ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.004×

49 examples

TechniqueUsed byProcedure example
T1059.004
Unix Shell
MalwareBRICKSTORM

BRICKSTORM has executed shell commands using `/bin/sh`.

T1059.004
Unix Shell
MalwareCOATHANGER

COATHANGER provides a BusyBox reverse shell for command and control.

T1059.004
Unix Shell
MalwareWindTail

WindTail can use the open command to execute an application.

T1059.004
Unix Shell
MalwareExaramel for Linux

Exaramel for Linux has a command to execute a shell command on the system.

T1059.004
Unix Shell
MalwareCASTLETAP

CASTLETAP has the ability to spawn BusyBox command shell in victim environments.

T1059.004
Unix Shell
MalwareNETWIRE

NETWIRE has the ability to use /bin/bash and /bin/sh to execute commands.

T1059.004
Unix Shell
MalwareJ-magic

The J-magic agent is executed through a command line argument which specifies an interface and listening port.

T1059.004
Unix Shell
MalwareGomir

Gomir reads command line arguments and parses them for functionality when executed from a Linux shell, and can execute arbitrary strings passed to it as shell commands.

T1059.004
Unix Shell
MalwareBOLDMOVE

BOLDMOVE is capable of spawning a remote command shell.

T1059.004
Unix Shell
MalwareTurian

Turian has the ability to use /bin/sh to execute commands.

T1059.004
Unix Shell
MalwareHildegard

Hildegard has used shell scripts for execution.

T1059.004
Unix Shell
MalwareCuckoo Stealer

Cuckoo Stealer can spawn a bash shell to enable execution on compromised hosts.

T1059.004
Unix Shell
MalwareSkidmap

Skidmap has used pm.sh to download and install its main payload.

T1059.004
Unix Shell
MalwareREPTILE

REPTILE can deploy components automatically with shell scripts.

T1059.004
Unix Shell
MalwareDoki

Doki has executed shell scripts with /bin/sh.

T1059.004
Unix Shell
MalwareFysbis

Fysbis has the ability to create and execute commands in a remote shell for CLI.

T1059.004
Unix Shell
MalwareKazuar

Kazuar uses /bin/bash to execute commands on the victim’s machine.

T1059.004
Unix Shell
MalwareGreen Lambert

Green Lambert can use shell scripts for execution, such as /bin/sh -c.

T1059.004
Unix Shell
MalwareSnappyTCP

SnappyTCP creates the reverse shell using a pthread spawning a bash shell.

T1059.004
Unix Shell
MalwareChaos

Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES.

T1059.004
Unix Shell
MalwareAnchor

Anchor can execute payloads via shell scripting.

T1059.004
Unix Shell
MalwarePACEMAKER

PACEMAKER can use a simple bash script for execution.

T1059.004
Unix Shell
MalwareBundlore

Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine.

T1059.004
Unix Shell
MalwareBPFDoor

BPFDoor can create a reverse shell and supports vt100 emulator formatting.

T1059.004
Unix Shell
MalwareDerusbi

Derusbi is capable of creating a remote Bash shell and executing commands.

T1059.004
Unix Shell
MalwareDrovorub

Drovorub can execute arbitrary commands as root on a compromised system.

T1059.004
Unix Shell
MalwarePULSECHECK

PULSECHECK can use Unix shell script for command execution.

T1059.004
Unix Shell
MalwareKobalos

Kobalos can spawn a new pseudo-terminal and execute arbitrary commands at the command prompt.

T1059.004
Unix Shell
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the /tmp folder.

T1059.004
Unix Shell
MalwareNKAbuse

NKAbuse is initially installed and executed through an initial shell script.

T1059.004
Unix Shell
MalwareMacMa

MacMa can execute supplied shell commands and uses bash scripts to perform additional actions.

T1059.004
Unix Shell
MalwareProton

Proton uses macOS' .command file type to script actions.

T1059.004
Unix Shell
MalwareCallMe

CallMe has the capability to create a reverse shell on victims.

T1059.004
Unix Shell
MalwareRIFLESPINE

RIFLESPINE can execute commands with `/bin/sh`.

T1059.004
Unix Shell
MalwareCoinTicker

CoinTicker executes a bash script to establish a reverse shell.

T1059.004
Unix Shell
MalwarePenquin

Penquin can execute remote commands using bash scripts.

T1059.004
Unix Shell
MalwareEbury

Ebury can use the commands `Xcsh` or `Xcls` to open a shell with Ebury level permissions and `Xxsh` to open a shell with root level.

T1059.004
Unix Shell
MalwareKinsing

Kinsing has used Unix shell scripts to execute commands in the victim environment.

T1059.004
Unix Shell
MalwarePITSTOP

PITSTOP has the ability to receive shell commands over a Unix domain socket.

T1059.004
Unix Shell
MalwareZIPLINE

ZIPLINE can use `/bin/sh` to create a reverse shell and execute commands.

T1059.004
Unix Shell
MalwareShai-Hulud

Shai-Hulud has utilized Linux shell commands to modify configuration files.

T1059.004
Unix Shell
MalwareVIRTUALPITA

VIRTUALPITA has the ability to spawn a bash shell for script execution.

T1059.004
Unix Shell
MalwareXCSSET

XCSSET uses a shell script to execute Mach-o files and osacompile commands such as, osacompile -x -o xcode.app main.applescript.

T1059.004
Unix Shell
MalwareAppleJeus

AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms.

T1059.004
Unix Shell
MalwareCookieMiner

CookieMiner has used a Unix shell script to run a series of commands targeting macOS.

T1059.004
Unix Shell
MalwareOSX/Shlayer

OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command sh -c tail -c +1381... to extract bytes at an offset from a specified file. OSX/Shlayer uses the curl -fsL "$url" >$tmp_path command to download malicious payloads into a temporary directory.

T1059.004
Unix Shell
MalwareLoudMiner

LoudMiner used shell scripts to launch various services and to start/stop the QEMU virtualization.

T1059.004
Unix Shell
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting.

T1059.004
Unix Shell
MalwareCanisterWorm

CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.