Unix Shell

T1059.004

Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org

About this technique

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Unix shells also support scripts that enable sequential execution of commands as well as other typical programming operations such as conditionals and loops. Common uses of shell scripts include long or repetitive tasks, or the need to run the same set of commands on multiple systems.

Adversaries may abuse Unix shells to execute various commands or payloads. Interactive shells may be accessed through command and control channels or during lateral movement such as with SSH. Adversaries may also leverage shell scripts to deliver and execute multiple commands on victims or as part of payloads used for persistence.

Some systems, such as embedded devices, lightweight Linux distributions, and ESXi servers, may leverage stripped-down Unix shells via Busybox, a small executable that contains a variety of tools, including a simple shell.

Detection rules27

Rules on DetectionCode tagged with T1059.004.

Sigma15

RuleLevelLog source
Linux Reverse Shell Indicatorcriticallinux / network_connection
AWS EC2 Startup Shell Script Changehighaws / NULL
Equation Group Indicatorshighlinux / NULL
JexBoss Command Sequencehighlinux / NULL
Script Interpreter Spawning Credential Scanner - Linuxhighlinux / process_creation
Shell Invocation via Env Command - Linuxhighlinux / process_creation
Suspicious Activity in Shell Commandshighlinux / NULL
Suspicious Download and Execute Pattern via Curl/Wgethighlinux / process_creation
Suspicious Filename with Embedded Base64 Commandshighlinux / file_event
Suspicious Reverse Shell Command Linehighlinux / NULL
BPFtrace Unsafe Option Usagemediumlinux / process_creation
Interactive Bash Suspicious Childrenmediumlinux / process_creation
Nohup Executionmediumlinux / process_creation
Potential Abuse of Linux Magic System Request Keymediumlinux / NULL
Suspicious Commands Linuxmediumlinux / NULL

Splunk12

RuleTypeRiskData source
Linux Decode Base64 to ShellTTPNULLSysmon for Linux EventID 1, Cisco Isovalent Process Exec
Linux Magic SysRq Key AbuseTTPNULLLinux Auditd Path, Linux Auditd Cwd
Linux MOTD Script AddedAnomalyNULLSysmon for Linux EventID 11
Linux Netcat Outbound ConnectionAnomalyNULLSysmon for Linux EventID 3
Linux Possible System Binary BackdoorAnomalyNULLSysmon for Linux EventID 11
Linux Suspicious Privileged Container ExecutionAnomalyNULLSysmon for Linux EventID 1
Linux Suspicious React or Next.js Child ProcessTTPNULLSysmon for Linux EventID 1
Linux Suspicious XDG AutostartAnomalyNULLSysmon for Linux EventID 11
Linux Unix Shell Enable All SysRq FunctionsAnomalyNULLSysmon for Linux EventID 1
MacOS LOLbinTTPNULLOsquery Results
MacOS Osascript Executing Interactive ShellAnomalyNULLOsquery Results
Suspicious Linux Discovery CommandsTTPNULLSysmon for Linux EventID 1

Groups11

Software49

Show 25 more

Campaigns6

Procedure examples66

Groups11

Used byProcedure example
GroupAPT41

APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871.

GroupAquatic Panda

Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware.

GroupContagious Interview

Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh.

GroupRocke

Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware.

GroupScattered Spider

Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance.

GroupSea Turtle

Sea Turtle used shell scripts for post-exploitation execution in victim environments.

GroupTeamPCP

TeamPCP has leveraged malware capable of execution via the Linux CLI.

GroupTeamTNT

TeamTNT has used shell scripts for execution.

View all 11 groups examples

Software49

Used byProcedure example
MalwareAnchor

Anchor can execute payloads via shell scripting.

MalwareAppleJeus

AppleJeus has used shell scripts to execute commands after installation and set persistence mechanisms.

MalwareBOLDMOVE

BOLDMOVE is capable of spawning a remote command shell.

MalwareBPFDoor

BPFDoor can create a reverse shell and supports vt100 emulator formatting.

MalwareBRICKSTORM

BRICKSTORM has executed shell commands using `/bin/sh`.

MalwareBundlore

Bundlore has leveraged /bin/sh and /bin/bash to execute commands on the victim machine.

MalwareCallMe

CallMe has the capability to create a reverse shell on victims.

MalwareCanisterWorm

CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence.

View all 49 software examples

Campaigns6

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized the Linux `dd` command to overwrite portions of the disks with random data.

CampaignFLORAHOX Activity

FLORAHOX Activity has executed multiple Bash controller scripts to provide command line inputs for FLORAHOX traversal configurations.

CampaignKV Botnet Activity

KV Botnet Activity utilizes multiple Bash scripts during botnet installation stages, and the final botnet payload allows for running commands in the Bash shell.

CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution.

CampaignQuad7 Activity

Quad7 Activity has enabled the creation of an access-controlled command shell /bin/sh on compromised routers.

CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of launching an interactive shell.

References2

  1. Apple ZShell Open source
    Apple. (2020, January 28). Use zsh as the default shell on your Mac. Retrieved June 12, 2020.
  2. DieNet Bash Open source
    die.net. (n.d.). bash(1) - Linux man page. Retrieved June 12, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.