Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the python.exe interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.
Python comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Adversaries can use these libraries to download and execute commands or other scripts as well as perform various malicious behaviors.
Rules on DetectionCode tagged with T1059.006.
| Rule | Level | Log source |
|---|---|---|
| Python One-Liners with Base64 Decoding | high | windows / process_creation |
| Python One-Liners with Base64 Decoding - Linux | high | linux / process_creation |
| AppLocker Application Would Have Been Blocked | medium | windows / NULL |
| AppLocker Prevented Application or Script from Running | medium | windows / NULL |
| Suspicious File Characteristics Due to Missing Fields | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Python Network Traffic During Package Build | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 3 |
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 has developed malware variants written in Python. |
| GroupAPT37 | APT37 has used Python scripts to execute payloads. |
| GroupAPT39 | APT39 has used a command line utility and a network scanner written in python. |
| GroupBRONZE BUTLER | BRONZE BUTLER has made use of Python-based remote access tools. |
| GroupCinnamon Tempest | Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files. |
| GroupContagious Interview | Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules. |
| GroupDragonfly | Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim. |
| GroupEarth Lusca | Earth Lusca used Python scripts for port scanning or building reverse shells. |
| Used by | Procedure example |
|---|---|
| MalwareBandook | Bandook can support commands to execute Python-based payloads. |
| MalwareBundlore | Bundlore has used Python scripts to execute payloads. |
| MalwareCanisterWorm | CanisterWorm has used a Python script as a second-stage backdoor. |
| MalwareChaes | Chaes has used Python scripts for execution and the installation of additional files. |
| MalwareCobalt Strike | Cobalt Strike can use Python to perform execution. |
| MalwareCoinTicker | CoinTicker executes a Python script to download its second stage. |
| MalwareCookieMiner | CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre. |
| ToolDonut | Donut can generate shellcode outputs that execute via Python. |
| Used by | Procedure example |
|---|---|
| CampaignCutting Edge | During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool. |
| CampaignOperation Wocao | During Operation Wocao, threat actors' backdoors were written in Python and compiled with py2exe. |
| CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used custom applications developed in python. |
| CampaignShadowRay | During ShadowRay, threat actors used the Python `pty` module to open reverse shells. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.