ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.007×

28 examples

TechniqueUsed byProcedure example
T1059.007
JavaScript
GroupIndrik Spider

Indrik Spider has used malicious JavaScript files for several components of their attack.

T1059.007
JavaScript
GroupKimsuky

Kimsuky has used JScript for logging and downloading additional tools. Kimsuky has used TRANSLATEXT, which contained four Javascript files for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data.

T1059.007
JavaScript
GroupTA577

TA577 has used JavaScript to execute additional malicious payloads.

T1059.007
JavaScript
GroupEvilnum

Evilnum has used malicious JavaScript files on the victim's machine.

T1059.007
JavaScript
GroupAPT32

APT32 has used JavaScript for drive-by downloads and C2 communications.

T1059.007
JavaScript
GroupMuddyWater

MuddyWater has used JavaScript files to execute its POWERSTATS payload.

T1059.007
JavaScript
GroupFIN6

FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites.

T1059.007
JavaScript
GroupLeafminer

Leafminer infected victims using JavaScript code.

T1059.007
JavaScript
GroupFIN7

FIN7 used JavaScript scripts to help perform tasks on the victim's machine.

T1059.007
JavaScript
GroupSidewinder

Sidewinder has used JavaScript to drop and execute malware loaders.

T1059.007
JavaScript
GroupMustang Panda

Mustang Panda has executed a JavaScript payload utilizing wscript.exe on the endpoint.

T1059.007
JavaScript
GroupContagious Interview

Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js.

T1059.007
JavaScript
GroupHigaisa

Higaisa used JavaScript to execute additional files.

T1059.007
JavaScript
GroupSaint Bear

Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot.

T1059.007
JavaScript
GroupMoustachedBouncer

MoustachedBouncer has used JavaScript to deliver malware hosted on HTML pages.

T1059.007
JavaScript
GroupWinter Vivern

Winter Vivern delivered malicious JavaScript to exploit targets when exploiting Roundcube Webmail servers.

T1059.007
JavaScript
GroupTurla

Turla has used various JavaScript-based backdoors.

T1059.007
JavaScript
GroupTA505

TA505 has used JavaScript for code execution.

T1059.007
JavaScript
GroupStar Blizzard

Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework.

T1059.007
JavaScript
GroupTA578

TA578 has used JavaScript files in malware execution chains.

T1059.007
JavaScript
GroupLazyScripter

LazyScripter has used JavaScript in its attacks.

T1059.007
JavaScript
GroupAPT-C-36

APT-C-36 has used a fileless attack chain composed of three JavaScript code snippets to execute subsequent payloads.

T1059.007
JavaScript
GroupEarth Lusca

Earth Lusca has manipulated legitimate websites to inject malicious JavaScript code as part of their watering hole operations.

T1059.007
JavaScript
GroupSilence

Silence has used JS scripts.

T1059.007
JavaScript
GroupCobalt Group

Cobalt Group has executed JavaScript scriptlets on the victim's machine.

T1059.007
JavaScript
GroupMolerats

Molerats used various implants, including those built with JS, on target machines.

T1059.007
JavaScript
GroupTeamPCP

TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions.

T1059.007
JavaScript
GroupShinyHunters

ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, ShinyHunters has checked for the authenticode tool using the command `npm list global authenticode`. Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: ` node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' `.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.