ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1059.006
Python
GroupAPT29

APT29 has developed malware variants written in Python.

T1059.006
Python
GroupCinnamon Tempest

Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files.

T1059.006
Python
GroupBRONZE BUTLER

BRONZE BUTLER has made use of Python-based remote access tools.

T1059.006
Python
GroupTonto Team

Tonto Team has used Python-based tools for execution.

T1059.006
Python
GroupEarth Lusca

Earth Lusca used Python scripts for port scanning or building reverse shells.

T1059.006
Python
GroupVOID MANTICORE

VOID MANTICORE has utilized Python scripts to execute its malicious payloads.

T1059.006
Python
GroupTeamPCP

TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection.

T1059.007
JavaScript
GroupIndrik Spider

Indrik Spider has used malicious JavaScript files for several components of their attack.

T1059.007
JavaScript
GroupKimsuky

Kimsuky has used JScript for logging and downloading additional tools. Kimsuky has used TRANSLATEXT, which contained four Javascript files for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data.

T1059.007
JavaScript
GroupTA577

TA577 has used JavaScript to execute additional malicious payloads.

T1059.007
JavaScript
GroupEvilnum

Evilnum has used malicious JavaScript files on the victim's machine.

T1059.007
JavaScript
GroupAPT32

APT32 has used JavaScript for drive-by downloads and C2 communications.

T1059.007
JavaScript
GroupMuddyWater

MuddyWater has used JavaScript files to execute its POWERSTATS payload.

T1059.007
JavaScript
GroupFIN6

FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites.

T1059.007
JavaScript
GroupLeafminer

Leafminer infected victims using JavaScript code.

T1059.007
JavaScript
GroupFIN7

FIN7 used JavaScript scripts to help perform tasks on the victim's machine.

T1059.007
JavaScript
GroupSidewinder

Sidewinder has used JavaScript to drop and execute malware loaders.

T1059.007
JavaScript
GroupMustang Panda

Mustang Panda has executed a JavaScript payload utilizing wscript.exe on the endpoint.

T1059.007
JavaScript
GroupContagious Interview

Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js.

T1059.007
JavaScript
GroupHigaisa

Higaisa used JavaScript to execute additional files.

T1059.007
JavaScript
GroupSaint Bear

Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot.

T1059.007
JavaScript
GroupMoustachedBouncer

MoustachedBouncer has used JavaScript to deliver malware hosted on HTML pages.

T1059.007
JavaScript
GroupWinter Vivern

Winter Vivern delivered malicious JavaScript to exploit targets when exploiting Roundcube Webmail servers.

T1059.007
JavaScript
GroupTurla

Turla has used various JavaScript-based backdoors.

T1059.007
JavaScript
GroupTA505

TA505 has used JavaScript for code execution.

T1059.007
JavaScript
GroupStar Blizzard

Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework.

T1059.007
JavaScript
GroupTA578

TA578 has used JavaScript files in malware execution chains.

T1059.007
JavaScript
GroupLazyScripter

LazyScripter has used JavaScript in its attacks.

T1059.007
JavaScript
GroupAPT-C-36

APT-C-36 has used a fileless attack chain composed of three JavaScript code snippets to execute subsequent payloads.

T1059.007
JavaScript
GroupEarth Lusca

Earth Lusca has manipulated legitimate websites to inject malicious JavaScript code as part of their watering hole operations.

T1059.007
JavaScript
GroupSilence

Silence has used JS scripts.

T1059.007
JavaScript
GroupCobalt Group

Cobalt Group has executed JavaScript scriptlets on the victim's machine.

T1059.007
JavaScript
GroupMolerats

Molerats used various implants, including those built with JS, on target machines.

T1059.007
JavaScript
GroupTeamPCP

TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions.

T1059.007
JavaScript
GroupShinyHunters

ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, ShinyHunters has checked for the authenticode tool using the command `npm list global authenticode`. Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: ` node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' `.

T1059.009
Cloud API
GroupTeamTNT

TeamTNT has leveraged AWS CLI to enumerate cloud environments with compromised credentials.

T1059.009
Cloud API
GroupStorm-0501

Storm-0501 has leveraged Cloud CLI to execute commands and exfiltrate data from compromised environments.

T1059.009
Cloud API
GroupAPT29

APT29 has leveraged the Microsoft Graph API to perform various actions across Azure and M365 environments. They have also utilized AADInternals PowerShell Modules to access the API

T1059.009
Cloud API
GroupShinyHunters

ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`.

T1059.010
AutoHotKey & AutoIT
GroupAPT39

APT39 has utilized AutoIt malware scripts embedded in Microsoft Office documents or malicious links.

T1059.012
Hypervisor CLI
GroupUNC3886

UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal.

T1059.013
Container CLI/API
GroupTeamTNT

TeamTNT targeted misconfigured containers and used container CLI tools.

T1059.013
Container CLI/API
GroupTeamPCP

TeamPCP has queried the Kubernetes API for local service account tokens and has used `kubectl` for lateral movement.

T1068
Exploitation for Privilege Escalation
GroupBlackByte

BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupVolt Typhoon

Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services.

T1068
Exploitation for Privilege Escalation
GroupAPT32

APT32 has used CVE-2016-7255 to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupHAFNIUM

HAFNIUM has targeted unpatched applications to elevate access in targeted organizations.

T1068
Exploitation for Privilege Escalation
GroupFIN6

FIN6 has used tools to exploit Windows vulnerabilities in order to escalate privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.

T1068
Exploitation for Privilege Escalation
GroupZIRCONIUM

ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupScattered Spider

Scattered Spider has deployed a malicious kernel driver through exploitation of CVE-2015-2291 in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.