Python

T1059.006

Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org

About this technique

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the python.exe interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.

Python comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Adversaries can use these libraries to download and execute commands or other scripts as well as perform various malicious behaviors.

Detection rules6

Rules on DetectionCode tagged with T1059.006.

Sigma5

Splunk1

RuleTypeRiskData source
Python Network Traffic During Package BuildAnomalyNULLSysmon EventID 1 AND Sysmon EventID 3

Groups19

Software40

Show 16 more

Campaigns4

Procedure examples63

Groups19

Used byProcedure example
GroupAPT29

APT29 has developed malware variants written in Python.

GroupAPT37

APT37 has used Python scripts to execute payloads.

GroupAPT39

APT39 has used a command line utility and a network scanner written in python.

GroupBRONZE BUTLER

BRONZE BUTLER has made use of Python-based remote access tools.

GroupCinnamon Tempest

Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files.

GroupContagious Interview

Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules.

GroupDragonfly

Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim.

GroupEarth Lusca

Earth Lusca used Python scripts for port scanning or building reverse shells.

View all 19 groups examples

Software40

Used byProcedure example
MalwareBandook

Bandook can support commands to execute Python-based payloads.

MalwareBundlore

Bundlore has used Python scripts to execute payloads.

MalwareCanisterWorm

CanisterWorm has used a Python script as a second-stage backdoor.

MalwareChaes

Chaes has used Python scripts for execution and the installation of additional files.

MalwareCobalt Strike

Cobalt Strike can use Python to perform execution.

MalwareCoinTicker

CoinTicker executes a Python script to download its second stage.

MalwareCookieMiner

CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre.

ToolDonut

Donut can generate shellcode outputs that execute via Python.

View all 40 software examples

Campaigns4

Used byProcedure example
CampaignCutting Edge

During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool.

CampaignOperation Wocao

During Operation Wocao, threat actors' backdoors were written in Python and compiled with py2exe.

CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used custom applications developed in python.

CampaignShadowRay

During ShadowRay, threat actors used the Python `pty` module to open reverse shells.

References1

  1. Zscaler APT31 Covid-19 October 2020 Open source
    Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.