Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Unix shells also support scripts that enable sequential execution of commands as well as other typical programming operations such as conditionals and loops. Common uses of shell scripts include long or repetitive tasks, or the need to run the same set of commands on multiple systems.
Adversaries may abuse Unix shells to execute various commands or payloads. Interactive shells may be accessed through command and control channels or during lateral movement such as with SSH. Adversaries may also leverage shell scripts to deliver and execute multiple commands on victims or as part of payloads used for persistence.
Some systems, such as embedded devices, lightweight Linux distributions, and ESXi servers, may leverage stripped-down Unix shells via Busybox, a small executable that contains a variety of tools, including a simple shell.
Rules on DetectionCode tagged with T1059.004.
| Rule | Level | Log source |
|---|---|---|
| Linux Reverse Shell Indicator | critical | linux / network_connection |
| AWS EC2 Startup Shell Script Change | high | aws / NULL |
| Equation Group Indicators | high | linux / NULL |
| JexBoss Command Sequence | high | linux / NULL |
| Script Interpreter Spawning Credential Scanner - Linux | high | linux / process_creation |
| Shell Invocation via Env Command - Linux | high | linux / process_creation |
| Suspicious Activity in Shell Commands | high | linux / NULL |
| Suspicious Download and Execute Pattern via Curl/Wget | high | linux / process_creation |
| Suspicious Filename with Embedded Base64 Commands | high | linux / file_event |
| Suspicious Reverse Shell Command Line | high | linux / NULL |
| BPFtrace Unsafe Option Usage | medium | linux / process_creation |
| Interactive Bash Suspicious Children | medium | linux / process_creation |
| Nohup Execution | medium | linux / process_creation |
| Potential Abuse of Linux Magic System Request Key | medium | linux / NULL |
| Suspicious Commands Linux | medium | linux / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Linux Decode Base64 to Shell | TTP | NULL | Sysmon for Linux EventID 1, Cisco Isovalent Process Exec |
| Linux Magic SysRq Key Abuse | TTP | NULL | Linux Auditd Path, Linux Auditd Cwd |
| Linux MOTD Script Added | Anomaly | NULL | Sysmon for Linux EventID 11 |
| Linux Netcat Outbound Connection | Anomaly | NULL | Sysmon for Linux EventID 3 |
| Linux Possible System Binary Backdoor | Anomaly | NULL | Sysmon for Linux EventID 11 |
| Linux Suspicious Privileged Container Execution | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Suspicious React or Next.js Child Process | TTP | NULL | Sysmon for Linux EventID 1 |
| Linux Suspicious XDG Autostart | Anomaly | NULL | Sysmon for Linux EventID 11 |
| Linux Unix Shell Enable All SysRq Functions | Anomaly | NULL | Sysmon for Linux EventID 1 |
| MacOS LOLbin | TTP | NULL | Osquery Results |
| MacOS Osascript Executing Interactive Shell | Anomaly | NULL | Osquery Results |
| Suspicious Linux Discovery Commands | TTP | NULL | Sysmon for Linux EventID 1 |
| Used by | Procedure example |
|---|---|
| GroupAPT41 | APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871. |
| GroupAquatic Panda | Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware. |
| GroupContagious Interview | Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh. |
| GroupRocke | Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware. |
| GroupScattered Spider | Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance. |
| GroupSea Turtle | Sea Turtle used shell scripts for post-exploitation execution in victim environments. |
| GroupTeamPCP | TeamPCP has leveraged malware capable of execution via the Linux CLI. |
| GroupTeamTNT | TeamTNT has used shell scripts for execution. |
| Used by | Procedure example |
|---|---|
| MalwareAnchor | Anchor can execute payloads via shell scripting. |
| MalwareAppleJeus | AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms. |
| MalwareBOLDMOVE | BOLDMOVE is capable of spawning a remote command shell. |
| MalwareBPFDoor | BPFDoor can create a reverse shell and supports vt100 emulator formatting. |
| MalwareBRICKSTORM | BRICKSTORM has executed shell commands using `/bin/sh`. |
| MalwareBundlore | Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine. |
| MalwareCallMe | CallMe has the capability to create a reverse shell on victims. |
| MalwareCanisterWorm | CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized the Linux `dd` command to overwrite portions of the disks with random data. |
| CampaignFLORAHOX Activity | FLORAHOX Activity has executed multiple Bash controller scripts to provide command line inputs for FLORAHOX traversal configurations. |
| CampaignKV Botnet Activity | KV Botnet Activity utilizes multiple Bash scripts during botnet installation stages, and the final botnet payload allows for running commands in the Bash shell. |
| CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution. |
| CampaignQuad7 Activity | Quad7 Activity has enabled the creation of an access-controlled command shell |
| CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of launching an interactive shell. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.