Real-world descriptions of how a group, tool or campaign used a technique.
46 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.005 Visual Basic |
GroupAPT38 | APT38 has used VBScript to execute commands and other operational tasks. |
| T1059.005 Visual Basic |
GroupSideCopy | SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`. |
| T1059.005 Visual Basic |
GroupKimsuky | Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT. |
| T1059.005 Visual Basic |
GroupPatchwork | Patchwork used Visual Basic Scripts (VBS) on victim machines. |
| T1059.005 Visual Basic |
GroupGorgon Group | Gorgon Group has used macros in Spearphishing Attachments as well as executed VBScripts on victim machines. |
| T1059.005 Visual Basic |
GroupAPT32 | APT32 has used macros, COM scriptlets, and VBS scripts. |
| T1059.005 Visual Basic |
GroupMuddyWater | MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros. |
| T1059.005 Visual Basic |
GroupGamaredon Group | Gamaredon Group has embedded malicious macros in document templates, which executed VBScript. Gamaredon Group has also delivered Microsoft Outlook VBA projects with embedded macros. Additionally, Gamaredon Group has executed VBScript files using wscript.exe. |
| T1059.005 Visual Basic |
GroupFIN7 | FIN7 used VBS scripts to help perform tasks on the victim's machine. |
| T1059.005 Visual Basic |
GroupSandworm Team | Sandworm Team has created VBScripts to run an SSH server. |
| T1059.005 Visual Basic |
GroupMachete | Machete has embedded malicious macros within spearphishing attachments to download additional files. |
| T1059.005 Visual Basic |
GroupSidewinder | Sidewinder has used VBScript to drop and execute malware loaders. |
| T1059.005 Visual Basic |
GroupMustang Panda | Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on. |
| T1059.005 Visual Basic |
GroupAPT39 | APT39 has utilized malicious VBS scripts in malware. |
| T1059.005 Visual Basic |
GroupContagious Interview | Contagious Interview has utilized Visual Basic scripts in the execution of their downloader malware targeting Windows devices including as script called update.vbs. |
| T1059.005 Visual Basic |
GroupTA2541 | TA2541 has used VBS files to execute or establish persistence for additional payloads, often using file names consistent with email themes or mimicking system functionality. |
| T1059.005 Visual Basic |
GroupAPT37 | APT37 executes shellcode and a VBA script to decode Base64 strings. |
| T1059.005 Visual Basic |
GroupOilRig | OilRig has used VBScript macros for execution on compromised hosts. |
| T1059.005 Visual Basic |
GroupHigaisa | Higaisa has used VBScript code on the victim's machine. |
| T1059.005 Visual Basic |
GroupTA459 | TA459 has a VBScript for execution. |
| T1059.005 Visual Basic |
GroupConfucius | Confucius has used VBScript to execute malicious code. |
| T1059.005 Visual Basic |
GroupLeviathan | Leviathan has used VBScript. |
| T1059.005 Visual Basic |
GroupTurla | Turla has used VBS scripts throughout its operations. |
| T1059.005 Visual Basic |
GroupTA505 | TA505 has used VBS for code execution. |
| T1059.005 Visual Basic |
GroupRedCurl | RedCurl has used VBScript to run malicious files. |
| T1059.005 Visual Basic |
GroupMirrorFace | MirrorFace has used remote templates with VBA code in malware infection chains. |
| T1059.005 Visual Basic |
GroupBRONZE BUTLER | BRONZE BUTLER has used VBS and VBE scripts for execution. |
| T1059.005 Visual Basic |
GroupLazyScripter | LazyScripter has used VBScript to execute malicious code. |
| T1059.005 Visual Basic |
GroupWindshift | Windshift has used Visual Basic 6 (VB6) payloads. |
| T1059.005 Visual Basic |
GroupMalteiro | Malteiro has utilized a dropper containing malicious VBS scripts. |
| T1059.005 Visual Basic |
GroupAPT42 | APT42 has used a VBScript to query anti-virus products. |
| T1059.005 Visual Basic |
GroupAPT-C-36 | APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening. |
| T1059.005 Visual Basic |
GroupLazarus Group | Lazarus Group has used VBA and embedded macros in Word documents to execute malicious code. |
| T1059.005 Visual Basic |
GroupEarth Lusca | Earth Lusca used VBA scripts. |
| T1059.005 Visual Basic |
GroupFIN4 | FIN4 has used VBA macros to display a dialog box and collect victim credentials. |
| T1059.005 Visual Basic |
GroupSilence | Silence has used VBS scripts. |
| T1059.005 Visual Basic |
GroupCobalt Group | Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution. |
| T1059.005 Visual Basic |
GroupMolerats | Molerats used various implants, including those built with VBScript, on target machines. |
| T1059.005 Visual Basic |
GroupTransparent Tribe | Transparent Tribe has crafted VBS-based malicious documents. |
| T1059.005 Visual Basic |
GroupInception | Inception has used VBScript to execute malicious commands and payloads. |
| T1059.005 Visual Basic |
GroupHEXANE | HEXANE has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger. |
| T1059.005 Visual Basic |
GroupRancor | Rancor has used VBS scripts as well as embedded macros for execution. |
| T1059.005 Visual Basic |
GroupWIRTE | WIRTE has used VBScript in its operations. |
| T1059.005 Visual Basic |
GroupMagic Hound | Magic Hound malware has used VBS scripts for execution. |
| T1059.005 Visual Basic |
GroupAPT33 | APT33 has used VBScript to initiate the delivery of payloads. |
| T1059.005 Visual Basic |
GroupFIN13 | FIN13 has used VBS scripts for code execution on comrpomised machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.