Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.006 Python |
GroupKimsuky | Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data. |
| T1059.006 Python |
GroupDragonfly | Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim. |
| T1059.006 Python |
GroupMuddyWater | MuddyWater has developed tools in Python including Out1. |
| T1059.006 Python |
GroupMachete | Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python. |
| T1059.006 Python |
GroupZIRCONIUM | ZIRCONIUM has used Python-based implants to interact with compromised hosts. |
| T1059.006 Python |
GroupRocke | Rocke has used Python-based malware to install and spread their coinminer. |
| T1059.006 Python |
GroupAPT39 | APT39 has used a command line utility and a network scanner written in python. |
| T1059.006 Python |
GroupUNC3886 | UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs. |
| T1059.006 Python |
GroupContagious Interview | Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules. |
| T1059.006 Python |
GroupAPT37 | APT37 has used Python scripts to execute payloads. |
| T1059.006 Python |
GroupTurla | Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads. |
| T1059.006 Python |
GroupRedCurl | RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445. |
| T1059.006 Python |
GroupAPT29 | APT29 has developed malware variants written in Python. |
| T1059.006 Python |
GroupCinnamon Tempest | Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files. |
| T1059.006 Python |
GroupBRONZE BUTLER | BRONZE BUTLER has made use of Python-based remote access tools. |
| T1059.006 Python |
GroupTonto Team | Tonto Team has used Python-based tools for execution. |
| T1059.006 Python |
GroupEarth Lusca | Earth Lusca used Python scripts for port scanning or building reverse shells. |
| T1059.006 Python |
GroupVOID MANTICORE | VOID MANTICORE has utilized Python scripts to execute its malicious payloads. |
| T1059.006 Python |
GroupTeamPCP | TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.