Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.004 Unix Shell |
GroupVolt Typhoon | Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh). |
| T1059.004 Unix Shell |
GroupAPT41 | APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871. |
| T1059.004 Unix Shell |
GroupTeamTNT | TeamTNT has used shell scripts for execution. |
| T1059.004 Unix Shell |
GroupRocke | Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware. |
| T1059.004 Unix Shell |
GroupScattered Spider | Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance. |
| T1059.004 Unix Shell |
GroupUNC3886 | UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs). |
| T1059.004 Unix Shell |
GroupContagious Interview | Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh. |
| T1059.004 Unix Shell |
GroupSea Turtle | Sea Turtle used shell scripts for post-exploitation execution in victim environments. |
| T1059.004 Unix Shell |
GroupAquatic Panda | Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware. |
| T1059.004 Unix Shell |
GroupVelvet Ant | Velvet Ant used a custom tool, VELVETSTING, to parse encoded inbound commands to compromised F5 BIG-IP devices and then execute them via the Unix shell. |
| T1059.004 Unix Shell |
GroupTeamPCP | TeamPCP has leveraged malware capable of execution via the Linux CLI. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.