Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.005 Visual Basic |
MalwareXbash | Xbash can execute malicious VBScript payloads on the victim’s machine. |
| T1059.005 Visual Basic |
MalwareDarkGate | DarkGate initial infection mechanisms include masquerading as pirated media that launches malicious VBScript on the victim. |
| T1059.005 Visual Basic |
MalwareNanHaiShu | NanHaiShu executes additional VBScript code on the victim's machine. |
| T1059.005 Visual Basic |
MalwareSVCReady | SVCReady has used VBA macros to execute shellcode. |
| T1059.005 Visual Basic |
MalwareFerocious | Ferocious has the ability to use Visual Basic scripts for execution. |
| T1059.005 Visual Basic |
MalwareSaint Bot | Saint Bot has used `.vbs` scripts for execution. |
| T1059.005 Visual Basic |
MalwareChaes | Chaes has used VBscript to execute malicious code. |
| T1059.005 Visual Basic |
MalwareTYPEFRAME | TYPEFRAME has used a malicious Word document for delivery with VBA macros for execution. |
| T1059.005 Visual Basic |
MalwareQUADAGENT | QUADAGENT uses VBScripts. |
| T1059.005 Visual Basic |
MalwareMetamorfo | Metamorfo has used VBS code on victims’ systems. |
| T1059.005 Visual Basic |
MalwareBandook | Bandook has used malicious VBA code against the target system. |
| T1059.005 Visual Basic |
MalwareKerrdown | Kerrdown can use a VBS base64 decoder function published by Motobit. |
| T1059.005 Visual Basic |
MalwareVBShower | VBShower has the ability to execute VBScript files. |
| T1059.005 Visual Basic |
MalwareStoneDrill | StoneDrill has several VBS scripts used throughout the malware's lifecycle. |
| T1059.005 Visual Basic |
MalwareOopsIE | OopsIE creates and uses a VBScript as part of its persistent execution. |
| T1059.005 Visual Basic |
MalwareGrandoreiro | Grandoreiro can use VBScript to execute malicious code. |
| T1059.005 Visual Basic |
MalwareSibot | Sibot executes commands using VBScript. |
| T1059.005 Visual Basic |
MalwareLunarMail | LunarMail has been installed using a VBA macro. |
| T1059.005 Visual Basic |
MalwareCobalt Strike | Cobalt Strike can use VBA to perform execution. |
| T1059.005 Visual Basic |
MalwareSUNBURST | SUNBURST used VBScripts to initiate the execution of payloads. |
| T1059.005 Visual Basic |
MalwareJCry | JCry has used VBS scripts. |
| T1059.005 Visual Basic |
MalwareREvil | REvil has used obfuscated VBA macros for execution. |
| T1059.005 Visual Basic |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses Word macros for execution. |
| T1059.005 Visual Basic |
MalwareNanoCore | NanoCore uses VBS files. |
| T1059.005 Visual Basic |
MalwareIPsec Helper | IPsec Helper can run arbitrary Visual Basic scripts and commands passed to it. |
| T1059.005 Visual Basic |
MalwareDanBot | DanBot can use a VBA macro embedded in an Excel file to drop the payload. |
| T1059.005 Visual Basic |
MalwareRamsay | Ramsay has included embedded Visual Basic scripts in malicious documents. |
| T1059.005 Visual Basic |
MalwareBackConfig | BackConfig has used VBS to install its downloader component and malicious documents with VBA macro code. |
| T1059.005 Visual Basic |
MalwareLookBack | LookBack has used VBA macros in Microsoft Word attachments to drop additional files to the host. |
| T1059.005 Visual Basic |
MalwareLokibot | Lokibot has used VBS scripts and XLS macros for execution. |
| T1059.005 Visual Basic |
MalwarePoetRAT | PoetRAT has used Word documents with VBScripts to execute malicious activities. |
| T1059.005 Visual Basic |
MalwareBabyShark | BabyShark can execute additional VisualBasic content. |
| T1059.005 Visual Basic |
MalwareMelcoz | Melcoz can use VBS scripts to execute malicious DLLs. |
| T1059.005 Visual Basic |
MalwareKOCTOPUS | KOCTOPUS has used VBScript to call wscript to execute a PowerShell command. |
| T1059.005 Visual Basic |
MalwareSTARWHALE | STARWHALE can use the VBScript function `GetRef` as part of its persistence mechanism. |
| T1059.005 Visual Basic |
MalwarePOWERSTATS | POWERSTATS can use VBScript (VBE) code for execution. |
| T1059.005 Visual Basic |
MalwareGoopy | Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2. |
| T1059.005 Visual Basic |
MalwareRemexi | Remexi uses AutoIt and VBS scripts throughout its execution process. |
| T1059.005 Visual Basic |
MalwareAstaroth | Astaroth has used malicious VBS e-mail attachments for execution. |
| T1059.005 Visual Basic |
MalwareQakBot | QakBot can use VBS to download and execute malicious files. |
| T1059.005 Visual Basic |
MalwarejRAT | jRAT has been distributed as HTA files with VBScript. |
| T1059.005 Visual Basic |
MalwareHelminth | One version of Helminth consists of VBScript scripts. |
| T1059.005 Visual Basic |
MalwareComnie | Comnie executes VBS scripts. |
| T1059.005 Visual Basic |
MalwareJSS Loader | JSS Loader can download and execute VBScript files. |
| T1059.005 Visual Basic |
ToolRemcos | Remcos can execute VBS remotely. |
| T1059.005 Visual Basic |
ToolDonut | Donut can generate shellcode outputs that execute via VBScript. |
| T1059.005 Visual Basic |
ToolKoadic | Koadic performs most of its operations using Windows Script Host (VBScript) and runs arbitrary shellcode . |
| T1059.006 Python |
MalwarereGeorg | reGeorg is a Python-based web shell. |
| T1059.006 Python |
MalwareInvisibleFerret | InvisibleFerret is written in Python and has used Python scripts for execution. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1059.006 Python |
MalwareUPSTYLE | UPSTYLE is a Python-based application. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.