ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1059.005
Visual Basic
GroupFIN7

FIN7 used VBS scripts to help perform tasks on the victim's machine.

T1059.005
Visual Basic
GroupSandworm Team

Sandworm Team has created VBScripts to run an SSH server.

T1059.005
Visual Basic
GroupMachete

Machete has embedded malicious macros within spearphishing attachments to download additional files.

T1059.005
Visual Basic
GroupSidewinder

Sidewinder has used VBScript to drop and execute malware loaders.

T1059.005
Visual Basic
GroupMustang Panda

Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on.

T1059.005
Visual Basic
GroupAPT39

APT39 has utilized malicious VBS scripts in malware.

T1059.005
Visual Basic
GroupContagious Interview

Contagious Interview has utilized Visual Basic scripts in the execution of their downloader malware targeting Windows devices including as script called update.vbs.

T1059.005
Visual Basic
GroupTA2541

TA2541 has used VBS files to execute or establish persistence for additional payloads, often using file names consistent with email themes or mimicking system functionality.

T1059.005
Visual Basic
GroupAPT37

APT37 executes shellcode and a VBA script to decode Base64 strings.

T1059.005
Visual Basic
GroupOilRig

OilRig has used VBScript macros for execution on compromised hosts.

T1059.005
Visual Basic
GroupHigaisa

Higaisa has used VBScript code on the victim's machine.

T1059.005
Visual Basic
GroupTA459

TA459 has a VBScript for execution.

T1059.005
Visual Basic
GroupConfucius

Confucius has used VBScript to execute malicious code.

T1059.005
Visual Basic
GroupLeviathan

Leviathan has used VBScript.

T1059.005
Visual Basic
GroupTurla

Turla has used VBS scripts throughout its operations.

T1059.005
Visual Basic
GroupTA505

TA505 has used VBS for code execution.

T1059.005
Visual Basic
GroupRedCurl

RedCurl has used VBScript to run malicious files.

T1059.005
Visual Basic
GroupMirrorFace

MirrorFace has used remote templates with VBA code in malware infection chains.

T1059.005
Visual Basic
GroupBRONZE BUTLER

BRONZE BUTLER has used VBS and VBE scripts for execution.

T1059.005
Visual Basic
GroupLazyScripter

LazyScripter has used VBScript to execute malicious code.

T1059.005
Visual Basic
GroupWindshift

Windshift has used Visual Basic 6 (VB6) payloads.

T1059.005
Visual Basic
GroupMalteiro

Malteiro has utilized a dropper containing malicious VBS scripts.

T1059.005
Visual Basic
GroupAPT42

APT42 has used a VBScript to query anti-virus products.

T1059.005
Visual Basic
GroupAPT-C-36

APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening.

T1059.005
Visual Basic
GroupLazarus Group

Lazarus Group has used VBA and embedded macros in Word documents to execute malicious code.

T1059.005
Visual Basic
GroupEarth Lusca

Earth Lusca used VBA scripts.

T1059.005
Visual Basic
GroupFIN4

FIN4 has used VBA macros to display a dialog box and collect victim credentials.

T1059.005
Visual Basic
GroupSilence

Silence has used VBS scripts.

T1059.005
Visual Basic
GroupCobalt Group

Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution.

T1059.005
Visual Basic
GroupMolerats

Molerats used various implants, including those built with VBScript, on target machines.

T1059.005
Visual Basic
GroupTransparent Tribe

Transparent Tribe has crafted VBS-based malicious documents.

T1059.005
Visual Basic
GroupInception

Inception has used VBScript to execute malicious commands and payloads.

T1059.005
Visual Basic
GroupHEXANE

HEXANE has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger.

T1059.005
Visual Basic
GroupRancor

Rancor has used VBS scripts as well as embedded macros for execution.

T1059.005
Visual Basic
GroupWIRTE

WIRTE has used VBScript in its operations.

T1059.005
Visual Basic
GroupMagic Hound

Magic Hound malware has used VBS scripts for execution.

T1059.005
Visual Basic
GroupAPT33

APT33 has used VBScript to initiate the delivery of payloads.

T1059.005
Visual Basic
GroupFIN13

FIN13 has used VBS scripts for code execution on comrpomised machines.

T1059.006
Python
GroupKimsuky

Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data.

T1059.006
Python
GroupDragonfly

Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim.

T1059.006
Python
GroupMuddyWater

MuddyWater has developed tools in Python including Out1.

T1059.006
Python
GroupMachete

Machete used multiple compiled Python scripts on the victim’s system. Machete's main backdoor Machete is also written in Python.

T1059.006
Python
GroupZIRCONIUM

ZIRCONIUM has used Python-based implants to interact with compromised hosts.

T1059.006
Python
GroupRocke

Rocke has used Python-based malware to install and spread their coinminer.

T1059.006
Python
GroupAPT39

APT39 has used a command line utility and a network scanner written in python.

T1059.006
Python
GroupUNC3886

UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs.

T1059.006
Python
GroupContagious Interview

Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules.

T1059.006
Python
GroupAPT37

APT37 has used Python scripts to execute payloads.

T1059.006
Python
GroupTurla

Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads.

T1059.006
Python
GroupRedCurl

RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.