ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.003×

18 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell.

T1059.003
Windows Command Shell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors utilized `cmd.exe` and batch scripts within the victim environment.

T1059.003
Windows Command Shell
CampaignFrankenstein

During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate", as well as other encoded commands from the command-line

T1059.003
Windows Command Shell
CampaignOperation Honeybee

During Operation Honeybee, various implants used batch scripting and `cmd.exe` for execution.

T1059.003
Windows Command Shell
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution installation via JavaScript will launch follow-on commands via cmd.exe.

T1059.003
Windows Command Shell
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe.

T1059.003
Windows Command Shell
CampaignC0015

During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries.

T1059.003
Windows Command Shell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used Windows batch files for persistence and execution.

T1059.003
Windows Command Shell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines.

T1059.003
Windows Command Shell
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used `cmd.exe` to run PowerShell commands to drop additional files on the compromised host.

T1059.003
Windows Command Shell
CampaignFunnyDream

During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script.

T1059.003
Windows Command Shell
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used batch scripts to perform reconnaissance.

T1059.003
Windows Command Shell
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used cmd.exe for execution.

T1059.003
Windows Command Shell
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run `cmd.exe` commands on multiple victim machines.

T1059.003
Windows Command Shell
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `xp_cmdshell` command in MS-SQL.

T1059.003
Windows Command Shell
CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells.

T1059.003
Windows Command Shell
CampaignOperation Wocao

During Operation Wocao, threat actors spawned a new `cmd.exe` process to execute commands.

T1059.003
Windows Command Shell
CampaignC0017

During C0017, APT41 used `cmd.exe` to execute reconnaissance commands.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.