ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.006×

19 examples

TechniqueUsed byProcedure example
T1059.006
Python
GroupKimsuky

Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data.

T1059.006
Python
GroupDragonfly

Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim.

T1059.006
Python
GroupMuddyWater

MuddyWater has developed tools in Python including Out1.

T1059.006
Python
GroupMachete

Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python.

T1059.006
Python
GroupZIRCONIUM

ZIRCONIUM has used Python-based implants to interact with compromised hosts.

T1059.006
Python
GroupRocke

Rocke has used Python-based malware to install and spread their coinminer.

T1059.006
Python
GroupAPT39

APT39 has used a command line utility and a network scanner written in python.

T1059.006
Python
GroupUNC3886

UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs.

T1059.006
Python
GroupContagious Interview

Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules.

T1059.006
Python
GroupAPT37

APT37 has used Python scripts to execute payloads.

T1059.006
Python
GroupTurla

Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads.

T1059.006
Python
GroupRedCurl

RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445.

T1059.006
Python
GroupAPT29

APT29 has developed malware variants written in Python.

T1059.006
Python
GroupCinnamon Tempest

Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files.

T1059.006
Python
GroupBRONZE BUTLER

BRONZE BUTLER has made use of Python-based remote access tools.

T1059.006
Python
GroupTonto Team

Tonto Team has used Python-based tools for execution.

T1059.006
Python
GroupEarth Lusca

Earth Lusca used Python scripts for port scanning or building reverse shells.

T1059.006
Python
GroupVOID MANTICORE

VOID MANTICORE has utilized Python scripts to execute its malicious payloads.

T1059.006
Python
GroupTeamPCP

TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.