Real-world descriptions of how a group, tool or campaign used a technique.
40 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.006 Python |
MalwarereGeorg | reGeorg is a Python-based web shell. |
| T1059.006 Python |
MalwareInvisibleFerret | InvisibleFerret is written in Python and has used Python scripts for execution. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1059.006 Python |
MalwareUPSTYLE | UPSTYLE is a Python-based application. |
| T1059.006 Python |
MalwarePyDCrypt | PyDCrypt, along with its functions, is written in Python. |
| T1059.006 Python |
MalwareTurian | Turian has the ability to use Python to spawn a Unix shell. |
| T1059.006 Python |
MalwareTHINCRUST | THINCRUST can use Python scripts for command execution. |
| T1059.006 Python |
MalwareMachete | Machete is written in Python and is used in conjunction with additional Python scripts. |
| T1059.006 Python |
MalwareDropBook | DropBook is a Python-based backdoor compiled with PyInstaller. |
| T1059.006 Python |
MalwareKeydnap | Keydnap uses Python for scripting to execute additional commands. |
| T1059.006 Python |
MalwarePUNCHBUGGY | PUNCHBUGGY has used python scripts. |
| T1059.006 Python |
MalwareKeyBoy | KeyBoy uses Python scripts for installing files and performing execution. |
| T1059.006 Python |
MalwareLumma Stealer | Lumma Stealer has used malicious Python scripts to execute payloads. |
| T1059.006 Python |
MalwareChaes | Chaes has used Python scripts for execution and the installation of additional files. |
| T1059.006 Python |
MalwareBundlore | Bundlore has used Python scripts to execute payloads. |
| T1059.006 Python |
MalwareVIRTUALPIE | VIRTUALPIE is a Python-based backdoor malware. |
| T1059.006 Python |
MalwareBandook | Bandook can support commands to execute Python-based payloads. |
| T1059.006 Python |
MalwarePysa | Pysa has used Python scripts to deploy ransomware. |
| T1059.006 Python |
MalwareSpeakUp | SpeakUp uses Python scripts. |
| T1059.006 Python |
MalwareCobalt Strike | Cobalt Strike can use Python to perform execution. |
| T1059.006 Python |
MalwareNeo-reGeorg | Neo-reGeorg is a Python-based web shell. |
| T1059.006 Python |
MalwareFRAMESTING | FRAMESTING is a Python web shell that can embed in the Ivanti Connect Secure CAV Python package. |
| T1059.006 Python |
MalwareLAMEHUG | LAMEHUG can use Python scripts for execution. |
| T1059.006 Python |
MalwarePoetRAT | PoetRAT was executed with a Python script and worked in conjunction with additional Python-based post-exploitation tools. |
| T1059.006 Python |
MalwareCoinTicker | CoinTicker executes a Python script to download its second stage. |
| T1059.006 Python |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has searched the contents of two Python files scanner.py and scanner_legacy.py by searching for specific lines and replacing them with values that reduce their ability to track mismatches or new files. |
| T1059.006 Python |
MalwareEbury | Ebury has used Python to implement its DGA. |
| T1059.006 Python |
MalwareVIRTUALPITA | VIRTUALPITA can call a Python script to run commands on a targeted guest virtual machine. |
| T1059.006 Python |
MalwareMechaFlounder | MechaFlounder uses a python-based payload. |
| T1059.006 Python |
MalwareDRYHOOK | DRYHOOK is a Python-based script that executes within the victim environment. |
| T1059.006 Python |
MalwareCookieMiner | CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre. |
| T1059.006 Python |
MalwareLizar | Lizar has used Python scripts (ps2x.py script and ps2p.py) to execute files on remote hosts using the Impacket library. |
| T1059.006 Python |
MalwareSmall Sieve | Small Sieve can use Python scripts to execute commands. |
| T1059.006 Python |
ToolSILENTTRINITY | SILENTTRINITY is written in Python and can use multiple Python scripts for execution on targeted systems. |
| T1059.006 Python |
ToolRemcos | Remcos uses Python scripts. |
| T1059.006 Python |
ToolDonut | Donut can generate shellcode outputs that execute via Python. |
| T1059.006 Python |
ToolIronNetInjector | IronNetInjector can use IronPython scripts to load payloads with the help of a .NET injector. |
| T1059.006 Python |
ToolPupy | Pupy can use an add on feature when creating payloads that allows you to create custom Python scripts (“scriptlets”) to perform tasks offline (without requiring a session) such as sandbox detection, adding persistence, etc. |
| T1059.006 Python |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has leveraged Python scripts to download additional payloads, engage in discovery, and to establish persistence. |
| T1059.006 Python |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized Python scripts to execute payloads. |
| T1059.006 Python |
MalwareCanisterWorm | CanisterWorm has used a Python script as a second-stage backdoor. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.