Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.005 Mshta |
GroupAPT38 | APT38 has used a renamed version of `mshta.exe` to execute malicious HTML files. |
| T1218.005 Mshta |
GroupSideCopy | SideCopy has utilized `mshta.exe` to execute a malicious hta file. |
| T1218.005 Mshta |
GroupKimsuky | Kimsuky has used mshta.exe to run malicious scripts on the system. |
| T1218.005 Mshta |
GroupAPT32 | APT32 has used mshta.exe for code execution. |
| T1218.005 Mshta |
GroupMuddyWater | MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution. |
| T1218.005 Mshta |
GroupGamaredon Group | Gamaredon Group has used `mshta.exe` to execute malicious files. |
| T1218.005 Mshta |
GroupFIN7 | FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems. |
| T1218.005 Mshta |
GroupSidewinder | Sidewinder has used |
| T1218.005 Mshta |
GroupMustang Panda | Mustang Panda has used mshta.exe to launch collection scripts. |
| T1218.005 Mshta |
GroupTA2541 | TA2541 has used `mshta` to execute scripts including VBS. |
| T1218.005 Mshta |
GroupConfucius | Confucius has used mshta.exe to execute malicious VBScript. |
| T1218.005 Mshta |
GroupAPT29 | APT29 has use `mshta` to execute malicious scripts on a compromised host. |
| T1218.005 Mshta |
GroupTA551 | TA551 has used mshta.exe to execute malicious payloads. |
| T1218.005 Mshta |
GroupLazyScripter | LazyScripter has used `mshta.exe` to execute Koadic stagers. |
| T1218.005 Mshta |
GroupLazarus Group | Lazarus Group has used |
| T1218.005 Mshta |
GroupEarth Lusca | Earth Lusca has used `mshta.exe` to load an HTA script within a malicious .LNK file. |
| T1218.005 Mshta |
GroupInception | Inception has used malicious HTA files to drop and execute malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.