ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1059.007
JavaScript
MalwareXbash

Xbash can execute malicious JavaScript payloads on the victim’s machine.

T1059.007
JavaScript
MalwareNanHaiShu

NanHaiShu executes additional Jscript code on the victim's machine.

T1059.007
JavaScript
MalwareLatrodectus

Latrodectus has used JavaScript files as part its infection chain during malicious spam
email campaigns.

T1059.007
JavaScript
MalwareChaes

Chaes has used JavaScript and Node.Js information stealer script that exfiltrates data using the node process.

T1059.007
JavaScript
MalwareBundlore

Bundlore can execute JavaScript by injecting it into the victim's browser.

T1059.007
JavaScript
MalwareGlassWorm

GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript.

T1059.007
JavaScript
MalwareMetamorfo

Metamorfo includes payloads written in JavaScript.

T1059.007
JavaScript
MalwareKONNI

KONNI has executed malicious JavaScript code.

T1059.007
JavaScript
MalwareBlackByte Ransomware

BlackByte Ransomware is distributed as a JavaScript launcher file.

T1059.007
JavaScript
MalwareStrelaStealer

StrelaStealer has been distributed as a malicious JavaScript object.

T1059.007
JavaScript
MalwareWARPWIRE

WARPWIRE is a credential harvester written in JavaScript.

T1059.007
JavaScript
MalwareCobalt Strike

The Cobalt Strike System Profiler can use JavaScript to perform reconnaissance actions.

T1059.007
JavaScript
MalwareValak

Valak can execute JavaScript containing configuration data for establishing persistence.

T1059.007
JavaScript
MalwareAshTag

AshTag can use JSON files to deliver payloads and configuration files.

T1059.007
JavaScript
MalwareShai-Hulud

Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js.

T1059.007
JavaScript
MalwarePOWERSTATS

POWERSTATS can use JavaScript code for execution.

T1059.007
JavaScript
MalwareAstaroth

Astaroth uses JavaScript to perform its core functionalities.

T1059.007
JavaScript
MalwareQakBot

The QakBot web inject module can inject Java Script into web banking pages visited by the victim.

T1059.007
JavaScript
MalwarejRAT

jRAT has been distributed as HTA files with JScript.

T1059.007
JavaScript
MalwareJSS Loader

JSS Loader can download and execute JavaScript files.

T1059.007
JavaScript
MalwareXORIndex Loader

XORIndex Loader has executed malicious JavaScript code.

T1059.007
JavaScript
Toolevilginx2

evilginx2 can inject JavaScript code into HTML content to customize phishing attacks.

T1059.007
JavaScript
ToolFRP

FRP can support the use of a JSON configuration file.

T1059.007
JavaScript
ToolRemcos

Remcos has the ability to execute JavaScript remotely.

T1059.007
JavaScript
ToolDonut

Donut can generate shellcode outputs that execute via JavaScript or JScript.

T1059.007
JavaScript
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has infected victims through malicious pre and post-install scripts within the package.json file.

T1059.007
JavaScript
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged JavaScript runtime to execute malicious scripts.

T1059.007
JavaScript
MalwareCanisterWorm

CanisterWorm can leverage stolen tokens to execute Javascsript (deploy.js) for self-propagation.

T1059.007
JavaScript
MalwareKali365

Kali365 has executed JavaScript within victims' browsers through a React frontend that detects browser sessions to evade automated analysis, auto-copies actor-generated device codes to the victim's clipboard, and polls the actor's C2 infrastructure every three seconds to confirm when OAuth token capture has completed..

T1059.008
Network Device CLI
MalwareLine Dancer

Line Dancer can execute native commands in networking device command line interfaces.

T1059.008
Network Device CLI
MalwarePHASEJAM

PHASEJAM has leveraged native commands associated with the compromised network appliance to execute code.

T1059.008
Network Device CLI
MalwareDRYHOOK

DRYHOOK has the ability to interact with Ivanti Connect Secure environments and to modify system components.

T1059.009
Cloud API
ToolPacu

Pacu leverages the AWS CLI for its operations.

T1059.009
Cloud API
ToolTruffleHog

TruffleHog has leveraged Cloud CLI in order to enumerate and gather credentials.

T1059.010
AutoHotKey & AutoIT
MalwareLumma Stealer

Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables.

T1059.010
AutoHotKey & AutoIT
MalwareDarkGate

DarkGate uses AutoIt scripts dropped to a hidden directory during initial installation phases, such as `test.au3`.

T1059.010
AutoHotKey & AutoIT
MalwareXLoader

XLoader can use an AutoIT script to decrypt a payload file, load it into victim memory, then execute it on the victim machine.

T1059.010
AutoHotKey & AutoIT
MalwareOutSteel

OutSteel was developed using the AutoIT scripting language.

T1059.010
AutoHotKey & AutoIT
MalwareMelcoz

Melcoz has been distributed through an AutoIt loader script.

T1059.011
Lua
MalwareLine Runner

Line Runner utilizes Lua scripts for command execution.

T1059.011
Lua
MalwareRemsec

Remsec can use modules written in Lua for execution.

T1059.011
Lua
MalwareRedLine Stealer

RedLine Stealer malware has leveraged Lua bytecode to perform malicious behavior.

T1059.011
Lua
MalwareEvilBunny

EvilBunny has used Lua scripts to execute payloads.

T1059.011
Lua
MalwarePoetRAT

PoetRAT has executed a Lua script through a Lua interpreter for Windows.

T1059.012
Hypervisor CLI
MalwareCheerscrypt

Cheerscrypt has leveraged `esxcli` in order to terminate running virtual machines.

T1059.012
Hypervisor CLI
MalwareVIRTUALPIE

VIRTUALPIE is capable of command line execution on compromised ESXi servers.

T1059.012
Hypervisor CLI
MalwareRoyal

Royal ransomware uses `esxcli` to gather a list of running VMs and terminate them.

T1059.013
Container CLI/API
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized the Docker command-line tool to gather details of the victim environment and collect credentials.

T1068
Exploitation for Privilege Escalation
MalwareStuxnet

Stuxnet used MS10-073 and an undisclosed Task Scheduler vulnerability to escalate privileges on local Windows machines.

T1068
Exploitation for Privilege Escalation
MalwareCosmicDuke

CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.