Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.004 Unix Shell |
MalwarePACEMAKER | PACEMAKER can use a simple bash script for execution. |
| T1059.004 Unix Shell |
MalwareBundlore | Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine. |
| T1059.004 Unix Shell |
MalwareBPFDoor | BPFDoor can create a reverse shell and supports vt100 emulator formatting. |
| T1059.004 Unix Shell |
MalwareDerusbi | Derusbi is capable of creating a remote Bash shell and executing commands. |
| T1059.004 Unix Shell |
MalwareDrovorub | Drovorub can execute arbitrary commands as root on a compromised system. |
| T1059.004 Unix Shell |
MalwarePULSECHECK | PULSECHECK can use Unix shell script for command execution. |
| T1059.004 Unix Shell |
MalwareKobalos | Kobalos can spawn a new pseudo-terminal and execute arbitrary commands at the command prompt. |
| T1059.004 Unix Shell |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the |
| T1059.004 Unix Shell |
MalwareNKAbuse | NKAbuse is initially installed and executed through an initial shell script. |
| T1059.004 Unix Shell |
MalwareMacMa | MacMa can execute supplied shell commands and uses bash scripts to perform additional actions. |
| T1059.004 Unix Shell |
MalwareProton | Proton uses macOS' .command file type to script actions. |
| T1059.004 Unix Shell |
MalwareCallMe | CallMe has the capability to create a reverse shell on victims. |
| T1059.004 Unix Shell |
MalwareRIFLESPINE | RIFLESPINE can execute commands with `/bin/sh`. |
| T1059.004 Unix Shell |
MalwareCoinTicker | CoinTicker executes a bash script to establish a reverse shell. |
| T1059.004 Unix Shell |
MalwarePenquin | Penquin can execute remote commands using bash scripts. |
| T1059.004 Unix Shell |
MalwareEbury | Ebury can use the commands `Xcsh` or `Xcls` to open a shell with Ebury level permissions and `Xxsh` to open a shell with root level. |
| T1059.004 Unix Shell |
MalwareKinsing | Kinsing has used Unix shell scripts to execute commands in the victim environment. |
| T1059.004 Unix Shell |
MalwarePITSTOP | PITSTOP has the ability to receive shell commands over a Unix domain socket. |
| T1059.004 Unix Shell |
MalwareZIPLINE | ZIPLINE can use `/bin/sh` to create a reverse shell and execute commands. |
| T1059.004 Unix Shell |
MalwareShai-Hulud | Shai-Hulud has utilized Linux shell commands to modify configuration files. |
| T1059.004 Unix Shell |
MalwareVIRTUALPITA | VIRTUALPITA has the ability to spawn a bash shell for script execution. |
| T1059.004 Unix Shell |
MalwareXCSSET | XCSSET uses a shell script to execute Mach-o files and |
| T1059.004 Unix Shell |
MalwareAppleJeus | AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms. |
| T1059.004 Unix Shell |
MalwareCookieMiner | CookieMiner has used a Unix shell script to run a series of commands targeting macOS. |
| T1059.004 Unix Shell |
MalwareOSX/Shlayer | OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command |
| T1059.004 Unix Shell |
MalwareLoudMiner | LoudMiner used shell scripts to launch various services and to start/stop the QEMU virtualization. |
| T1059.004 Unix Shell |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting. |
| T1059.004 Unix Shell |
MalwareCanisterWorm | CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence. |
| T1059.005 Visual Basic |
MalwareBumblebee | Bumblebee can create a Visual Basic script to enable persistence. |
| T1059.005 Visual Basic |
MalwareExaramel for Windows | Exaramel for Windows has a command to execute VBS scripts on the victim’s machine. |
| T1059.005 Visual Basic |
MalwareSmoke Loader | Smoke Loader adds a Visual Basic script in the Startup folder to deploy the payload. |
| T1059.005 Visual Basic |
MalwareTAMECAT | TAMECAT has used VBScript to query anti-virus products. |
| T1059.005 Visual Basic |
MalwareUrsnif | Ursnif droppers have used VBA macros to download and execute the malware's full executable payload. |
| T1059.005 Visual Basic |
MalwareNETWIRE | NETWIRE has been executed through use of VBScripts. |
| T1059.005 Visual Basic |
MalwareEmotet | Emotet has sent Microsoft Word documents with embedded macros that will invoke scripts to download additional payloads. |
| T1059.005 Visual Basic |
MalwareSystemBC | SystemBC has leveraged VBScript to execute malicious code. |
| T1059.005 Visual Basic |
MalwareSquirrelwaffle | Squirrelwaffle has used malicious VBA macros in Microsoft Word documents and Excel spreadsheets that execute an `AutoOpen` subroutine. |
| T1059.005 Visual Basic |
MalwareShrinkLocker | ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution. |
| T1059.005 Visual Basic |
MalwareSnip3 | Snip3 can use visual basic scripts for first-stage execution. |
| T1059.005 Visual Basic |
MalwareWhisperGate | WhisperGate can use a Visual Basic script to exclude the `C:\` drive from Windows Defender. |
| T1059.005 Visual Basic |
MalwareMispadu | Mispadu’s dropper uses VBS files to install payloads and perform execution. |
| T1059.005 Visual Basic |
MalwareIcedID | IcedID has used obfuscated VBA string expressions. |
| T1059.005 Visual Basic |
MalwarePowerShower | PowerShower has the ability to save and execute VBScript. |
| T1059.005 Visual Basic |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts. |
| T1059.005 Visual Basic |
MalwareFlagpro | Flagpro can execute malicious VBA macros embedded in .xlsm files. |
| T1059.005 Visual Basic |
MalwareKeyBoy | KeyBoy uses VBS scripts for installing files and performing execution. |
| T1059.005 Visual Basic |
MalwarePteranodon | Pteranodon can use a malicious VBS file for execution. |
| T1059.005 Visual Basic |
MalwareROKRAT | ROKRAT has used Visual Basic for execution. |
| T1059.005 Visual Basic |
MalwareJavali | Javali has used embedded VBScript to download malicious payloads from C2. |
| T1059.005 Visual Basic |
MalwareBisonal | Bisonal's dropper creates VBS scripts on the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.