ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1059.004
Unix Shell
MalwarePACEMAKER

PACEMAKER can use a simple bash script for execution.

T1059.004
Unix Shell
MalwareBundlore

Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine.

T1059.004
Unix Shell
MalwareBPFDoor

BPFDoor can create a reverse shell and supports vt100 emulator formatting.

T1059.004
Unix Shell
MalwareDerusbi

Derusbi is capable of creating a remote Bash shell and executing commands.

T1059.004
Unix Shell
MalwareDrovorub

Drovorub can execute arbitrary commands as root on a compromised system.

T1059.004
Unix Shell
MalwarePULSECHECK

PULSECHECK can use Unix shell script for command execution.

T1059.004
Unix Shell
MalwareKobalos

Kobalos can spawn a new pseudo-terminal and execute arbitrary commands at the command prompt.

T1059.004
Unix Shell
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the /tmp folder.

T1059.004
Unix Shell
MalwareNKAbuse

NKAbuse is initially installed and executed through an initial shell script.

T1059.004
Unix Shell
MalwareMacMa

MacMa can execute supplied shell commands and uses bash scripts to perform additional actions.

T1059.004
Unix Shell
MalwareProton

Proton uses macOS' .command file type to script actions.

T1059.004
Unix Shell
MalwareCallMe

CallMe has the capability to create a reverse shell on victims.

T1059.004
Unix Shell
MalwareRIFLESPINE

RIFLESPINE can execute commands with `/bin/sh`.

T1059.004
Unix Shell
MalwareCoinTicker

CoinTicker executes a bash script to establish a reverse shell.

T1059.004
Unix Shell
MalwarePenquin

Penquin can execute remote commands using bash scripts.

T1059.004
Unix Shell
MalwareEbury

Ebury can use the commands `Xcsh` or `Xcls` to open a shell with Ebury level permissions and `Xxsh` to open a shell with root level.

T1059.004
Unix Shell
MalwareKinsing

Kinsing has used Unix shell scripts to execute commands in the victim environment.

T1059.004
Unix Shell
MalwarePITSTOP

PITSTOP has the ability to receive shell commands over a Unix domain socket.

T1059.004
Unix Shell
MalwareZIPLINE

ZIPLINE can use `/bin/sh` to create a reverse shell and execute commands.

T1059.004
Unix Shell
MalwareShai-Hulud

Shai-Hulud has utilized Linux shell commands to modify configuration files.

T1059.004
Unix Shell
MalwareVIRTUALPITA

VIRTUALPITA has the ability to spawn a bash shell for script execution.

T1059.004
Unix Shell
MalwareXCSSET

XCSSET uses a shell script to execute Mach-o files and osacompile commands such as, osacompile -x -o xcode.app main.applescript.

T1059.004
Unix Shell
MalwareAppleJeus

AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms.

T1059.004
Unix Shell
MalwareCookieMiner

CookieMiner has used a Unix shell script to run a series of commands targeting macOS.

T1059.004
Unix Shell
MalwareOSX/Shlayer

OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command sh -c tail -c +1381... to extract bytes at an offset from a specified file. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.

T1059.004
Unix Shell
MalwareLoudMiner

LoudMiner used shell scripts to launch various services and to start/stop the QEMU virtualization.

T1059.004
Unix Shell
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting.

T1059.004
Unix Shell
MalwareCanisterWorm

CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence.

T1059.005
Visual Basic
MalwareBumblebee

Bumblebee can create a Visual Basic script to enable persistence.

T1059.005
Visual Basic
MalwareExaramel for Windows

Exaramel for Windows has a command to execute VBS scripts on the victim’s machine.

T1059.005
Visual Basic
MalwareSmoke Loader

Smoke Loader adds a Visual Basic script in the Startup folder to deploy the payload.

T1059.005
Visual Basic
MalwareTAMECAT

TAMECAT has used VBScript to query anti-virus products.

T1059.005
Visual Basic
MalwareUrsnif

Ursnif droppers have used VBA macros to download and execute the malware's full executable payload.

T1059.005
Visual Basic
MalwareNETWIRE

NETWIRE has been executed through use of VBScripts.

T1059.005
Visual Basic
MalwareEmotet

Emotet has sent Microsoft Word documents with embedded macros that will invoke scripts to download additional payloads.

T1059.005
Visual Basic
MalwareSystemBC

SystemBC has leveraged VBScript to execute malicious code.

T1059.005
Visual Basic
MalwareSquirrelwaffle

Squirrelwaffle has used malicious VBA macros in Microsoft Word documents and Excel spreadsheets that execute an `AutoOpen` subroutine.

T1059.005
Visual Basic
MalwareShrinkLocker

ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution.

T1059.005
Visual Basic
MalwareSnip3

Snip3 can use visual basic scripts for first-stage execution.

T1059.005
Visual Basic
MalwareWhisperGate

WhisperGate can use a Visual Basic script to exclude the `C:\` drive from Windows Defender.

T1059.005
Visual Basic
MalwareMispadu

Mispadu’s dropper uses VBS files to install payloads and perform execution.

T1059.005
Visual Basic
MalwareIcedID

IcedID has used obfuscated VBA string expressions.

T1059.005
Visual Basic
MalwarePowerShower

PowerShower has the ability to save and execute VBScript.

T1059.005
Visual Basic
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts.

T1059.005
Visual Basic
MalwareFlagpro

Flagpro can execute malicious VBA macros embedded in .xlsm files.

T1059.005
Visual Basic
MalwareKeyBoy

KeyBoy uses VBS scripts for installing files and performing execution.

T1059.005
Visual Basic
MalwarePteranodon

Pteranodon can use a malicious VBS file for execution.

T1059.005
Visual Basic
MalwareROKRAT

ROKRAT has used Visual Basic for execution.

T1059.005
Visual Basic
MalwareJavali

Javali has used embedded VBScript to download malicious payloads from C2.

T1059.005
Visual Basic
MalwareBisonal

Bisonal's dropper creates VBS scripts on the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.