Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.006 Python |
GroupAPT29 | APT29 has developed malware variants written in Python. |
| T1059.006 Python |
GroupCinnamon Tempest | Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files. |
| T1059.006 Python |
GroupBRONZE BUTLER | BRONZE BUTLER has made use of Python-based remote access tools. |
| T1059.006 Python |
GroupTonto Team | Tonto Team has used Python-based tools for execution. |
| T1059.006 Python |
GroupEarth Lusca | Earth Lusca used Python scripts for port scanning or building reverse shells. |
| T1059.006 Python |
GroupVOID MANTICORE | VOID MANTICORE has utilized Python scripts to execute its malicious payloads. |
| T1059.006 Python |
GroupTeamPCP | TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection. |
| T1059.007 JavaScript |
GroupIndrik Spider | Indrik Spider has used malicious JavaScript files for several components of their attack. |
| T1059.007 JavaScript |
GroupKimsuky | Kimsuky has used JScript for logging and downloading additional tools. Kimsuky has used TRANSLATEXT, which contained four Javascript files for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data. |
| T1059.007 JavaScript |
GroupTA577 | TA577 has used JavaScript to execute additional malicious payloads. |
| T1059.007 JavaScript |
GroupEvilnum | Evilnum has used malicious JavaScript files on the victim's machine. |
| T1059.007 JavaScript |
GroupAPT32 | APT32 has used JavaScript for drive-by downloads and C2 communications. |
| T1059.007 JavaScript |
GroupMuddyWater | MuddyWater has used JavaScript files to execute its POWERSTATS payload. |
| T1059.007 JavaScript |
GroupFIN6 | FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites. |
| T1059.007 JavaScript |
GroupLeafminer | Leafminer infected victims using JavaScript code. |
| T1059.007 JavaScript |
GroupFIN7 | FIN7 used JavaScript scripts to help perform tasks on the victim's machine. |
| T1059.007 JavaScript |
GroupSidewinder | Sidewinder has used JavaScript to drop and execute malware loaders. |
| T1059.007 JavaScript |
GroupMustang Panda | Mustang Panda has executed a JavaScript payload utilizing wscript.exe on the endpoint. |
| T1059.007 JavaScript |
GroupContagious Interview | Contagious Interview has leveraged JavaScript in the execution of their downloader malware targeting Windows devices using a NodeJS script titled nvidia.js. |
| T1059.007 JavaScript |
GroupHigaisa | Higaisa used JavaScript to execute additional files. |
| T1059.007 JavaScript |
GroupSaint Bear | Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot. |
| T1059.007 JavaScript |
GroupMoustachedBouncer | MoustachedBouncer has used JavaScript to deliver malware hosted on HTML pages. |
| T1059.007 JavaScript |
GroupWinter Vivern | Winter Vivern delivered malicious JavaScript to exploit targets when exploiting Roundcube Webmail servers. |
| T1059.007 JavaScript |
GroupTurla | Turla has used various JavaScript-based backdoors. |
| T1059.007 JavaScript |
GroupTA505 | TA505 has used JavaScript for code execution. |
| T1059.007 JavaScript |
GroupStar Blizzard | Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework. |
| T1059.007 JavaScript |
GroupTA578 | TA578 has used JavaScript files in malware execution chains. |
| T1059.007 JavaScript |
GroupLazyScripter | LazyScripter has used JavaScript in its attacks. |
| T1059.007 JavaScript |
GroupAPT-C-36 | APT-C-36 has used a fileless attack chain composed of three JavaScript code snippets to execute subsequent payloads. |
| T1059.007 JavaScript |
GroupEarth Lusca | Earth Lusca has manipulated legitimate websites to inject malicious JavaScript code as part of their watering hole operations. |
| T1059.007 JavaScript |
GroupSilence | Silence has used JS scripts. |
| T1059.007 JavaScript |
GroupCobalt Group | Cobalt Group has executed JavaScript scriptlets on the victim's machine. |
| T1059.007 JavaScript |
GroupMolerats | Molerats used various implants, including those built with JS, on target machines. |
| T1059.007 JavaScript |
GroupTeamPCP | TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions. |
| T1059.007 JavaScript |
GroupShinyHunters | ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, ShinyHunters has checked for the authenticode tool using the command `npm list global authenticode`. Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: ` node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' `. |
| T1059.009 Cloud API |
GroupTeamTNT | TeamTNT has leveraged AWS CLI to enumerate cloud environments with compromised credentials. |
| T1059.009 Cloud API |
GroupStorm-0501 | Storm-0501 has leveraged Cloud CLI to execute commands and exfiltrate data from compromised environments. |
| T1059.009 Cloud API |
GroupAPT29 | APT29 has leveraged the Microsoft Graph API to perform various actions across Azure and M365 environments. They have also utilized AADInternals PowerShell Modules to access the API |
| T1059.009 Cloud API |
GroupShinyHunters | ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`. |
| T1059.010 AutoHotKey & AutoIT |
GroupAPT39 | APT39 has utilized AutoIt malware scripts embedded in Microsoft Office documents or malicious links. |
| T1059.012 Hypervisor CLI |
GroupUNC3886 | UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal. |
| T1059.013 Container CLI/API |
GroupTeamTNT | TeamTNT targeted misconfigured containers and used container CLI tools. |
| T1059.013 Container CLI/API |
GroupTeamPCP | TeamPCP has queried the Kubernetes API for local service account tokens and has used `kubectl` for lateral movement. |
| T1068 Exploitation for Privilege Escalation |
GroupBlackByte | BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupVolt Typhoon | Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT32 | APT32 has used CVE-2016-7255 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupHAFNIUM | HAFNIUM has targeted unpatched applications to elevate access in targeted organizations. |
| T1068 Exploitation for Privilege Escalation |
GroupFIN6 | FIN6 has used tools to exploit Windows vulnerabilities in order to escalate privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupZIRCONIUM | ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupScattered Spider | Scattered Spider has deployed a malicious kernel driver through exploitation of CVE-2015-2291 in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.