ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
GroupDark Caracal

Dark Caracal has used macros in Word documents that would download a second stage if executed.

T1059.003
Windows Command Shell
GroupCinnamon Tempest

Cinnamon Tempest has executed ransomware using batch scripts deployed via GPO.

T1059.003
Windows Command Shell
GroupChimera

Chimera has used the Windows Command Shell and batch scripts for execution on compromised hosts.

T1059.003
Windows Command Shell
GroupMirrorFace

MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation.

T1059.003
Windows Command Shell
GroupMedusa Group

Medusa Group has used Windows Command Prompt to control and execute commands on the system to include ingress, network, and filesystem enumeration activities.

T1059.003
Windows Command Shell
GroupBRONZE BUTLER

BRONZE BUTLER has used batch scripts and the command-line interface for execution.

T1059.003
Windows Command Shell
GroupTA551

TA551 has used cmd.exe to execute commands.

T1059.003
Windows Command Shell
GroupDarkhotel

Darkhotel has dropped an mspaint.lnk shortcut to disk which launches a shell script that downloads and executes a file.

T1059.003
Windows Command Shell
GroupLazyScripter

LazyScripter has used batch files to deploy open-source and multi-stage RATs.

T1059.003
Windows Command Shell
GroupToddyCat

ToddyCat has used .bat scripts and `cmd` for execution on compromised hosts.

T1059.003
Windows Command Shell
GroupAgrius

Agrius uses ASPXSpy web shells to enable follow-on command execution via cmd.exe.

T1059.003
Windows Command Shell
GroupAPT28

An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads.

T1059.003
Windows Command Shell
GroupMetador

Metador has used the Windows command line to execute commands.

T1059.003
Windows Command Shell
GroupAPT5

APT5 has used cmd.exe for execution on compromised systems.

T1059.003
Windows Command Shell
GroupFox Kitten

Fox Kitten has used cmd.exe likely as a password changing mechanism.

T1059.003
Windows Command Shell
GroupLazarus Group

Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system.

T1059.003
Windows Command Shell
GroupINC Ransom

INC Ransom has used `cmd.exe` to launch malicious payloads.

T1059.003
Windows Command Shell
GroupSilence

Silence has used Windows command-line to run commands.

T1059.003
Windows Command Shell
GroupSowbug

Sowbug has used command line during its intrusions.

T1059.003
Windows Command Shell
GroupThreat Group-1314

Threat Group-1314 actors spawned shells on remote systems on a victim network to execute commands.

T1059.003
Windows Command Shell
GroupCobalt Group

Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files.

T1059.003
Windows Command Shell
GroupWizard Spider

Wizard Spider has used `cmd.exe` to execute commands on a victim's machine.

T1059.003
Windows Command Shell
GroupPlay

Play has used a batch script to remove indicators of its presence on compromised hosts.

T1059.003
Windows Command Shell
GroupRancor

Rancor has used cmd.exe to execute commmands.

T1059.003
Windows Command Shell
GroupWIRTE

WIRTE has used the Windows command line as part of infection chains to open documents.

T1059.003
Windows Command Shell
GroupMagic Hound

Magic Hound has used the command-line interface for code execution.

T1059.003
Windows Command Shell
GroupThreat Group-3390

Threat Group-3390 has used command-line interfaces for execution.

T1059.003
Windows Command Shell
GroupFIN10

FIN10 has executed malicious .bat files containing PowerShell commands.

T1059.003
Windows Command Shell
GroupFIN8

FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`.

T1059.003
Windows Command Shell
GroupFIN13

FIN13 has leveraged `xp_cmdshell` and Windows Command Shell to execute commands on a compromised machine. FIN13 has also attempted to leverage the ‘xp_cmdshell’ SQL procedure to execute remote commands on internal MS-SQL servers.

T1059.003
Windows Command Shell
GroupNomadic Octopus

Nomadic Octopus used cmd.exe /c within a malicious macro.

T1059.004
Unix Shell
GroupVolt Typhoon

Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh).

T1059.004
Unix Shell
GroupAPT41

APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871.

T1059.004
Unix Shell
GroupTeamTNT

TeamTNT has used shell scripts for execution.

T1059.004
Unix Shell
GroupRocke

Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware.

T1059.004
Unix Shell
GroupScattered Spider

Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance.

T1059.004
Unix Shell
GroupUNC3886

UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs).

T1059.004
Unix Shell
GroupContagious Interview

Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh.

T1059.004
Unix Shell
GroupSea Turtle

Sea Turtle used shell scripts for post-exploitation execution in victim environments.

T1059.004
Unix Shell
GroupAquatic Panda

Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware.

T1059.004
Unix Shell
GroupVelvet Ant

Velvet Ant used a custom tool, VELVETSTING, to parse encoded inbound commands to compromised F5 BIG-IP devices and then execute them via the Unix shell.

T1059.004
Unix Shell
GroupTeamPCP

TeamPCP has leveraged malware capable of execution via the Linux CLI.

T1059.005
Visual Basic
GroupAPT38

APT38 has used VBScript to execute commands and other operational tasks.

T1059.005
Visual Basic
GroupSideCopy

SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`.

T1059.005
Visual Basic
GroupKimsuky

Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT.

T1059.005
Visual Basic
GroupPatchwork

Patchwork used Visual Basic Scripts (VBS) on victim machines.

T1059.005
Visual Basic
GroupGorgon Group

Gorgon Group has used macros in Spearphishing Attachments as well as executed VBScripts on victim machines.

T1059.005
Visual Basic
GroupAPT32

APT32 has used macros, COM scriptlets, and VBS scripts.

T1059.005
Visual Basic
GroupMuddyWater

MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.

T1059.005
Visual Basic
GroupGamaredon Group

Gamaredon Group has embedded malicious macros in document templates, which executed VBScript. Gamaredon Group has also delivered Microsoft Outlook VBA projects with embedded macros. Additionally, Gamaredon Group has executed VBScript files using wscript.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.