Real-world descriptions of how a group, tool or campaign used a technique.
295 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareCardinal RAT | Cardinal RAT can execute commands. |
| T1059.003 Windows Command Shell |
MalwareDanBot | DanBot has the ability to execute arbitrary commands via `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareBISCUIT | BISCUIT has a command to launch a command shell on the system. |
| T1059.003 Windows Command Shell |
MalwarePisloader | Pisloader uses cmd.exe to set the Registry Run key value. It also has a command to spawn a command shell. |
| T1059.003 Windows Command Shell |
MalwareGoldenSpy | GoldenSpy can execute remote commands via the command-line interface. |
| T1059.003 Windows Command Shell |
MalwareGold Dragon | Gold Dragon uses cmd.exe to execute commands for discovery. |
| T1059.003 Windows Command Shell |
MalwareRGDoor | RGDoor uses cmd.exe to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareHARDRAIN | HARDRAIN uses cmd.exe to execute |
| T1059.003 Windows Command Shell |
MalwareRevenge RAT | Revenge RAT uses cmd.exe to execute commands and run scripts on the victim's machine. |
| T1059.003 Windows Command Shell |
MalwareFunnyDream | FunnyDream can use `cmd.exe` for execution on remote hosts. |
| T1059.003 Windows Command Shell |
MalwareROADSWEEP | ROADSWEEP can open cmd.exe to enable command execution. |
| T1059.003 Windows Command Shell |
MalwareMore_eggs | More_eggs has used cmd.exe for execution. |
| T1059.003 Windows Command Shell |
MalwareTinyZBot | TinyZBot supports execution from the command-line. |
| T1059.003 Windows Command Shell |
MalwareOutSteel | OutSteel has used `cmd.exe` to scan a compromised host for specific file extensions. |
| T1059.003 Windows Command Shell |
MalwareBackConfig | BackConfig can download and run batch files to execute commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareDEADEYE | DEADEYE can run `cmd /c copy /y /b C:\Users\public\syslog_6-*.dat C:\Users\public\syslog.dll` to combine separated sections of code into a single DLL prior to execution. |
| T1059.003 Windows Command Shell |
MalwareLAMEHUG | LAMEHUG can use `cmd.exe` to display a decoy file to spearphishing victims. |
| T1059.003 Windows Command Shell |
MalwareInnaputRAT | InnaputRAT launches a shell to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareGrimAgent | GrimAgent can use the Windows Command Shell to execute commands, including its own removal. |
| T1059.003 Windows Command Shell |
MalwareLookBack | LookBack executes the |
| T1059.003 Windows Command Shell |
MalwareClop | Clop can use cmd.exe to help execute commands on the system. |
| T1059.003 Windows Command Shell |
MalwareLokibot | Lokibot has used |
| T1059.003 Windows Command Shell |
MalwareEgregor | Egregor has used batch files for execution and can launch Internet Explorer from cmd.exe. |
| T1059.003 Windows Command Shell |
MalwarePoetRAT | PoetRAT has called cmd through a Word document macro. |
| T1059.003 Windows Command Shell |
MalwareFELIXROOT | FELIXROOT executes batch scripts on the victim’s machine, and can launch a reverse shell for command execution. |
| T1059.003 Windows Command Shell |
MalwareZxShell | ZxShell can launch a reverse command shell. |
| T1059.003 Windows Command Shell |
MalwareCoinTicker | CoinTicker executes a bash script to establish a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareBabyShark | BabyShark has used cmd.exe to execute commands. |
| T1059.003 Windows Command Shell |
MalwareBONDUPDATER | BONDUPDATER can read batch commands in a file sent from its C2 server and execute them with cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareTroll Stealer | Troll Stealer can create and execute Windows batch scripts. |
| T1059.003 Windows Command Shell |
MalwareBLACKCOFFEE | BLACKCOFFEE has the capability to create a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareMeteor | Meteor can run `set.bat`, `update.bat`, `cache.bat`, `bcd.bat`, `msrun.bat`, and similar scripts. |
| T1059.003 Windows Command Shell |
MalwarenjRAT | njRAT can launch a command shell interface for executing commands. |
| T1059.003 Windows Command Shell |
MalwareMaze | The Maze encryption process has used batch scripts with various commands. |
| T1059.003 Windows Command Shell |
MalwareComRAT | ComRAT has used |
| T1059.003 Windows Command Shell |
MalwareTURNEDUP | TURNEDUP is capable of creating a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareManjusaka | Manjusaka can execute arbitrary commands passed to it from the C2 controller via `cmd.exe /c`. |
| T1059.003 Windows Command Shell |
MalwareJPIN | JPIN can use the command-line utility cacls.exe to change file permissions. |
| T1059.003 Windows Command Shell |
MalwareSideTwist | SideTwist can execute shell commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareKOCTOPUS | KOCTOPUS has used `cmd.exe` and batch files for execution. |
| T1059.003 Windows Command Shell |
MalwareMechaFlounder | MechaFlounder has the ability to run commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareHTTPBrowser | HTTPBrowser is capable of spawning a reverse shell on a victim. |
| T1059.003 Windows Command Shell |
MalwareMis-Type | Mis-Type has used `cmd.exe` to run commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareLunarWeb | LunarWeb can run shell commands using a BAT file with a name matching `%TEMP%\<random_9_alnum_chars>.batfile` or through cmd.exe with the `/c` and `/U` option for Unicode output. |
| T1059.003 Windows Command Shell |
MalwareDipsind | Dipsind can spawn remote shells. |
| T1059.003 Windows Command Shell |
MalwareQilin | Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i |
| T1059.003 Windows Command Shell |
MalwareSTARWHALE | STARWHALE has the ability to execute commands via `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareMirageFox | MirageFox has the capability to execute commands using cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareDownPaper | DownPaper uses the command line. |
| T1059.003 Windows Command Shell |
MalwareCozyCar | A module in CozyCar allows arbitrary commands to be executed by invoking |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.