Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.005 Visual Basic |
GroupFIN7 | FIN7 used VBS scripts to help perform tasks on the victim's machine. |
| T1059.005 Visual Basic |
GroupSandworm Team | Sandworm Team has created VBScripts to run an SSH server. |
| T1059.005 Visual Basic |
GroupMachete | Machete has embedded malicious macros within spearphishing attachments to download additional files. |
| T1059.005 Visual Basic |
GroupSidewinder | Sidewinder has used VBScript to drop and execute malware loaders. |
| T1059.005 Visual Basic |
GroupMustang Panda | Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on. |
| T1059.005 Visual Basic |
GroupAPT39 | APT39 has utilized malicious VBS scripts in malware. |
| T1059.005 Visual Basic |
GroupContagious Interview | Contagious Interview has utilized Visual Basic scripts in the execution of their downloader malware targeting Windows devices including as script called update.vbs. |
| T1059.005 Visual Basic |
GroupTA2541 | TA2541 has used VBS files to execute or establish persistence for additional payloads, often using file names consistent with email themes or mimicking system functionality. |
| T1059.005 Visual Basic |
GroupAPT37 | APT37 executes shellcode and a VBA script to decode Base64 strings. |
| T1059.005 Visual Basic |
GroupOilRig | OilRig has used VBScript macros for execution on compromised hosts. |
| T1059.005 Visual Basic |
GroupHigaisa | Higaisa has used VBScript code on the victim's machine. |
| T1059.005 Visual Basic |
GroupTA459 | TA459 has a VBScript for execution. |
| T1059.005 Visual Basic |
GroupConfucius | Confucius has used VBScript to execute malicious code. |
| T1059.005 Visual Basic |
GroupLeviathan | Leviathan has used VBScript. |
| T1059.005 Visual Basic |
GroupTurla | Turla has used VBS scripts throughout its operations. |
| T1059.005 Visual Basic |
GroupTA505 | TA505 has used VBS for code execution. |
| T1059.005 Visual Basic |
GroupRedCurl | RedCurl has used VBScript to run malicious files. |
| T1059.005 Visual Basic |
GroupMirrorFace | MirrorFace has used remote templates with VBA code in malware infection chains. |
| T1059.005 Visual Basic |
GroupBRONZE BUTLER | BRONZE BUTLER has used VBS and VBE scripts for execution. |
| T1059.005 Visual Basic |
GroupLazyScripter | LazyScripter has used VBScript to execute malicious code. |
| T1059.005 Visual Basic |
GroupWindshift | Windshift has used Visual Basic 6 (VB6) payloads. |
| T1059.005 Visual Basic |
GroupMalteiro | Malteiro has utilized a dropper containing malicious VBS scripts. |
| T1059.005 Visual Basic |
GroupAPT42 | APT42 has used a VBScript to query anti-virus products. |
| T1059.005 Visual Basic |
GroupAPT-C-36 | APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening. |
| T1059.005 Visual Basic |
GroupLazarus Group | Lazarus Group has used VBA and embedded macros in Word documents to execute malicious code. |
| T1059.005 Visual Basic |
GroupEarth Lusca | Earth Lusca used VBA scripts. |
| T1059.005 Visual Basic |
GroupFIN4 | FIN4 has used VBA macros to display a dialog box and collect victim credentials. |
| T1059.005 Visual Basic |
GroupSilence | Silence has used VBS scripts. |
| T1059.005 Visual Basic |
GroupCobalt Group | Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution. |
| T1059.005 Visual Basic |
GroupMolerats | Molerats used various implants, including those built with VBScript, on target machines. |
| T1059.005 Visual Basic |
GroupTransparent Tribe | Transparent Tribe has crafted VBS-based malicious documents. |
| T1059.005 Visual Basic |
GroupInception | Inception has used VBScript to execute malicious commands and payloads. |
| T1059.005 Visual Basic |
GroupHEXANE | HEXANE has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger. |
| T1059.005 Visual Basic |
GroupRancor | Rancor has used VBS scripts as well as embedded macros for execution. |
| T1059.005 Visual Basic |
GroupWIRTE | WIRTE has used VBScript in its operations. |
| T1059.005 Visual Basic |
GroupMagic Hound | Magic Hound malware has used VBS scripts for execution. |
| T1059.005 Visual Basic |
GroupAPT33 | APT33 has used VBScript to initiate the delivery of payloads. |
| T1059.005 Visual Basic |
GroupFIN13 | FIN13 has used VBS scripts for code execution on comrpomised machines. |
| T1059.006 Python |
GroupKimsuky | Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data. |
| T1059.006 Python |
GroupDragonfly | Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim. |
| T1059.006 Python |
GroupMuddyWater | MuddyWater has developed tools in Python including Out1. |
| T1059.006 Python |
GroupMachete | Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python. |
| T1059.006 Python |
GroupZIRCONIUM | ZIRCONIUM has used Python-based implants to interact with compromised hosts. |
| T1059.006 Python |
GroupRocke | Rocke has used Python-based malware to install and spread their coinminer. |
| T1059.006 Python |
GroupAPT39 | APT39 has used a command line utility and a network scanner written in python. |
| T1059.006 Python |
GroupUNC3886 | UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs. |
| T1059.006 Python |
GroupContagious Interview | Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules. |
| T1059.006 Python |
GroupAPT37 | APT37 has used Python scripts to execute payloads. |
| T1059.006 Python |
GroupTurla | Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads. |
| T1059.006 Python |
GroupRedCurl | RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.