Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.007 JavaScript |
GroupIndrik Spider | Indrik Spider has used malicious JavaScript files for several components of their attack. |
| T1059.007 JavaScript |
GroupKimsuky | Kimsuky has used JScript for logging and downloading additional tools. Kimsuky has used TRANSLATEXT, which contained four Javascript files for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data. |
| T1059.007 JavaScript |
GroupTA577 | TA577 has used JavaScript to execute additional malicious payloads. |
| T1059.007 JavaScript |
GroupEvilnum | Evilnum has used malicious JavaScript files on the victim's machine. |
| T1059.007 JavaScript |
GroupAPT32 | APT32 has used JavaScript for drive-by downloads and C2 communications. |
| T1059.007 JavaScript |
GroupMuddyWater | MuddyWater has used JavaScript files to execute its POWERSTATS payload. |
| T1059.007 JavaScript |
GroupFIN6 | FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites. |
| T1059.007 JavaScript |
GroupLeafminer | Leafminer infected victims using JavaScript code. |
| T1059.007 JavaScript |
GroupFIN7 | FIN7 used JavaScript scripts to help perform tasks on the victim's machine. |
| T1059.007 JavaScript |
GroupSidewinder | Sidewinder has used JavaScript to drop and execute malware loaders. |
| T1059.007 JavaScript |
GroupMustang Panda | Mustang Panda has executed a JavaScript payload utilizing wscript.exe on the endpoint. |
| T1059.007 JavaScript |
GroupContagious Interview | Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js. |
| T1059.007 JavaScript |
GroupHigaisa | Higaisa used JavaScript to execute additional files. |
| T1059.007 JavaScript |
GroupSaint Bear | Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot. |
| T1059.007 JavaScript |
GroupMoustachedBouncer | MoustachedBouncer has used JavaScript to deliver malware hosted on HTML pages. |
| T1059.007 JavaScript |
GroupWinter Vivern | Winter Vivern delivered malicious JavaScript to exploit targets when exploiting Roundcube Webmail servers. |
| T1059.007 JavaScript |
GroupTurla | Turla has used various JavaScript-based backdoors. |
| T1059.007 JavaScript |
GroupTA505 | TA505 has used JavaScript for code execution. |
| T1059.007 JavaScript |
GroupStar Blizzard | Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework. |
| T1059.007 JavaScript |
GroupTA578 | TA578 has used JavaScript files in malware execution chains. |
| T1059.007 JavaScript |
GroupLazyScripter | LazyScripter has used JavaScript in its attacks. |
| T1059.007 JavaScript |
GroupAPT-C-36 | APT-C-36 has used a fileless attack chain composed of three JavaScript code snippets to execute subsequent payloads. |
| T1059.007 JavaScript |
GroupEarth Lusca | Earth Lusca has manipulated legitimate websites to inject malicious JavaScript code as part of their watering hole operations. |
| T1059.007 JavaScript |
GroupSilence | Silence has used JS scripts. |
| T1059.007 JavaScript |
GroupCobalt Group | Cobalt Group has executed JavaScript scriptlets on the victim's machine. |
| T1059.007 JavaScript |
GroupMolerats | Molerats used various implants, including those built with JS, on target machines. |
| T1059.007 JavaScript |
GroupTeamPCP | TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions. |
| T1059.007 JavaScript |
GroupShinyHunters | ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, ShinyHunters has checked for the authenticode tool using the command `npm list global authenticode`. Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: ` node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' `. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.