Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org
Adversaries may abuse Lua commands and scripts for execution. Lua is a cross-platform scripting and programming language primarily designed for embedded use in applications. Lua can be executed on the command-line (through the stand-alone lua interpreter), via scripts (.lua), or from Lua-embedded programs (through the struct lua_State).
Lua scripts may be executed by adversaries for malicious purposes. Adversaries may incorporate, abuse, or replace existing Lua interpreters to allow for malicious Lua command execution at runtime.
Rules on DetectionCode tagged with T1059.011.
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareEvilBunny | EvilBunny has used Lua scripts to execute payloads. |
| MalwareLine Runner | Line Runner utilizes Lua scripts for command execution. |
| MalwarePoetRAT | PoetRAT has executed a Lua script through a Lua interpreter for Windows. |
| MalwareRedLine Stealer | RedLine Stealer malware has leveraged Lua bytecode to perform malicious behavior. |
| MalwareRemsec | Remsec can use modules written in Lua for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.