ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1059.006
Python
MalwarePyDCrypt

PyDCrypt, along with its functions, is written in Python.

T1059.006
Python
MalwareTurian

Turian has the ability to use Python to spawn a Unix shell.

T1059.006
Python
MalwareTHINCRUST

THINCRUST can use Python scripts for command execution.

T1059.006
Python
MalwareMachete

Machete is written in Python and is used in conjunction with additional Python scripts.

T1059.006
Python
MalwareDropBook

DropBook is a Python-based backdoor compiled with PyInstaller.

T1059.006
Python
MalwareKeydnap

Keydnap uses Python for scripting to execute additional commands.

T1059.006
Python
MalwarePUNCHBUGGY

PUNCHBUGGY has used python scripts.

T1059.006
Python
MalwareKeyBoy

KeyBoy uses Python scripts for installing files and performing execution.

T1059.006
Python
MalwareLumma Stealer

Lumma Stealer has used malicious Python scripts to execute payloads.

T1059.006
Python
MalwareChaes

Chaes has used Python scripts for execution and the installation of additional files.

T1059.006
Python
MalwareBundlore

Bundlore has used Python scripts to execute payloads.

T1059.006
Python
MalwareVIRTUALPIE

VIRTUALPIE is a Python-based backdoor malware.

T1059.006
Python
MalwareBandook

Bandook can support commands to execute Python-based payloads.

T1059.006
Python
MalwarePysa

Pysa has used Python scripts to deploy ransomware.

T1059.006
Python
MalwareSpeakUp

SpeakUp uses Python scripts.

T1059.006
Python
MalwareCobalt Strike

Cobalt Strike can use Python to perform execution.

T1059.006
Python
MalwareNeo-reGeorg

Neo-reGeorg is a Python-based web shell.

T1059.006
Python
MalwareFRAMESTING

FRAMESTING is a Python web shell that can embed in the Ivanti Connect Secure CAV Python package.

T1059.006
Python
MalwareLAMEHUG

LAMEHUG can use Python scripts for execution.

T1059.006
Python
MalwarePoetRAT

PoetRAT was executed with a Python script and worked in conjunction with additional Python-based post-exploitation tools.

T1059.006
Python
MalwareCoinTicker

CoinTicker executes a Python script to download its second stage.

T1059.006
Python
MalwareSPAWNCHIMERA

SPAWNCHIMERA has searched the contents of two Python files scanner.py and scanner_legacy.py by searching for specific lines and replacing them with values that reduce their ability to track mismatches or new files.

T1059.006
Python
MalwareEbury

Ebury has used Python to implement its DGA.

T1059.006
Python
MalwareVIRTUALPITA

VIRTUALPITA can call a Python script to run commands on a targeted guest virtual machine.

T1059.006
Python
MalwareMechaFlounder

MechaFlounder uses a python-based payload.

T1059.006
Python
MalwareDRYHOOK

DRYHOOK is a Python-based script that executes within the victim environment.

T1059.006
Python
MalwareCookieMiner

CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre.

T1059.006
Python
MalwareLizar

Lizar has used Python scripts (ps2x.py script and ps2p.py) to execute files on remote hosts using the Impacket library.

T1059.006
Python
MalwareSmall Sieve

Small Sieve can use Python scripts to execute commands.

T1059.006
Python
ToolSILENTTRINITY

SILENTTRINITY is written in Python and can use multiple Python scripts for execution on targeted systems.

T1059.006
Python
ToolRemcos

Remcos uses Python scripts.

T1059.006
Python
ToolDonut

Donut can generate shellcode outputs that execute via Python.

T1059.006
Python
ToolIronNetInjector

IronNetInjector can use IronPython scripts to load payloads with the help of a .NET injector.

T1059.006
Python
ToolPupy

Pupy can use an add on feature when creating payloads that allows you to create custom Python scripts (“scriptlets”) to perform tasks offline (without requiring a session) such as sandbox detection, adding persistence, etc.

T1059.006
Python
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has leveraged Python scripts to download additional payloads, engage in discovery, and to establish persistence.

T1059.006
Python
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Python scripts to execute payloads.

T1059.006
Python
MalwareCanisterWorm

CanisterWorm has used a Python script as a second-stage backdoor.

T1059.007
JavaScript
MalwareGRIFFON

GRIFFON is written in and executed as JavaScript.

T1059.007
JavaScript
MalwareKOPILUWAK

KOPILUWAK had used Javascript to perform its core functions.

T1059.007
JavaScript
MalwareTsundere Botnet

Tsundere Botnet has the ability to run JavaScript code from the C2 server. Additionally, Tsundere Botnet has used Node.js to execute JavaScript code for the loader component.

T1059.007
JavaScript
MalwareAppleSeed

AppleSeed has the ability to use JavaScript to execute PowerShell.

T1059.007
JavaScript
MalwareEnvyScout

EnvyScout can write files to disk with JavaScript using a modified version of the open-source tool FileSaver.

T1059.007
JavaScript
MalwareGootloader

Gootloader can execute a Javascript file for initial infection.

T1059.007
JavaScript
MalwareHexEval Loader

HexEval Loader has executed malicious JavaScript code.

T1059.007
JavaScript
MalwareInvisiMole

InvisiMole can use a JavaScript file as part of its execution chain.

T1059.007
JavaScript
MalwareAvaddon

Avaddon has been executed through a malicious JScript downloader.

T1059.007
JavaScript
MalwareSocGholish

The SocGholish payload is executed as JavaScript.

T1059.007
JavaScript
MalwareSpicyOmelette

SpicyOmelette has the ability to execute arbitrary JavaScript code on a compromised host.

T1059.007
JavaScript
MalwareBeaverTail

BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS.

T1059.007
JavaScript
MalwareDarkWatchman

DarkWatchman uses JavaScript to perform its core functionalities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.