Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.005 Mshta |
MalwarePteranodon | Pteranodon can use mshta.exe to execute an HTA file hosted on a remote server. |
| T1218.005 Mshta |
MalwareLumma Stealer | Lumma Stealer has used mshta.exe to execute additional content. |
| T1218.005 Mshta |
MalwareXbash | Xbash can use mshta for executing scripts. |
| T1218.005 Mshta |
MalwareNanHaiShu | NanHaiShu uses mshta.exe to load its program and files. |
| T1218.005 Mshta |
MalwareMetamorfo | Metamorfo has used mshta.exe to execute a HTA payload. |
| T1218.005 Mshta |
MalwareSibot | Sibot has been executed via MSHTA application. |
| T1218.005 Mshta |
MalwareRevenge RAT | Revenge RAT uses mshta.exe to run malicious scripts on the system. |
| T1218.005 Mshta |
MalwareBabyShark | BabyShark has used mshta.exe to download and execute applications from a remote server. |
| T1218.005 Mshta |
MalwarePOWERSTATS | POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts. |
| T1218.005 Mshta |
ToolCovenant | Covenant can create HTA files to install Grunt listeners. |
| T1218.005 Mshta |
ToolKoadic | Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.