
| T1218.007 Msiexec |
ToolRemoteUtilities | RemoteUtilities can use Msiexec to install a service. |
| T1218.007 Msiexec |
MalwareDuqu | Duqu has used |
| T1218.008 Odbcconf |
GroupCobalt Group | Cobalt Group has used |
| T1218.008 Odbcconf |
MalwareBumblebee | Bumblebee can use `odbcconf.exe` to run DLLs on targeted hosts. |
| T1218.008 Odbcconf |
MalwareRaspberry Robin | Raspberry Robin uses the Windows utility odbcconf.exe to execute malicious commands, using the |
| T1218.009 Regsvcs/Regasm |
MalwareAgent Tesla | Agent Tesla has dropped RegAsm.exe onto systems for performing malicious activity. |
| T1218.010 Regsvr32 |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used `regsvr32` to execute malware. |
| T1218.010 Regsvr32 |
CampaignC0015 | During C0015, the threat actors employed code that used `regsvr32` for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.