Real-world descriptions of how a group, tool or campaign used a technique.
49 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.004 Unix Shell |
MalwareBRICKSTORM | BRICKSTORM has executed shell commands using `/bin/sh`. |
| T1059.004 Unix Shell |
MalwareCOATHANGER | COATHANGER provides a BusyBox reverse shell for command and control. |
| T1059.004 Unix Shell |
MalwareWindTail | WindTail can use the |
| T1059.004 Unix Shell |
MalwareExaramel for Linux | Exaramel for Linux has a command to execute a shell command on the system. |
| T1059.004 Unix Shell |
MalwareCASTLETAP | CASTLETAP has the ability to spawn BusyBox command shell in victim environments. |
| T1059.004 Unix Shell |
MalwareNETWIRE | NETWIRE has the ability to use |
| T1059.004 Unix Shell |
MalwareJ-magic | The J-magic agent is executed through a command line argument which specifies an interface and listening port. |
| T1059.004 Unix Shell |
MalwareGomir | Gomir reads command line arguments and parses them for functionality when executed from a Linux shell, and can execute arbitrary strings passed to it as shell commands. |
| T1059.004 Unix Shell |
MalwareBOLDMOVE | BOLDMOVE is capable of spawning a remote command shell. |
| T1059.004 Unix Shell |
MalwareTurian | Turian has the ability to use |
| T1059.004 Unix Shell |
MalwareHildegard | Hildegard has used shell scripts for execution. |
| T1059.004 Unix Shell |
MalwareCuckoo Stealer | Cuckoo Stealer can spawn a bash shell to enable execution on compromised hosts. |
| T1059.004 Unix Shell |
MalwareSkidmap | Skidmap has used |
| T1059.004 Unix Shell |
MalwareREPTILE | REPTILE can deploy components automatically with shell scripts. |
| T1059.004 Unix Shell |
MalwareDoki | Doki has executed shell scripts with /bin/sh. |
| T1059.004 Unix Shell |
MalwareFysbis | Fysbis has the ability to create and execute commands in a remote shell for CLI. |
| T1059.004 Unix Shell |
MalwareKazuar | Kazuar uses /bin/bash to execute commands on the victim’s machine. |
| T1059.004 Unix Shell |
MalwareGreen Lambert | Green Lambert can use shell scripts for execution, such as |
| T1059.004 Unix Shell |
MalwareSnappyTCP | SnappyTCP creates the reverse shell using a pthread spawning a bash shell. |
| T1059.004 Unix Shell |
MalwareChaos | Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES. |
| T1059.004 Unix Shell |
MalwareAnchor | Anchor can execute payloads via shell scripting. |
| T1059.004 Unix Shell |
MalwarePACEMAKER | PACEMAKER can use a simple bash script for execution. |
| T1059.004 Unix Shell |
MalwareBundlore | Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine. |
| T1059.004 Unix Shell |
MalwareBPFDoor | BPFDoor can create a reverse shell and supports vt100 emulator formatting. |
| T1059.004 Unix Shell |
MalwareDerusbi | Derusbi is capable of creating a remote Bash shell and executing commands. |
| T1059.004 Unix Shell |
MalwareDrovorub | Drovorub can execute arbitrary commands as root on a compromised system. |
| T1059.004 Unix Shell |
MalwarePULSECHECK | PULSECHECK can use Unix shell script for command execution. |
| T1059.004 Unix Shell |
MalwareKobalos | Kobalos can spawn a new pseudo-terminal and execute arbitrary commands at the command prompt. |
| T1059.004 Unix Shell |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses a shell script as the main executable inside an app bundle and drops an embedded base64-encoded payload to the |
| T1059.004 Unix Shell |
MalwareNKAbuse | NKAbuse is initially installed and executed through an initial shell script. |
| T1059.004 Unix Shell |
MalwareMacMa | MacMa can execute supplied shell commands and uses bash scripts to perform additional actions. |
| T1059.004 Unix Shell |
MalwareProton | Proton uses macOS' .command file type to script actions. |
| T1059.004 Unix Shell |
MalwareCallMe | CallMe has the capability to create a reverse shell on victims. |
| T1059.004 Unix Shell |
MalwareRIFLESPINE | RIFLESPINE can execute commands with `/bin/sh`. |
| T1059.004 Unix Shell |
MalwareCoinTicker | CoinTicker executes a bash script to establish a reverse shell. |
| T1059.004 Unix Shell |
MalwarePenquin | Penquin can execute remote commands using bash scripts. |
| T1059.004 Unix Shell |
MalwareEbury | Ebury can use the commands `Xcsh` or `Xcls` to open a shell with Ebury level permissions and `Xxsh` to open a shell with root level. |
| T1059.004 Unix Shell |
MalwareKinsing | Kinsing has used Unix shell scripts to execute commands in the victim environment. |
| T1059.004 Unix Shell |
MalwarePITSTOP | PITSTOP has the ability to receive shell commands over a Unix domain socket. |
| T1059.004 Unix Shell |
MalwareZIPLINE | ZIPLINE can use `/bin/sh` to create a reverse shell and execute commands. |
| T1059.004 Unix Shell |
MalwareShai-Hulud | Shai-Hulud has utilized Linux shell commands to modify configuration files. |
| T1059.004 Unix Shell |
MalwareVIRTUALPITA | VIRTUALPITA has the ability to spawn a bash shell for script execution. |
| T1059.004 Unix Shell |
MalwareXCSSET | XCSSET uses a shell script to execute Mach-o files and |
| T1059.004 Unix Shell |
MalwareAppleJeus | AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms. |
| T1059.004 Unix Shell |
MalwareCookieMiner | CookieMiner has used a Unix shell script to run a series of commands targeting macOS. |
| T1059.004 Unix Shell |
MalwareOSX/Shlayer | OSX/Shlayer can use bash scripts to check the macOS version, download payloads, and extract bytes from files. OSX/Shlayer uses the command |
| T1059.004 Unix Shell |
MalwareLoudMiner | LoudMiner used shell scripts to launch various services and to start/stop the QEMU virtualization. |
| T1059.004 Unix Shell |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting. |
| T1059.004 Unix Shell |
MalwareCanisterWorm | CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.