Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.005 Visual Basic |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant. |
| T1059.005 Visual Basic |
CampaignFrankenstein | During Frankenstein, the threat actors used Word documents that prompted the victim to enable macros and run a Visual Basic script. |
| T1059.005 Visual Basic |
CampaignOperation Sharpshooter | During Operation Sharpshooter, the threat actors used a VBA macro to execute a simple downloader that installed Rising Sun. |
| T1059.005 Visual Basic |
CampaignOperation Honeybee | For Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant. |
| T1059.005 Visual Basic |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors used Visual Basic scripts. |
| T1059.005 Visual Basic |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a VBA script called `vba_macro.exe`. This macro dropped `FONTCACHE.DAT`, the primary BlackEnergy implant; `rundll32.exe`, for executing the malware; `NTUSER.log`, an empty file; and desktop.ini, the default file used to determine folder displays on Windows machines. |
| T1059.005 Visual Basic |
CampaignC0015 | During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code. |
| T1059.005 Visual Basic |
CampaignJuicy Mix | During Juicy Mix, OilRig used VBS droppers to deliver and establish persistence for the Mango backdoor. |
| T1059.005 Visual Basic |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 wrote malware such as Sibot in Visual Basic. |
| T1059.005 Visual Basic |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution. |
| T1059.005 Visual Basic |
CampaignFunnyDream | During FunnyDream, the threat actors used a Visual Basic script to run remote commands. |
| T1059.005 Visual Basic |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors executed an encoded VBScript file using `wscript` and wrote the decoded output to a text file. |
| T1059.005 Visual Basic |
CampaignOuter Space | During Outer Space, OilRig used VBS droppers to deploy malware. |
| T1059.005 Visual Basic |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server. |
| T1059.005 Visual Basic |
CampaignOperation Wocao | During Operation Wocao, threat actors used VBScript to conduct reconnaissance on targeted systems. |
| T1059.005 Visual Basic |
CampaignC0011 | For C0011, Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.