ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.006×

40 examples

TechniqueUsed byProcedure example
T1059.006
Python
MalwarereGeorg

reGeorg is a Python-based web shell.

T1059.006
Python
MalwareInvisibleFerret

InvisibleFerret is written in Python and has used Python scripts for execution.

T1059.006
Python
MalwareUPSTYLE

UPSTYLE is a Python-based application.

T1059.006
Python
MalwarePyDCrypt

PyDCrypt, along with its functions, is written in Python.

T1059.006
Python
MalwareTurian

Turian has the ability to use Python to spawn a Unix shell.

T1059.006
Python
MalwareTHINCRUST

THINCRUST can use Python scripts for command execution.

T1059.006
Python
MalwareMachete

Machete is written in Python and is used in conjunction with additional Python scripts.

T1059.006
Python
MalwareDropBook

DropBook is a Python-based backdoor compiled with PyInstaller.

T1059.006
Python
MalwareKeydnap

Keydnap uses Python for scripting to execute additional commands.

T1059.006
Python
MalwarePUNCHBUGGY

PUNCHBUGGY has used python scripts.

T1059.006
Python
MalwareKeyBoy

KeyBoy uses Python scripts for installing files and performing execution.

T1059.006
Python
MalwareLumma Stealer

Lumma Stealer has used malicious Python scripts to execute payloads.

T1059.006
Python
MalwareChaes

Chaes has used Python scripts for execution and the installation of additional files.

T1059.006
Python
MalwareBundlore

Bundlore has used Python scripts to execute payloads.

T1059.006
Python
MalwareVIRTUALPIE

VIRTUALPIE is a Python-based backdoor malware.

T1059.006
Python
MalwareBandook

Bandook can support commands to execute Python-based payloads.

T1059.006
Python
MalwarePysa

Pysa has used Python scripts to deploy ransomware.

T1059.006
Python
MalwareSpeakUp

SpeakUp uses Python scripts.

T1059.006
Python
MalwareCobalt Strike

Cobalt Strike can use Python to perform execution.

T1059.006
Python
MalwareNeo-reGeorg

Neo-reGeorg is a Python-based web shell.

T1059.006
Python
MalwareFRAMESTING

FRAMESTING is a Python web shell that can embed in the Ivanti Connect Secure CAV Python package.

T1059.006
Python
MalwareLAMEHUG

LAMEHUG can use Python scripts for execution.

T1059.006
Python
MalwarePoetRAT

PoetRAT was executed with a Python script and worked in conjunction with additional Python-based post-exploitation tools.

T1059.006
Python
MalwareCoinTicker

CoinTicker executes a Python script to download its second stage.

T1059.006
Python
MalwareSPAWNCHIMERA

SPAWNCHIMERA has searched the contents of two Python files scanner.py and scanner_legacy.py by searching for specific lines and replacing them with values that reduce their ability to track mismatches or new files.

T1059.006
Python
MalwareEbury

Ebury has used Python to implement its DGA.

T1059.006
Python
MalwareVIRTUALPITA

VIRTUALPITA can call a Python script to run commands on a targeted guest virtual machine.

T1059.006
Python
MalwareMechaFlounder

MechaFlounder uses a python-based payload.

T1059.006
Python
MalwareDRYHOOK

DRYHOOK is a Python-based script that executes within the victim environment.

T1059.006
Python
MalwareCookieMiner

CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre.

T1059.006
Python
MalwareLizar

Lizar has used Python scripts (ps2x.py script and ps2p.py) to execute files on remote hosts using the Impacket library.

T1059.006
Python
MalwareSmall Sieve

Small Sieve can use Python scripts to execute commands.

T1059.006
Python
ToolSILENTTRINITY

SILENTTRINITY is written in Python and can use multiple Python scripts for execution on targeted systems.

T1059.006
Python
ToolRemcos

Remcos uses Python scripts.

T1059.006
Python
ToolDonut

Donut can generate shellcode outputs that execute via Python.

T1059.006
Python
ToolIronNetInjector

IronNetInjector can use IronPython scripts to load payloads with the help of a .NET injector.

T1059.006
Python
ToolPupy

Pupy can use an add on feature when creating payloads that allows you to create custom Python scripts (“scriptlets”) to perform tasks offline (without requiring a session) such as sandbox detection, adding persistence, etc.

T1059.006
Python
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has leveraged Python scripts to download additional payloads, engage in discovery, and to establish persistence.

T1059.006
Python
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Python scripts to execute payloads.

T1059.006
Python
MalwareCanisterWorm

CanisterWorm has used a Python script as a second-stage backdoor.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.