Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
GroupDark Caracal | Dark Caracal has used macros in Word documents that would download a second stage if executed. |
| T1059.003 Windows Command Shell |
GroupCinnamon Tempest | Cinnamon Tempest has executed ransomware using batch scripts deployed via GPO. |
| T1059.003 Windows Command Shell |
GroupChimera | Chimera has used the Windows Command Shell and batch scripts for execution on compromised hosts. |
| T1059.003 Windows Command Shell |
GroupMirrorFace | MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation. |
| T1059.003 Windows Command Shell |
GroupMedusa Group | Medusa Group has used Windows Command Prompt to control and execute commands on the system to include ingress, network, and filesystem enumeration activities. |
| T1059.003 Windows Command Shell |
GroupBRONZE BUTLER | BRONZE BUTLER has used batch scripts and the command-line interface for execution. |
| T1059.003 Windows Command Shell |
GroupTA551 | TA551 has used |
| T1059.003 Windows Command Shell |
GroupDarkhotel | Darkhotel has dropped an mspaint.lnk shortcut to disk which launches a shell script that downloads and executes a file. |
| T1059.003 Windows Command Shell |
GroupLazyScripter | LazyScripter has used batch files to deploy open-source and multi-stage RATs. |
| T1059.003 Windows Command Shell |
GroupToddyCat | ToddyCat has used .bat scripts and `cmd` for execution on compromised hosts. |
| T1059.003 Windows Command Shell |
GroupAgrius | Agrius uses ASPXSpy web shells to enable follow-on command execution via |
| T1059.003 Windows Command Shell |
GroupAPT28 | An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads. |
| T1059.003 Windows Command Shell |
GroupMetador | Metador has used the Windows command line to execute commands. |
| T1059.003 Windows Command Shell |
GroupAPT5 | APT5 has used cmd.exe for execution on compromised systems. |
| T1059.003 Windows Command Shell |
GroupFox Kitten | Fox Kitten has used cmd.exe likely as a password changing mechanism. |
| T1059.003 Windows Command Shell |
GroupLazarus Group | Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system. |
| T1059.003 Windows Command Shell |
GroupINC Ransom | INC Ransom has used `cmd.exe` to launch malicious payloads. |
| T1059.003 Windows Command Shell |
GroupSilence | Silence has used Windows command-line to run commands. |
| T1059.003 Windows Command Shell |
GroupSowbug | Sowbug has used command line during its intrusions. |
| T1059.003 Windows Command Shell |
GroupThreat Group-1314 | Threat Group-1314 actors spawned shells on remote systems on a victim network to execute commands. |
| T1059.003 Windows Command Shell |
GroupCobalt Group | Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files. |
| T1059.003 Windows Command Shell |
GroupWizard Spider | Wizard Spider has used `cmd.exe` to execute commands on a victim's machine. |
| T1059.003 Windows Command Shell |
GroupPlay | Play has used a batch script to remove indicators of its presence on compromised hosts. |
| T1059.003 Windows Command Shell |
GroupRancor | Rancor has used cmd.exe to execute commmands. |
| T1059.003 Windows Command Shell |
GroupWIRTE | WIRTE has used the Windows command line as part of infection chains to open documents. |
| T1059.003 Windows Command Shell |
GroupMagic Hound | Magic Hound has used the command-line interface for code execution. |
| T1059.003 Windows Command Shell |
GroupThreat Group-3390 | Threat Group-3390 has used command-line interfaces for execution. |
| T1059.003 Windows Command Shell |
GroupFIN10 | FIN10 has executed malicious .bat files containing PowerShell commands. |
| T1059.003 Windows Command Shell |
GroupFIN8 | FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`. |
| T1059.003 Windows Command Shell |
GroupFIN13 | FIN13 has leveraged `xp_cmdshell` and Windows Command Shell to execute commands on a compromised machine. FIN13 has also attempted to leverage the ‘xp_cmdshell’ SQL procedure to execute remote commands on internal MS-SQL servers. |
| T1059.003 Windows Command Shell |
GroupNomadic Octopus | Nomadic Octopus used |
| T1059.004 Unix Shell |
GroupVolt Typhoon | Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh). |
| T1059.004 Unix Shell |
GroupAPT41 | APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871. |
| T1059.004 Unix Shell |
GroupTeamTNT | TeamTNT has used shell scripts for execution. |
| T1059.004 Unix Shell |
GroupRocke | Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware. |
| T1059.004 Unix Shell |
GroupScattered Spider | Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance. |
| T1059.004 Unix Shell |
GroupUNC3886 | UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs). |
| T1059.004 Unix Shell |
GroupContagious Interview | Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh. |
| T1059.004 Unix Shell |
GroupSea Turtle | Sea Turtle used shell scripts for post-exploitation execution in victim environments. |
| T1059.004 Unix Shell |
GroupAquatic Panda | Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware. |
| T1059.004 Unix Shell |
GroupVelvet Ant | Velvet Ant used a custom tool, VELVETSTING, to parse encoded inbound commands to compromised F5 BIG-IP devices and then execute them via the Unix shell. |
| T1059.004 Unix Shell |
GroupTeamPCP | TeamPCP has leveraged malware capable of execution via the Linux CLI. |
| T1059.005 Visual Basic |
GroupAPT38 | APT38 has used VBScript to execute commands and other operational tasks. |
| T1059.005 Visual Basic |
GroupSideCopy | SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`. |
| T1059.005 Visual Basic |
GroupKimsuky | Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT. |
| T1059.005 Visual Basic |
GroupPatchwork | Patchwork used Visual Basic Scripts (VBS) on victim machines. |
| T1059.005 Visual Basic |
GroupGorgon Group | Gorgon Group has used macros in Spearphishing Attachments as well as executed VBScripts on victim machines. |
| T1059.005 Visual Basic |
GroupAPT32 | APT32 has used macros, COM scriptlets, and VBS scripts. |
| T1059.005 Visual Basic |
GroupMuddyWater | MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros. |
| T1059.005 Visual Basic |
GroupGamaredon Group | Gamaredon Group has embedded malicious macros in document templates, which executed VBScript. Gamaredon Group has also delivered Microsoft Outlook VBA projects with embedded macros. Additionally, Gamaredon Group has executed VBScript files using wscript.exe. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.