ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.005×

46 examples

TechniqueUsed byProcedure example
T1059.005
Visual Basic
GroupAPT38

APT38 has used VBScript to execute commands and other operational tasks.

T1059.005
Visual Basic
GroupSideCopy

SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`.

T1059.005
Visual Basic
GroupKimsuky

Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT.

T1059.005
Visual Basic
GroupPatchwork

Patchwork used Visual Basic Scripts (VBS) on victim machines.

T1059.005
Visual Basic
GroupGorgon Group

Gorgon Group has used macros in Spearphishing Attachments as well as executed VBScripts on victim machines.

T1059.005
Visual Basic
GroupAPT32

APT32 has used macros, COM scriptlets, and VBS scripts.

T1059.005
Visual Basic
GroupMuddyWater

MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.

T1059.005
Visual Basic
GroupGamaredon Group

Gamaredon Group has embedded malicious macros in document templates, which executed VBScript. Gamaredon Group has also delivered Microsoft Outlook VBA projects with embedded macros. Additionally, Gamaredon Group has executed VBScript files using wscript.exe.

T1059.005
Visual Basic
GroupFIN7

FIN7 used VBS scripts to help perform tasks on the victim's machine.

T1059.005
Visual Basic
GroupSandworm Team

Sandworm Team has created VBScripts to run an SSH server.

T1059.005
Visual Basic
GroupMachete

Machete has embedded malicious macros within spearphishing attachments to download additional files.

T1059.005
Visual Basic
GroupSidewinder

Sidewinder has used VBScript to drop and execute malware loaders.

T1059.005
Visual Basic
GroupMustang Panda

Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on.

T1059.005
Visual Basic
GroupAPT39

APT39 has utilized malicious VBS scripts in malware.

T1059.005
Visual Basic
GroupContagious Interview

Contagious Interview has utilized Visual Basic scripts in the execution of their downloader malware targeting Windows devices including as script called update.vbs.

T1059.005
Visual Basic
GroupTA2541

TA2541 has used VBS files to execute or establish persistence for additional payloads, often using file names consistent with email themes or mimicking system functionality.

T1059.005
Visual Basic
GroupAPT37

APT37 executes shellcode and a VBA script to decode Base64 strings.

T1059.005
Visual Basic
GroupOilRig

OilRig has used VBScript macros for execution on compromised hosts.

T1059.005
Visual Basic
GroupHigaisa

Higaisa has used VBScript code on the victim's machine.

T1059.005
Visual Basic
GroupTA459

TA459 has a VBScript for execution.

T1059.005
Visual Basic
GroupConfucius

Confucius has used VBScript to execute malicious code.

T1059.005
Visual Basic
GroupLeviathan

Leviathan has used VBScript.

T1059.005
Visual Basic
GroupTurla

Turla has used VBS scripts throughout its operations.

T1059.005
Visual Basic
GroupTA505

TA505 has used VBS for code execution.

T1059.005
Visual Basic
GroupRedCurl

RedCurl has used VBScript to run malicious files.

T1059.005
Visual Basic
GroupMirrorFace

MirrorFace has used remote templates with VBA code in malware infection chains.

T1059.005
Visual Basic
GroupBRONZE BUTLER

BRONZE BUTLER has used VBS and VBE scripts for execution.

T1059.005
Visual Basic
GroupLazyScripter

LazyScripter has used VBScript to execute malicious code.

T1059.005
Visual Basic
GroupWindshift

Windshift has used Visual Basic 6 (VB6) payloads.

T1059.005
Visual Basic
GroupMalteiro

Malteiro has utilized a dropper containing malicious VBS scripts.

T1059.005
Visual Basic
GroupAPT42

APT42 has used a VBScript to query anti-virus products.

T1059.005
Visual Basic
GroupAPT-C-36

APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening.

T1059.005
Visual Basic
GroupLazarus Group

Lazarus Group has used VBA and embedded macros in Word documents to execute malicious code.

T1059.005
Visual Basic
GroupEarth Lusca

Earth Lusca used VBA scripts.

T1059.005
Visual Basic
GroupFIN4

FIN4 has used VBA macros to display a dialog box and collect victim credentials.

T1059.005
Visual Basic
GroupSilence

Silence has used VBS scripts.

T1059.005
Visual Basic
GroupCobalt Group

Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution.

T1059.005
Visual Basic
GroupMolerats

Molerats used various implants, including those built with VBScript, on target machines.

T1059.005
Visual Basic
GroupTransparent Tribe

Transparent Tribe has crafted VBS-based malicious documents.

T1059.005
Visual Basic
GroupInception

Inception has used VBScript to execute malicious commands and payloads.

T1059.005
Visual Basic
GroupHEXANE

HEXANE has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger.

T1059.005
Visual Basic
GroupRancor

Rancor has used VBS scripts as well as embedded macros for execution.

T1059.005
Visual Basic
GroupWIRTE

WIRTE has used VBScript in its operations.

T1059.005
Visual Basic
GroupMagic Hound

Magic Hound malware has used VBS scripts for execution.

T1059.005
Visual Basic
GroupAPT33

APT33 has used VBScript to initiate the delivery of payloads.

T1059.005
Visual Basic
GroupFIN13

FIN13 has used VBS scripts for code execution on comrpomised machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.