Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.007 JavaScript |
MalwareXbash | Xbash can execute malicious JavaScript payloads on the victim’s machine. |
| T1059.007 JavaScript |
MalwareNanHaiShu | NanHaiShu executes additional Jscript code on the victim's machine. |
| T1059.007 JavaScript |
MalwareLatrodectus | Latrodectus has used JavaScript files as part its infection chain during malicious spam |
| T1059.007 JavaScript |
MalwareChaes | Chaes has used JavaScript and Node.Js information stealer script that exfiltrates data using the node process. |
| T1059.007 JavaScript |
MalwareBundlore | Bundlore can execute JavaScript by injecting it into the victim's browser. |
| T1059.007 JavaScript |
MalwareGlassWorm | GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript. |
| T1059.007 JavaScript |
MalwareMetamorfo | Metamorfo includes payloads written in JavaScript. |
| T1059.007 JavaScript |
MalwareKONNI | KONNI has executed malicious JavaScript code. |
| T1059.007 JavaScript |
MalwareBlackByte Ransomware | BlackByte Ransomware is distributed as a JavaScript launcher file. |
| T1059.007 JavaScript |
MalwareStrelaStealer | StrelaStealer has been distributed as a malicious JavaScript object. |
| T1059.007 JavaScript |
MalwareWARPWIRE | WARPWIRE is a credential harvester written in JavaScript. |
| T1059.007 JavaScript |
MalwareCobalt Strike | The Cobalt Strike System Profiler can use JavaScript to perform reconnaissance actions. |
| T1059.007 JavaScript |
MalwareValak | Valak can execute JavaScript containing configuration data for establishing persistence. |
| T1059.007 JavaScript |
MalwareAshTag | AshTag can use JSON files to deliver payloads and configuration files. |
| T1059.007 JavaScript |
MalwareShai-Hulud | Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js. |
| T1059.007 JavaScript |
MalwarePOWERSTATS | POWERSTATS can use JavaScript code for execution. |
| T1059.007 JavaScript |
MalwareAstaroth | Astaroth uses JavaScript to perform its core functionalities. |
| T1059.007 JavaScript |
MalwareQakBot | The QakBot web inject module can inject Java Script into web banking pages visited by the victim. |
| T1059.007 JavaScript |
MalwarejRAT | jRAT has been distributed as HTA files with JScript. |
| T1059.007 JavaScript |
MalwareJSS Loader | JSS Loader can download and execute JavaScript files. |
| T1059.007 JavaScript |
MalwareXORIndex Loader | XORIndex Loader has executed malicious JavaScript code. |
| T1059.007 JavaScript |
Toolevilginx2 | evilginx2 can inject JavaScript code into HTML content to customize phishing attacks. |
| T1059.007 JavaScript |
ToolFRP | FRP can support the use of a JSON configuration file. |
| T1059.007 JavaScript |
ToolRemcos | Remcos has the ability to execute JavaScript remotely. |
| T1059.007 JavaScript |
ToolDonut | Donut can generate shellcode outputs that execute via JavaScript or JScript. |
| T1059.007 JavaScript |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has infected victims through malicious pre and post-install scripts within the package.json file. |
| T1059.007 JavaScript |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged JavaScript runtime to execute malicious scripts. |
| T1059.007 JavaScript |
MalwareCanisterWorm | CanisterWorm can leverage stolen tokens to execute Javascsript (deploy.js) for self-propagation. |
| T1059.007 JavaScript |
MalwareKali365 | Kali365 has executed JavaScript within victims' browsers through a React frontend that detects browser sessions to evade automated analysis, auto-copies actor-generated device codes to the victim's clipboard, and polls the actor's C2 infrastructure every three seconds to confirm when OAuth token capture has completed.. |
| T1059.008 Network Device CLI |
MalwareLine Dancer | Line Dancer can execute native commands in networking device command line interfaces. |
| T1059.008 Network Device CLI |
MalwarePHASEJAM | PHASEJAM has leveraged native commands associated with the compromised network appliance to execute code. |
| T1059.008 Network Device CLI |
MalwareDRYHOOK | DRYHOOK has the ability to interact with Ivanti Connect Secure environments and to modify system components. |
| T1059.009 Cloud API |
ToolPacu | Pacu leverages the AWS CLI for its operations. |
| T1059.009 Cloud API |
ToolTruffleHog | TruffleHog has leveraged Cloud CLI in order to enumerate and gather credentials. |
| T1059.010 AutoHotKey & AutoIT |
MalwareLumma Stealer | Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables. |
| T1059.010 AutoHotKey & AutoIT |
MalwareDarkGate | DarkGate uses AutoIt scripts dropped to a hidden directory during initial installation phases, such as `test.au3`. |
| T1059.010 AutoHotKey & AutoIT |
MalwareXLoader | XLoader can use an AutoIT script to decrypt a payload file, load it into victim memory, then execute it on the victim machine. |
| T1059.010 AutoHotKey & AutoIT |
MalwareOutSteel | OutSteel was developed using the AutoIT scripting language. |
| T1059.010 AutoHotKey & AutoIT |
MalwareMelcoz | Melcoz has been distributed through an AutoIt loader script. |
| T1059.011 Lua |
MalwareLine Runner | Line Runner utilizes Lua scripts for command execution. |
| T1059.011 Lua |
MalwareRemsec | Remsec can use modules written in Lua for execution. |
| T1059.011 Lua |
MalwareRedLine Stealer | RedLine Stealer malware has leveraged Lua bytecode to perform malicious behavior. |
| T1059.011 Lua |
MalwareEvilBunny | EvilBunny has used Lua scripts to execute payloads. |
| T1059.011 Lua |
MalwarePoetRAT | PoetRAT has executed a Lua script through a Lua interpreter for Windows. |
| T1059.012 Hypervisor CLI |
MalwareCheerscrypt | Cheerscrypt has leveraged `esxcli` in order to terminate running virtual machines. |
| T1059.012 Hypervisor CLI |
MalwareVIRTUALPIE | VIRTUALPIE is capable of command line execution on compromised ESXi servers. |
| T1059.012 Hypervisor CLI |
MalwareRoyal | Royal ransomware uses `esxcli` to gather a list of running VMs and terminate them. |
| T1059.013 Container CLI/API |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized the Docker command-line tool to gather details of the victim environment and collect credentials. |
| T1068 Exploitation for Privilege Escalation |
MalwareStuxnet | Stuxnet used MS10-073 and an undisclosed Task Scheduler vulnerability to escalate privileges on local Windows machines. |
| T1068 Exploitation for Privilege Escalation |
MalwareCosmicDuke | CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.