ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.005×

16 examples

TechniqueUsed byProcedure example
T1059.005
Visual Basic
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant.

T1059.005
Visual Basic
CampaignFrankenstein

During Frankenstein, the threat actors used Word documents that prompted the victim to enable macros and run a Visual Basic script.

T1059.005
Visual Basic
CampaignOperation Sharpshooter

During Operation Sharpshooter, the threat actors used a VBA macro to execute a simple downloader that installed Rising Sun.

T1059.005
Visual Basic
CampaignOperation Honeybee

For Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant.

T1059.005
Visual Basic
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used Visual Basic scripts.

T1059.005
Visual Basic
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a VBA script called `vba_macro.exe`. This macro dropped `FONTCACHE.DAT`, the primary BlackEnergy implant; `rundll32.exe`, for executing the malware; `NTUSER.log`, an empty file; and desktop.ini, the default file used to determine folder displays on Windows machines.

T1059.005
Visual Basic
CampaignC0015

During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code.

T1059.005
Visual Basic
CampaignJuicy Mix

During Juicy Mix, OilRig used VBS droppers to deliver and establish persistence for the Mango backdoor.

T1059.005
Visual Basic
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 wrote malware such as Sibot in Visual Basic.

T1059.005
Visual Basic
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution.

T1059.005
Visual Basic
CampaignFunnyDream

During FunnyDream, the threat actors used a Visual Basic script to run remote commands.

T1059.005
Visual Basic
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors executed an encoded VBScript file using `wscript` and wrote the decoded output to a text file.

T1059.005
Visual Basic
CampaignOuter Space

During Outer Space, OilRig used VBS droppers to deploy malware.

T1059.005
Visual Basic
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server.

T1059.005
Visual Basic
CampaignOperation Wocao

During Operation Wocao, threat actors used VBScript to conduct reconnaissance on targeted systems.

T1059.005
Visual Basic
CampaignC0011

For C0011, Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.