ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1218.005×

11 examples

TechniqueUsed byProcedure example
T1218.005
Mshta
MalwarePteranodon

Pteranodon can use mshta.exe to execute an HTA file hosted on a remote server.

T1218.005
Mshta
MalwareLumma Stealer

Lumma Stealer has used mshta.exe to execute additional content.

T1218.005
Mshta
MalwareXbash

Xbash can use mshta for executing scripts.

T1218.005
Mshta
MalwareNanHaiShu

NanHaiShu uses mshta.exe to load its program and files.

T1218.005
Mshta
MalwareMetamorfo

Metamorfo has used mshta.exe to execute a HTA payload.

T1218.005
Mshta
MalwareSibot

Sibot has been executed via MSHTA application.

T1218.005
Mshta
MalwareRevenge RAT

Revenge RAT uses mshta.exe to run malicious scripts on the system.

T1218.005
Mshta
MalwareBabyShark

BabyShark has used mshta.exe to download and execute applications from a remote server.

T1218.005
Mshta
MalwarePOWERSTATS

POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts.

T1218.005
Mshta
ToolCovenant

Covenant can create HTA files to install Grunt listeners.

T1218.005
Mshta
ToolKoadic

Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.