Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell. |
| T1059.003 Windows Command Shell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors utilized `cmd.exe` and batch scripts within the victim environment. |
| T1059.003 Windows Command Shell |
CampaignFrankenstein | During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate", as well as other encoded commands from the command-line |
| T1059.003 Windows Command Shell |
CampaignOperation Honeybee | During Operation Honeybee, various implants used batch scripting and `cmd.exe` for execution. |
| T1059.003 Windows Command Shell |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution installation via JavaScript will launch follow-on commands via cmd.exe. |
| T1059.003 Windows Command Shell |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe. |
| T1059.003 Windows Command Shell |
CampaignC0015 | During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries. |
| T1059.003 Windows Command Shell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used Windows batch files for persistence and execution. |
| T1059.003 Windows Command Shell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines. |
| T1059.003 Windows Command Shell |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used `cmd.exe` to run PowerShell commands to drop additional files on the compromised host. |
| T1059.003 Windows Command Shell |
CampaignFunnyDream | During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script. |
| T1059.003 Windows Command Shell |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used batch scripts to perform reconnaissance. |
| T1059.003 Windows Command Shell |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used |
| T1059.003 Windows Command Shell |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run `cmd.exe` commands on multiple victim machines. |
| T1059.003 Windows Command Shell |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `xp_cmdshell` command in MS-SQL. |
| T1059.003 Windows Command Shell |
CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells. |
| T1059.003 Windows Command Shell |
CampaignOperation Wocao | During Operation Wocao, threat actors spawned a new `cmd.exe` process to execute commands. |
| T1059.003 Windows Command Shell |
CampaignC0017 | During C0017, APT41 used `cmd.exe` to execute reconnaissance commands. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.