JavaScript

T1059.007

Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org

About this technique

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

JScript is the Microsoft implementation of the same scripting standard. JScript is interpreted via the Windows Script engine and thus integrated with many components of Windows such as the Component Object Model and Internet Explorer HTML Application (HTA) pages.

JavaScript for Automation (JXA) is a macOS scripting language based on JavaScript, included as part of Apple’s Open Scripting Architecture (OSA), that was introduced in OSX 10.10. Apple’s OSA provides scripting capabilities to control applications, interface with the operating system, and bridge access into the rest of Apple’s internal APIs. As of OSX 10.10, OSA only supports two languages, JXA and AppleScript. Scripts can be executed via the command line utility osascript, they can be compiled into applications or script files via osacompile, and they can be compiled and executed in memory of other programs by leveraging the OSAKit Framework.

Adversaries may abuse various implementations of JavaScript to execute various behaviors. Common uses include hosting malicious scripts on websites as part of a Drive-by Compromise or downloading and executing these script files as secondary payloads. Since these payloads are text-based, it is also very common for adversaries to obfuscate their content as part of Obfuscated Files or Information.

Detection rules31

Rules on DetectionCode tagged with T1059.007.

Sigma23

RuleLevelLog source
Adwind RAT / JRAT File Artifacthighwindows / file_event
Csc.EXE Execution Form Potentially Suspicious Parenthighwindows / process_creation
Cscript/Wscript Uncommon Script Extension Executionhighwindows / process_creation
HackTool - CACTUSTORCH Remote Thread Creationhighwindows / create_remote_thread
HackTool - Koadic Executionhighwindows / process_creation
HTML Help HH.EXE Suspicious Child Processhighwindows / process_creation
JXA In-memory Execution Via OSAScripthighmacos / process_creation
MSHTA Execution with Suspicious File Extensionshighwindows / process_creation
Potential Remote SquiblyTwo Technique Executionhighwindows / process_creation
Script Interpreter Spawning Credential Scanner - Windowshighwindows / process_creation
Suspicious HH.EXE Executionhighwindows / process_creation
WScript or CScript Dropper - Filehighwindows / file_event
AppLocker Application Would Have Been Blockedmediumwindows / NULL
AppLocker Prevented Application or Script from Runningmediumwindows / NULL
New Agent Skills Installation Attempt Via Node.EXEmediumwindows / process_creation

Splunk8

RuleTypeRiskData source
Cmdline Tool Not Executed In CMD ShellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Jscript Execution Using Cscript AppAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2
MacOS Osascript Executing JavaScript Code With ObjCAnomalyNULLOsquery Results
MS Scripting Process Loading Ldap ModuleAnomalyNULLSysmon EventID 7
MS Scripting Process Loading WMI ModuleAnomalyNULLSysmon EventID 7
Windows Cmdline Tool Execution From Non-Shell ProcessAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows GrimResource - MMC Process Accessing APDS DLLTTPNULLWindows Event Log Security 4663
Windows Node.exe Executing JS Script In Immediate FolderTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups28

Show 4 more

Software42

Show 18 more

Campaigns5

Procedure examples75

Groups28

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used a fileless attack chain composed of three JavaScript code snippets to execute subsequent payloads.

GroupAPT32

APT32 has used JavaScript for drive-by downloads and C2 communications.

GroupCobalt Group

Cobalt Group has executed JavaScript scriptlets on the victim's machine.

GroupContagious Interview

Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js.

GroupEarth Lusca

Earth Lusca has manipulated legitimate websites to inject malicious JavaScript code as part of their watering hole operations.

GroupEvilnum

Evilnum has used malicious JavaScript files on the victim's machine.

GroupFIN6

FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites.

GroupFIN7

FIN7 used JavaScript scripts to help perform tasks on the victim's machine.

View all 28 groups examples

Software42

Used byProcedure example
MalwareAppleSeed

AppleSeed has the ability to use JavaScript to execute PowerShell.

MalwareAshTag

AshTag can use JSON files to deliver payloads and configuration files.

MalwareAstaroth

Astaroth uses JavaScript to perform its core functionalities.

MalwareAvaddon

Avaddon has been executed through a malicious JScript downloader.

MalwareBeaverTail

BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS.

MalwareBlackByte Ransomware

BlackByte Ransomware is distributed as a JavaScript launcher file.

MalwareBundlore

Bundlore can execute JavaScript by injecting it into the victim's browser.

MalwareCanisterWorm

CanisterWorm can leverage stolen tokens to execute Javascsript (deploy.js) for self-propagation.

View all 42 software examples

Campaigns5

Used byProcedure example
CampaignC0015

During C0015, the threat actors used a malicious HTA file that contained a mix of encoded HTML and JavaScript/VBScript code.

CampaignC0017

During C0017, APT41 deployed JScript web shells on compromised systems.

CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used JavaScript code.

CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized obfuscated JavaScript files for initial Pikabot payload download.

CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution initial delivery included obfuscated JavaScript objects stored in password-protected ZIP archives.

References9

  1. Apple About Mac Scripting 2016 Open source
    Apple. (2016, June 13). About Mac Scripting. Retrieved April 14, 2021.
  2. JScrip May 2018 Open source
    Microsoft. (2018, May 31). Translating to JScript. Retrieved June 23, 2020.
  3. MDSec macOS JXA and VSCode Open source
    Dominic Chell. (2021, January 1). macOS Post-Exploitation Shenanigans with VSCode Extensions. Retrieved April 20, 2021.
  4. Microsoft JScript 2007 Open source
    Microsoft. (2007, August 15). The World of JScript, JavaScript, ECMAScript …. Retrieved June 23, 2020.
  5. Microsoft Windows Scripts Open source
    Microsoft. (2017, January 18). Windows Script Interfaces. Retrieved June 23, 2020.
  6. NodeJS Open source
    OpenJS Foundation. (n.d.). Node.js. Retrieved June 23, 2020.
  7. Red Canary Silver Sparrow Feb2021 Open source
    Tony Lambert. (2021, February 18). Clipping Silver Sparrow’s wings: Outing macOS malware before it takes flight. Retrieved April 20, 2021.
  8. SentinelOne macOS Red Team Open source
    Phil Stokes. (2019, December 5). macOS Red Team: Calling Apple APIs Without Building Binaries. Retrieved July 17, 2020.
  9. SpecterOps JXA 2020 Open source
    Pitt, L. (2020, August 6). Persistent JXA. Retrieved April 14, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.