ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.003×

295 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareCardinal RAT

Cardinal RAT can execute commands.

T1059.003
Windows Command Shell
MalwareDanBot

DanBot has the ability to execute arbitrary commands via `cmd.exe`.

T1059.003
Windows Command Shell
MalwareBISCUIT

BISCUIT has a command to launch a command shell on the system.

T1059.003
Windows Command Shell
MalwarePisloader

Pisloader uses cmd.exe to set the Registry Run key value. It also has a command to spawn a command shell.

T1059.003
Windows Command Shell
MalwareGoldenSpy

GoldenSpy can execute remote commands via the command-line interface.

T1059.003
Windows Command Shell
MalwareGold Dragon

Gold Dragon uses cmd.exe to execute commands for discovery.

T1059.003
Windows Command Shell
MalwareRGDoor

RGDoor uses cmd.exe to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareHARDRAIN

HARDRAIN uses cmd.exe to execute netshcommands.

T1059.003
Windows Command Shell
MalwareRevenge RAT

Revenge RAT uses cmd.exe to execute commands and run scripts on the victim's machine.

T1059.003
Windows Command Shell
MalwareFunnyDream

FunnyDream can use `cmd.exe` for execution on remote hosts.

T1059.003
Windows Command Shell
MalwareROADSWEEP

ROADSWEEP can open cmd.exe to enable command execution.

T1059.003
Windows Command Shell
MalwareMore_eggs

More_eggs has used cmd.exe for execution.

T1059.003
Windows Command Shell
MalwareTinyZBot

TinyZBot supports execution from the command-line.

T1059.003
Windows Command Shell
MalwareOutSteel

OutSteel has used `cmd.exe` to scan a compromised host for specific file extensions.

T1059.003
Windows Command Shell
MalwareBackConfig

BackConfig can download and run batch files to execute commands on a compromised host.

T1059.003
Windows Command Shell
MalwareDEADEYE

DEADEYE can run `cmd /c copy /y /b C:\Users\public\syslog_6-*.dat C:\Users\public\syslog.dll` to combine separated sections of code into a single DLL prior to execution.

T1059.003
Windows Command Shell
MalwareLAMEHUG

LAMEHUG can use `cmd.exe` to display a decoy file to spearphishing victims.

T1059.003
Windows Command Shell
MalwareInnaputRAT

InnaputRAT launches a shell to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareGrimAgent

GrimAgent can use the Windows Command Shell to execute commands, including its own removal.

T1059.003
Windows Command Shell
MalwareLookBack

LookBack executes the cmd.exe command.

T1059.003
Windows Command Shell
MalwareClop

Clop can use cmd.exe to help execute commands on the system.

T1059.003
Windows Command Shell
MalwareLokibot

Lokibot has used cmd /c commands embedded within batch scripts.

T1059.003
Windows Command Shell
MalwareEgregor

Egregor has used batch files for execution and can launch Internet Explorer from cmd.exe.

T1059.003
Windows Command Shell
MalwarePoetRAT

PoetRAT has called cmd through a Word document macro.

T1059.003
Windows Command Shell
MalwareFELIXROOT

FELIXROOT executes batch scripts on the victim’s machine, and can launch a reverse shell for command execution.

T1059.003
Windows Command Shell
MalwareZxShell

ZxShell can launch a reverse command shell.

T1059.003
Windows Command Shell
MalwareCoinTicker

CoinTicker executes a bash script to establish a reverse shell.

T1059.003
Windows Command Shell
MalwareBabyShark

BabyShark has used cmd.exe to execute commands.

T1059.003
Windows Command Shell
MalwareBONDUPDATER

BONDUPDATER can read batch commands in a file sent from its C2 server and execute them with cmd.exe.

T1059.003
Windows Command Shell
MalwareTroll Stealer

Troll Stealer can create and execute Windows batch scripts.

T1059.003
Windows Command Shell
MalwareBLACKCOFFEE

BLACKCOFFEE has the capability to create a reverse shell.

T1059.003
Windows Command Shell
MalwareMeteor

Meteor can run `set.bat`, `update.bat`, `cache.bat`, `bcd.bat`, `msrun.bat`, and similar scripts.

T1059.003
Windows Command Shell
MalwarenjRAT

njRAT can launch a command shell interface for executing commands.

T1059.003
Windows Command Shell
MalwareMaze

The Maze encryption process has used batch scripts with various commands.

T1059.003
Windows Command Shell
MalwareComRAT

ComRAT has used cmd.exe to execute commands.

T1059.003
Windows Command Shell
MalwareTURNEDUP

TURNEDUP is capable of creating a reverse shell.

T1059.003
Windows Command Shell
MalwareManjusaka

Manjusaka can execute arbitrary commands passed to it from the C2 controller via `cmd.exe /c`.

T1059.003
Windows Command Shell
MalwareJPIN

JPIN can use the command-line utility cacls.exe to change file permissions.

T1059.003
Windows Command Shell
MalwareSideTwist

SideTwist can execute shell commands on a compromised host.

T1059.003
Windows Command Shell
MalwareKOCTOPUS

KOCTOPUS has used `cmd.exe` and batch files for execution.

T1059.003
Windows Command Shell
MalwareMechaFlounder

MechaFlounder has the ability to run commands on a compromised host.

T1059.003
Windows Command Shell
MalwareHTTPBrowser

HTTPBrowser is capable of spawning a reverse shell on a victim.

T1059.003
Windows Command Shell
MalwareMis-Type

Mis-Type has used `cmd.exe` to run commands on a compromised host.

T1059.003
Windows Command Shell
MalwareLunarWeb

LunarWeb can run shell commands using a BAT file with a name matching `%TEMP%\<⁠random_9_alnum_chars>.batfile` or through cmd.exe with the `/c` and `/U` option for Unicode output.

T1059.003
Windows Command Shell
MalwareDipsind

Dipsind can spawn remote shells.

T1059.003
Windows Command Shell
MalwareQilin

Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i
C:\Users\xxx\<encryptor_1>.exe --password [PASSWORD] --spread --spread-process` to execute its encryptor to target multiple network shares.

T1059.003
Windows Command Shell
MalwareSTARWHALE

STARWHALE has the ability to execute commands via `cmd.exe`.

T1059.003
Windows Command Shell
MalwareMirageFox

MirageFox has the capability to execute commands using cmd.exe.

T1059.003
Windows Command Shell
MalwareDownPaper

DownPaper uses the command line.

T1059.003
Windows Command Shell
MalwareCozyCar

A module in CozyCar allows arbitrary commands to be executed by invoking C:\Windows\System32\cmd.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.