Real-world descriptions of how a group, tool or campaign used a technique.
42 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.007 JavaScript |
MalwareGRIFFON | GRIFFON is written in and executed as JavaScript. |
| T1059.007 JavaScript |
MalwareKOPILUWAK | KOPILUWAK had used Javascript to perform its core functions. |
| T1059.007 JavaScript |
MalwareTsundere Botnet | Tsundere Botnet has the ability to run JavaScript code from the C2 server. Additionally, Tsundere Botnet has used Node.js to execute JavaScript code for the loader component. |
| T1059.007 JavaScript |
MalwareAppleSeed | AppleSeed has the ability to use JavaScript to execute PowerShell. |
| T1059.007 JavaScript |
MalwareEnvyScout | EnvyScout can write files to disk with JavaScript using a modified version of the open-source tool FileSaver. |
| T1059.007 JavaScript |
MalwareGootloader | Gootloader can execute a Javascript file for initial infection. |
| T1059.007 JavaScript |
MalwareHexEval Loader | HexEval Loader has executed malicious JavaScript code. |
| T1059.007 JavaScript |
MalwareInvisiMole | InvisiMole can use a JavaScript file as part of its execution chain. |
| T1059.007 JavaScript |
MalwareAvaddon | Avaddon has been executed through a malicious JScript downloader. |
| T1059.007 JavaScript |
MalwareSocGholish | The SocGholish payload is executed as JavaScript. |
| T1059.007 JavaScript |
MalwareSpicyOmelette | SpicyOmelette has the ability to execute arbitrary JavaScript code on a compromised host. |
| T1059.007 JavaScript |
MalwareBeaverTail | BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1059.007 JavaScript |
MalwareDarkWatchman | DarkWatchman uses JavaScript to perform its core functionalities. |
| T1059.007 JavaScript |
MalwareXbash | Xbash can execute malicious JavaScript payloads on the victim’s machine. |
| T1059.007 JavaScript |
MalwareNanHaiShu | NanHaiShu executes additional Jscript code on the victim's machine. |
| T1059.007 JavaScript |
MalwareLatrodectus | Latrodectus has used JavaScript files as part its infection chain during malicious spam |
| T1059.007 JavaScript |
MalwareChaes | Chaes has used JavaScript and Node.Js information stealer script that exfiltrates data using the node process. |
| T1059.007 JavaScript |
MalwareBundlore | Bundlore can execute JavaScript by injecting it into the victim's browser. |
| T1059.007 JavaScript |
MalwareGlassWorm | GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript. |
| T1059.007 JavaScript |
MalwareMetamorfo | Metamorfo includes payloads written in JavaScript. |
| T1059.007 JavaScript |
MalwareKONNI | KONNI has executed malicious JavaScript code. |
| T1059.007 JavaScript |
MalwareBlackByte Ransomware | BlackByte Ransomware is distributed as a JavaScript launcher file. |
| T1059.007 JavaScript |
MalwareStrelaStealer | StrelaStealer has been distributed as a malicious JavaScript object. |
| T1059.007 JavaScript |
MalwareWARPWIRE | WARPWIRE is a credential harvester written in JavaScript. |
| T1059.007 JavaScript |
MalwareCobalt Strike | The Cobalt Strike System Profiler can use JavaScript to perform reconnaissance actions. |
| T1059.007 JavaScript |
MalwareValak | Valak can execute JavaScript containing configuration data for establishing persistence. |
| T1059.007 JavaScript |
MalwareAshTag | AshTag can use JSON files to deliver payloads and configuration files. |
| T1059.007 JavaScript |
MalwareShai-Hulud | Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js. |
| T1059.007 JavaScript |
MalwarePOWERSTATS | POWERSTATS can use JavaScript code for execution. |
| T1059.007 JavaScript |
MalwareAstaroth | Astaroth uses JavaScript to perform its core functionalities. |
| T1059.007 JavaScript |
MalwareQakBot | The QakBot web inject module can inject Java Script into web banking pages visited by the victim. |
| T1059.007 JavaScript |
MalwarejRAT | jRAT has been distributed as HTA files with JScript. |
| T1059.007 JavaScript |
MalwareJSS Loader | JSS Loader can download and execute JavaScript files. |
| T1059.007 JavaScript |
MalwareXORIndex Loader | XORIndex Loader has executed malicious JavaScript code. |
| T1059.007 JavaScript |
Toolevilginx2 | evilginx2 can inject JavaScript code into HTML content to customize phishing attacks. |
| T1059.007 JavaScript |
ToolFRP | FRP can support the use of a JSON configuration file. |
| T1059.007 JavaScript |
ToolRemcos | Remcos has the ability to execute JavaScript remotely. |
| T1059.007 JavaScript |
ToolDonut | Donut can generate shellcode outputs that execute via JavaScript or JScript. |
| T1059.007 JavaScript |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has infected victims through malicious pre and post-install scripts within the package.json file. |
| T1059.007 JavaScript |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged JavaScript runtime to execute malicious scripts. |
| T1059.007 JavaScript |
MalwareCanisterWorm | CanisterWorm can leverage stolen tokens to execute Javascsript (deploy.js) for self-propagation. |
| T1059.007 JavaScript |
MalwareKali365 | Kali365 has executed JavaScript within victims' browsers through a React frontend that detects browser sessions to evade automated analysis, auto-copies actor-generated device codes to the victim's clipboard, and polls the actor's C2 infrastructure every three seconds to confirm when OAuth token capture has completed.. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.