ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.004×

11 examples

TechniqueUsed byProcedure example
T1059.004
Unix Shell
GroupVolt Typhoon

Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh).

T1059.004
Unix Shell
GroupAPT41

APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871.

T1059.004
Unix Shell
GroupTeamTNT

TeamTNT has used shell scripts for execution.

T1059.004
Unix Shell
GroupRocke

Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware.

T1059.004
Unix Shell
GroupScattered Spider

Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance.

T1059.004
Unix Shell
GroupUNC3886

UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs).

T1059.004
Unix Shell
GroupContagious Interview

Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh.

T1059.004
Unix Shell
GroupSea Turtle

Sea Turtle used shell scripts for post-exploitation execution in victim environments.

T1059.004
Unix Shell
GroupAquatic Panda

Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware.

T1059.004
Unix Shell
GroupVelvet Ant

Velvet Ant used a custom tool, VELVETSTING, to parse encoded inbound commands to compromised F5 BIG-IP devices and then execute them via the Unix shell.

T1059.004
Unix Shell
GroupTeamPCP

TeamPCP has leveraged malware capable of execution via the Linux CLI.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.