ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.007×

42 examples

TechniqueUsed byProcedure example
T1059.007
JavaScript
MalwareGRIFFON

GRIFFON is written in and executed as JavaScript.

T1059.007
JavaScript
MalwareKOPILUWAK

KOPILUWAK had used Javascript to perform its core functions.

T1059.007
JavaScript
MalwareTsundere Botnet

Tsundere Botnet has the ability to run JavaScript code from the C2 server. Additionally, Tsundere Botnet has used Node.js to execute JavaScript code for the loader component.

T1059.007
JavaScript
MalwareAppleSeed

AppleSeed has the ability to use JavaScript to execute PowerShell.

T1059.007
JavaScript
MalwareEnvyScout

EnvyScout can write files to disk with JavaScript using a modified version of the open-source tool FileSaver.

T1059.007
JavaScript
MalwareGootloader

Gootloader can execute a Javascript file for initial infection.

T1059.007
JavaScript
MalwareHexEval Loader

HexEval Loader has executed malicious JavaScript code.

T1059.007
JavaScript
MalwareInvisiMole

InvisiMole can use a JavaScript file as part of its execution chain.

T1059.007
JavaScript
MalwareAvaddon

Avaddon has been executed through a malicious JScript downloader.

T1059.007
JavaScript
MalwareSocGholish

The SocGholish payload is executed as JavaScript.

T1059.007
JavaScript
MalwareSpicyOmelette

SpicyOmelette has the ability to execute arbitrary JavaScript code on a compromised host.

T1059.007
JavaScript
MalwareBeaverTail

BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS.

T1059.007
JavaScript
MalwareDarkWatchman

DarkWatchman uses JavaScript to perform its core functionalities.

T1059.007
JavaScript
MalwareXbash

Xbash can execute malicious JavaScript payloads on the victim’s machine.

T1059.007
JavaScript
MalwareNanHaiShu

NanHaiShu executes additional Jscript code on the victim's machine.

T1059.007
JavaScript
MalwareLatrodectus

Latrodectus has used JavaScript files as part its infection chain during malicious spam
email campaigns.

T1059.007
JavaScript
MalwareChaes

Chaes has used JavaScript and Node.Js information stealer script that exfiltrates data using the node process.

T1059.007
JavaScript
MalwareBundlore

Bundlore can execute JavaScript by injecting it into the victim's browser.

T1059.007
JavaScript
MalwareGlassWorm

GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript.

T1059.007
JavaScript
MalwareMetamorfo

Metamorfo includes payloads written in JavaScript.

T1059.007
JavaScript
MalwareKONNI

KONNI has executed malicious JavaScript code.

T1059.007
JavaScript
MalwareBlackByte Ransomware

BlackByte Ransomware is distributed as a JavaScript launcher file.

T1059.007
JavaScript
MalwareStrelaStealer

StrelaStealer has been distributed as a malicious JavaScript object.

T1059.007
JavaScript
MalwareWARPWIRE

WARPWIRE is a credential harvester written in JavaScript.

T1059.007
JavaScript
MalwareCobalt Strike

The Cobalt Strike System Profiler can use JavaScript to perform reconnaissance actions.

T1059.007
JavaScript
MalwareValak

Valak can execute JavaScript containing configuration data for establishing persistence.

T1059.007
JavaScript
MalwareAshTag

AshTag can use JSON files to deliver payloads and configuration files.

T1059.007
JavaScript
MalwareShai-Hulud

Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js.

T1059.007
JavaScript
MalwarePOWERSTATS

POWERSTATS can use JavaScript code for execution.

T1059.007
JavaScript
MalwareAstaroth

Astaroth uses JavaScript to perform its core functionalities.

T1059.007
JavaScript
MalwareQakBot

The QakBot web inject module can inject Java Script into web banking pages visited by the victim.

T1059.007
JavaScript
MalwarejRAT

jRAT has been distributed as HTA files with JScript.

T1059.007
JavaScript
MalwareJSS Loader

JSS Loader can download and execute JavaScript files.

T1059.007
JavaScript
MalwareXORIndex Loader

XORIndex Loader has executed malicious JavaScript code.

T1059.007
JavaScript
Toolevilginx2

evilginx2 can inject JavaScript code into HTML content to customize phishing attacks.

T1059.007
JavaScript
ToolFRP

FRP can support the use of a JSON configuration file.

T1059.007
JavaScript
ToolRemcos

Remcos has the ability to execute JavaScript remotely.

T1059.007
JavaScript
ToolDonut

Donut can generate shellcode outputs that execute via JavaScript or JScript.

T1059.007
JavaScript
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has infected victims through malicious pre and post-install scripts within the package.json file.

T1059.007
JavaScript
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged JavaScript runtime to execute malicious scripts.

T1059.007
JavaScript
MalwareCanisterWorm

CanisterWorm can leverage stolen tokens to execute Javascsript (deploy.js) for self-propagation.

T1059.007
JavaScript
MalwareKali365

Kali365 has executed JavaScript within victims' browsers through a React frontend that detects browser sessions to evade automated analysis, auto-copies actor-generated device codes to the victim's clipboard, and polls the actor's C2 infrastructure every three seconds to confirm when OAuth token capture has completed..

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.