LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1059: Command and Scripting Interpreter

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.

Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in Initial Access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells, as well as utilize various Remote Services in order to achieve remote Execution.[1][2][3]

EnterpriseT1059TechniqueObject v2.7Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Command and Scripting Interpreter is a high-value execution behavior because it represents the normal tools administrators and platforms use to run work: shells, PowerShell, Python, JavaScript, Visual Basic, cloud APIs, network device CLIs, hypervisor CLIs, and container CLIs/APIs. For leaders, the issue is not that these tools exist; it is whether the organization can distinguish approved administration and automation from suspicious execution across endpoints, cloud, identity, network devices, ESXi, SaaS, Office, and containers.

Executive priority

Treat T1059 as a coverage and resilience question: do critical systems have logging, least privilege, execution controls, and incident response procedures for interpreter abuse? Because this technique spans many platforms, gaps often appear outside traditional endpoint monitoring, especially in cloud APIs, network devices, hypervisors, and containers. Executives should ask for evidence that command execution is logged, reviewed, and constrained for privileged users and administrative interfaces.

Technical view

ATT&CK provides no official detection text for this parent technique, but the relationship to DET0516 indicates behavioral detection of command and scripting interpreter abuse is relevant. SOC and detection teams should validate coverage by sub-technique and platform: PowerShell and Windows command shell on Windows; Unix shell on Linux, macOS, ESXi, and network devices; AppleScript on macOS; Python, JavaScript, Visual Basic, AutoHotKey/AutoIT, and Lua where present; cloud API execution across IaaS, identity provider, Office Suite, and SaaS; hypervisor CLI on ESXi; and container CLI/API activity in container environments. Detection should focus on unusual interpreter execution context, remote command execution patterns, privileged use, unexpected parent/child process relationships where available, and administrative command activity inconsistent with approved operations.

Likely telemetry

  • Endpoint process creation and command-line telemetry for Windows, Linux, and macOS systems
  • PowerShell activity and remote command logging where PowerShell is used
  • Shell history and command audit records for Unix-like systems, ESXi, and network devices
  • Cloud API, cloud CLI, in-browser cloud shell, identity provider, SaaS, and Office Suite audit logs
  • Container daemon/API and container CLI activity logs

Detection direction

  • Map detections to the T1059 sub-techniques instead of relying on one generic rule; each interpreter and platform has different normal behavior.
  • Baseline approved administrative automation so detections do not drown in legitimate scripts, cloud CLI use, configuration management, or help desk activity.
  • Prioritize visibility for remote execution paths referenced by ATT&CK, including PowerShell remoting, remote services, network device command history, and remote shell execution patterns.
  • Validate blind spots beyond endpoints: cloud APIs, identity provider activity, SaaS administration, containers, ESXi, and network device CLIs may not be covered by standard EDR telemetry.
  • Tune for suspicious context rather than interpreter name alone: uncommon user, privileged account use, unusual host, unexpected command sequence, script execution from untrusted locations, or activity following initial access payloads.

Mitigation priorities

  • Start with auditing: verify command, script, cloud API, network device, container, and hypervisor activity is recorded and periodically reviewed.
  • Apply privileged account management so interpreter and CLI use requiring elevated permissions is limited, accountable, and monitored.
  • Use execution prevention, application control, script blocking, and code signing where practical to reduce unauthorized script and binary execution.
  • Disable or remove unnecessary interpreters, features, programs, and administrative interfaces where business use does not justify exposure.
  • Limit unauthorized software installation so additional interpreters or scripting tools are not introduced without approval.
Additional notes and limits

This object is a parent technique with many sub-techniques, so useful assessment requires environment-specific scoping. The most important defensive question is whether each platform’s native execution interfaces are governed and observable. Relationship context supports DET0516 behavioral detection and mitigations including audit, privileged account management, software restriction, execution prevention, behavior prevention, code signing, web content restriction, feature removal, and antimalware.

MITRE did not provide official detection text for T1059 in the supplied fields. This take therefore avoids asserting specific detection logic or coverage. Local platform inventory, administrative workflows, logging configuration, and retention practices are required to determine actual exposure and monitoring maturity.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Command and Scripting Interpreter

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.

Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in Initial Access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells, as well as utilize various Remote Services in order to achieve remote Execution.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

13 rows
DomainIDNameRelationship / procedure
EnterpriseT1059.005Visual BasicSub-techniqueVisual Basic subtechnique of this object.
EnterpriseT1059.002AppleScriptSub-techniqueAppleScript subtechnique of this object.
EnterpriseT1059.003Windows Command ShellSub-techniqueWindows Command Shell subtechnique of this object.
EnterpriseT1059.013Container CLI/APISub-techniqueContainer CLI/API subtechnique of this object.
EnterpriseT1059.004Unix ShellSub-techniqueUnix Shell subtechnique of this object.
EnterpriseT1059.010AutoHotKey & AutoITSub-techniqueAutoHotKey & AutoIT subtechnique of this object.
EnterpriseT1059.008Network Device CLISub-techniqueNetwork Device CLI subtechnique of this object.
EnterpriseT1059.012Hypervisor CLISub-techniqueHypervisor CLI subtechnique of this object.
EnterpriseT1059.006PythonSub-techniquePython subtechnique of this object.
EnterpriseT1059.001PowerShellSub-techniquePowerShell subtechnique of this object.
EnterpriseT1059.009Cloud APISub-techniqueCloud API subtechnique of this object.
EnterpriseT1059.011LuaSub-techniqueLua subtechnique of this object.
EnterpriseT1059.007JavaScriptSub-techniqueJavaScript subtechnique of this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0117: Fox Kitten

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.[1][2][3][4]

GroupEnterprise

G0038: Stealth Falcon

Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least 2012. Circumstantial evidence suggests there could be a link between this group and the United Arab Emirates (UAE) government, but that has not been confirmed. [1]

GroupEnterprise

G1035: Winter Vivern

Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.[1][2][3][4][5]

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

GroupEnterprise

G0037: FIN6

FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.[1][2]

GroupEnterprise

G0053: FIN5

FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active since at least 2008 and has targeted the restaurant, gaming, and hotel industries. The group is made up of actors who likely speak Russian. [1] [2] [3]

GroupEnterprise

G0073: APT19

APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. [1] Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same. [2] [3] [4]

GroupEnterprise

G0050: APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]

GroupEnterprise

G0035: Dragonfly

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.[1][2] Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.[3][4][5][6][7][8][9]

GroupEnterprise

G1031: Saint Bear

Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns. Saint Bear typically relies on phishing or web staging of malicious documents and related file types for initial access, spoofing government or related entities.[1][2] Saint Bear has previously been confused with Ember Bear operations, but analysis of behaviors, tools, and targeting indicates these are distinct clusters.

GroupEnterprise

G0107: Whitefly

Whitefly is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information. The group has been linked to an attack against Singapore’s largest public health organization, SingHealth.[1]

GroupEnterprise

G0087: APT39

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.[1][2][3][4][5]

MalwareEnterprise

S0023: CHOPSTICK

CHOPSTICK is a malware family of modular backdoors used by APT28. It has been used since at least 2012 and is usually dropped on victims as second-stage malware, though it has been used as first-stage malware in several cases. It has both Windows and Linux variants. [1] [2] [3] [4] It is tracked separately from the X-Agent for Android.

WindowsLinux
ToolEnterprise

S0695: Donut

Donut is an open source framework used to generate position-independent shellcode.[1][2] Donut generated code has been used by multiple threat actors to inject and load malicious payloads into memory.[3]

Windows
MalwareEnterprise

S0167: Matryoshka

Matryoshka is a malware framework used by CopyKittens that consists of a dropper, loader, and RAT. It has multiple versions; v1 was seen in the wild from July 2016 until January 2017. v2 has fewer commands and other minor differences. [1] [2]

Windows
ToolEnterprise

S0434: Imminent Monitor

Imminent Monitor was a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was conducted to take down the Imminent Monitor infrastructure. Various cracked versions and variations of this RAT are still in circulation.[1]

Windows
MalwareEnterprise

S0487: Kessel

Kessel is an advanced version of OpenSSH which acts as a custom backdoor, mainly acting to steal credentials and function as a bot. Kessel has been active since its C2 domain began resolving in August 2018.[1]

Linux
MalwareEnterprise

S1151: ZeroCleare

ZeroCleare is a wiper malware that has been used in conjunction with the RawDisk driver since at least 2019 by suspected Iran-nexus threat actors including activity targeting the energy and industrial sectors in the Middle East and political targets in Albania.[1][2][3][4]

Windows
CampaignEnterprise

C0005: Operation Spalax

Operation Spalax was a campaign that primarily targeted Colombian government organizations and private companies, particularly those associated with the energy and metallurgical industries. The Operation Spalax threat actors distributed commodity malware and tools using generic phishing topics related to COVID-19, banking, and law enforcement action. Security researchers noted indicators of compromise and some infrastructure overlaps with other campaigns dating back to April 2018, including at least one separately attributed to APT-C-36, however identified enough differences to report this as separate, unattributed activity.[1]

CampaignEnterprise

C0029: Cutting Edge

Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously Pulse Secure) VPN appliances. Cutting Edge targeted the U.S. defense industrial base and multiple sectors globally including telecommunications, financial, aerospace, and technology. Cutting Edge featured the use of defense evasion and living-off-the-land (LoTL) techniques along with the deployment of web shells and other custom malware.[1][2][3][4][5]

CampaignEnterprise

C0053: FLORAHOX Activity

FLORAHOX Activity is conducted using a hybrid operational relay box (ORB) network, which combines two types of infrastructure: compromised devices and leased Virtual Private Servers (VPS). The compromised devices include end-of-life routers and IoT devices, while VPS space is commercially leased and managed by ORB network administrators. This hybrid ORB network allows adversaries to proxy and obscure malicious traffic, making the source of the traffic more difficult to trace.

The FLORAHOX ORB network has been leveraged by multiple cyber threat actors, including China-nexus actors like ZIRCONIUM. These adversaries conduct espionage campaigns through FLORAHOX Activity, relying on the ORB network's ability to funnel traffic through Tor nodes, provisioned VPS servers, and compromised routers to obfuscate malicious traffic.[1]

CampaignEnterprise

C0046: ArcaneDoor

ArcaneDoor is a campaign targeting networking devices from Cisco and other vendors between July 2023 and April 2024, primarily focused on government and critical infrastructure networks. ArcaneDoor is associated with the deployment of the custom backdoors Line Runner and Line Dancer. ArcaneDoor is attributed to a group referred to as UAT4356 or STORM-1849, and is assessed to be a state-sponsored campaign.[1][2]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.7
Created
Modified
Raw hash
8a29e36c9ad491a3...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.7Current bundle8a29e36c9ad4…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Powershell Remote Commands

    Microsoft. (2020, August 21). Running Remote Commands. Retrieved July 26, 2021.

    Open source URL
  2. [2]
    Cisco IOS Software Integrity Assurance - Command History

    Cisco. (n.d.). Cisco IOS Software Integrity Assurance - Command History. Retrieved October 21, 2020.

    Open source URL
  3. [3]
    Remote Shell Execution in Python

    Abdou Rockikz. (2020, July). How to Execute Shell Commands in a Remote Machine in Python. Retrieved July 26, 2021.

    Open source URL
  4. [4]
    ClearSky Pay2Kitten December 2020

    ClearSky. (2020, December 17). Pay2Key Ransomware – A New Campaign by Fox Kitten. Retrieved December 21, 2020.

    Open source URL
  5. [5]
    Citizen Lab Stealth Falcon May 2016

    Marczak, B. and Scott-Railton, J.. (2016, May 29). Keep Calm and (Don’t) Enable Macros: A New Threat Actor Targets UAE Dissidents. Retrieved June 8, 2016.

    Open source URL
  6. [6]
    DomainTools WinterVivern 2021

    Chad Anderson. (2021, April 27). Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages. Retrieved July 29, 2024.

    Open source URL
  7. [7]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  8. [8]
    Flashpoint FIN 7 March 2019

    Platt, J. and Reeves, J.. (2019, March). FIN7 Revisited: Inside Astra Panel and SQLRat Malware. Retrieved June 18, 2019.

    Open source URL
  9. [9]
    Malwarebytes DarkComet March 2018

    Kujawa, A. (2018, March 27). You dirty RAT! Part 1: DarkComet. Retrieved November 6, 2018.

    Open source URL
  10. [10]
    FireEye FIN6 April 2016

    FireEye Threat Intelligence. (2016, April). Follow the Money: Dissecting the Operations of the Cyber Crime Group FIN6. Retrieved November 17, 2024.

    Open source URL
  11. [11]
    FireEye FIN6 Apr 2019

    McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.

    Open source URL
  12. [12]
    Zscaler

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.

    Open source URL
  13. [13]
    ESET Operation Spalax Jan 2021

    M. Porolli. (2021, January 21). Operation Spalax: Targeted malware attacks in Colombia. Retrieved September 16, 2022.

    Open source URL
  14. [14]
    Crowdstrike DNC June 2016

    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.

    Open source URL
  15. [15]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  16. [16]
    Donut Github

    TheWover. (2019, May 9). donut. Retrieved March 25, 2022.

    Open source URL
  17. [17]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  18. [18]
    NCC Group Fivehands June 2021

    Matthews, M. and Backhouse, W. (2021, June 15). Handy guide to a new Fivehands ransomware variant. Retrieved June 24, 2021.

    Open source URL
  19. [19]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  20. [20]
    ClearSky Wilted Tulip July 2017

    ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.

  21. [21]
    QiAnXin APT-C-36 Feb2019

    QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.

    Open source URL
  22. [22]
    ESET ForSSHe December 2018

    Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

    Open source URL
  23. [23]
    Mandiant Cutting Edge Part 2 January 2024

    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.

    Open source URL
  24. [24]
    Mandiant Cutting Edge January 2024

    McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.

    Open source URL
  25. [25]
    FireEye APT19

    Ahl, I. (2017, June 06). Privileges and Credentials: Phished at the Request of Counsel. Retrieved May 17, 2018.

    Open source URL
  26. [26]
    Mandiant ROADSWEEP August 2022

    Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.

    Open source URL
  27. [27]
    FireEye Hacking Team

    FireEye Threat Intelligence. (2015, July 13). Demonstrating Hustle, Chinese APT Groups Quickly Use Zero-Day Vulnerability (CVE-2015-5119) Following Hacking Team Leak. Retrieved January 25, 2016.

    Open source URL
  28. [28]
    Nccgroup Gh0st April 2018

    Pantazopoulos, N. (2018, April 17). Decoding network data from a Gh0st RAT variant. Retrieved November 2, 2018.

    Open source URL
  29. [29]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  30. [30]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  31. [31]
    ANSSI Sandworm January 2021

    ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.

    Open source URL
  32. [32]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  33. [33]
    Mandiant Pulse Secure Zero-Day April 2021

    Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.

    Open source URL
  34. [34]
    ORB Mandiant

    Raggi, Michael. (2024, May 22). IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders. Retrieved July 8, 2024.

    Open source URL
  35. [35]
    Microsoft PowerShell CLM

    PowerShell Team. (2017, November 2). PowerShell Constrained Language Mode. Retrieved March 27, 2023.

    Open source URL
  36. [36]
    CheckPoint Bandook Nov 2020

    Check Point. (2020, November 26). Bandook: Signed & Delivered. Retrieved May 31, 2021.

    Open source URL
  37. [37]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  38. [38]
    Lumen Versa 2024

    Black Lotus Labs. (2024, August 27). Taking The Crossroads: The Versa Director Zero-Day Exploitaiton. Retrieved August 27, 2024.

    Open source URL
  39. [39]
    Symantec Whitefly March 2019

    Symantec. (2019, March 6). Whitefly: Espionage Group has Singapore in Its Sights. Retrieved May 26, 2020.

    Open source URL
  40. [40]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  41. [41]
    Mandiant APT42-untangling

    Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved October 9, 2024.

    Open source URL
  42. [42]
    CheckPoint SpeakUp Feb 2019

    Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan. Retrieved April 17, 2019.

    Open source URL
  43. [43]
    FireEye APT39 Jan 2019

    Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.

    Open source URL
  44. [44]
    FBI FLASH APT39 September 2020

    FBI. (2020, September 17). Indicators of Compromise Associated with Rana Intelligence Computing, also known as Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, and ITG07. Retrieved December 10, 2020.

    Open source URL
  45. [45]
    Mandiant Operation Ke3chang November 2014

    Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.

    Open source URL
  46. [46]
    NCC Group APT15 Alive and Strong

    Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.

    Open source URL
  47. [47]
    Netspi PowerShell Execution Policy Bypass

    Sutherland, S. (2014, September 9). 15 Ways to Bypass the PowerShell Execution Policy. Retrieved September 12, 2024.

    Open source URL
  48. [48]
    Microsoft PS JEA

    Microsoft. (2022, November 17). Just Enough Administration. Retrieved March 27, 2023.

    Open source URL
  49. [49]
    Cisco ArcaneDoor 2024

    Cisco Talos. (2024, April 24). ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices. Retrieved January 6, 2025.

    Open source URL
  50. [50]
    Volexity InkySquid RokRAT August 2021

    Cash, D., Grunzweig, J., Adair, S., Lancaster, T. (2021, August 25). North Korean BLUELIGHT Special: InkySquid Deploys RokRAT. Retrieved October 1, 2021.

    Open source URL
  51. [51]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  52. [52]
    Proofpoint TA505 October 2019

    Schwarz, D. et al. (2019, October 16). TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader. Retrieved May 29, 2020.

    Open source URL
  53. [53]
    ESET_MuddyWater_Dec2025

    ESET Research. (2025, December 2). MuddyWater: Snakes by the riverbank. Retrieved February 17, 2026.

    Open source URL
  54. [54]
    FireEye APT34 Dec 2017

    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.

    Open source URL
  55. [55]
    OilRig ISMAgent July 2017

    Falcone, R. and Lee, B. (2017, July 27). OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat Group. Retrieved January 8, 2018.

    Open source URL
  56. [56]
    Unit 42 OopsIE! Feb 2018

    Lee, B., Falcone, R. (2018, February 23). OopsIE! OilRig Uses ThreeDollars to Deliver New Trojan. Retrieved July 16, 2018.

    Open source URL
  57. [57]
    Unit 42 QUADAGENT July 2018

    Lee, B., Falcone, R. (2018, July 25). OilRig Targets Technology Service Provider and Government Agency with QUADAGENT. Retrieved August 9, 2018.

    Open source URL
  58. [58]
    Unit42 OilRig Nov 2018

    Falcone, R., Wilhoit, K.. (2018, November 16). Analyzing OilRig’s Ops Tempo from Testing to Weaponization to Delivery. Retrieved April 23, 2019.

    Open source URL
  59. [59]
    win10_asr

    Microsoft. (2021, July 2). Use attack surface reduction rules to prevent malware infection. Retrieved June 24, 2021.

    Open source URL
  60. [60]
    Github PowerShell Empire

    Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016.

    Open source URL
  61. [61]
    HP RaspberryRobin 2024

    Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024.

    Open source URL
  62. [62]
    Cisco IOS Software Integrity Assurance - Command History

    Cisco. (n.d.). Cisco IOS Software Integrity Assurance - Command History. Retrieved October 21, 2020.

    Open source URL
  63. [63]
    Cisco IOS Software Integrity Assurance - Command History

    Cisco. (n.d.). Cisco IOS Software Integrity Assurance - Command History. Retrieved October 21, 2020.

    Open source URL
  64. [64]
    Powershell Remote Commands

    Microsoft. (2020, August 21). Running Remote Commands. Retrieved July 26, 2021.

    Open source URL
  65. [65]
    Powershell Remote Commands

    Microsoft. (2020, August 21). Running Remote Commands. Retrieved July 26, 2021.

    Open source URL
  66. [66]
    Remote Shell Execution in Python

    Abdou Rockikz. (2020, July). How to Execute Shell Commands in a Remote Machine in Python. Retrieved July 26, 2021.

    Open source URL
  67. [67]
    Remote Shell Execution in Python

    Abdou Rockikz. (2020, July). How to Execute Shell Commands in a Remote Machine in Python. Retrieved July 26, 2021.

    Open source URL
  68. [68]
    mitre-attackT1059
    Open source URL
  69. [69]
    mitre-attackT1059
    Open source URL
  70. [70]
    mitre-attackT1059
    Open source URL
  71. [71]
    ClearSky Pay2Kitten December 2020

    ClearSky. (2020, December 17). Pay2Key Ransomware – A New Campaign by Fox Kitten. Retrieved December 21, 2020.

    Open source URL
  72. [72]
    Citizen Lab Stealth Falcon May 2016

    Marczak, B. and Scott-Railton, J.. (2016, May 29). Keep Calm and (Don’t) Enable Macros: A New Threat Actor Targets UAE Dissidents. Retrieved June 8, 2016.

    Open source URL
  73. [73]
    DomainTools WinterVivern 2021

    Chad Anderson. (2021, April 27). Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages. Retrieved July 29, 2024.

    Open source URL
  74. [74]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  75. [75]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  76. [76]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  77. [77]
    Flashpoint FIN 7 March 2019

    Platt, J. and Reeves, J.. (2019, March). FIN7 Revisited: Inside Astra Panel and SQLRat Malware. Retrieved June 18, 2019.

    Open source URL
  78. [78]
    Malwarebytes DarkComet March 2018

    Kujawa, A. (2018, March 27). You dirty RAT! Part 1: DarkComet. Retrieved November 6, 2018.

    Open source URL
  79. [79]
    FireEye FIN6 Apr 2019

    McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.

    Open source URL
  80. [80]
    FireEye FIN6 April 2016

    FireEye Threat Intelligence. (2016, April). Follow the Money: Dissecting the Operations of the Cyber Crime Group FIN6. Retrieved November 17, 2024.

    Open source URL
  81. [81]
    Zscaler

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.

    Open source URL
  82. [82]
    ESET Operation Spalax Jan 2021

    M. Porolli. (2021, January 21). Operation Spalax: Targeted malware attacks in Colombia. Retrieved September 16, 2022.

    Open source URL
  83. [83]
    Crowdstrike DNC June 2016

    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.

    Open source URL
  84. [84]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  85. [85]
    Donut Github

    TheWover. (2019, May 9). donut. Retrieved March 25, 2022.

    Open source URL
  86. [86]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  87. [87]
    NCC Group Fivehands June 2021

    Matthews, M. and Backhouse, W. (2021, June 15). Handy guide to a new Fivehands ransomware variant. Retrieved June 24, 2021.

    Open source URL
  88. [88]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  89. [89]
    ClearSky Wilted Tulip July 2017

    ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.

  90. [90]
    QiAnXin APT-C-36 Feb2019

    QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.

    Open source URL
  91. [91]
    ESET ForSSHe December 2018

    Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

    Open source URL
  92. [92]
    Mandiant Cutting Edge January 2024

    McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.

    Open source URL
  93. [93]
    Mandiant Cutting Edge Part 2 January 2024

    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.

    Open source URL
  94. [94]
    FireEye APT19

    Ahl, I. (2017, June 06). Privileges and Credentials: Phished at the Request of Counsel. Retrieved May 17, 2018.

    Open source URL
  95. [95]
    Mandiant ROADSWEEP August 2022

    Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.

    Open source URL
  96. [96]
    FireEye Hacking Team

    FireEye Threat Intelligence. (2015, July 13). Demonstrating Hustle, Chinese APT Groups Quickly Use Zero-Day Vulnerability (CVE-2015-5119) Following Hacking Team Leak. Retrieved January 25, 2016.

    Open source URL
  97. [97]
    Nccgroup Gh0st April 2018

    Pantazopoulos, N. (2018, April 17). Decoding network data from a Gh0st RAT variant. Retrieved November 2, 2018.

    Open source URL
  98. [98]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  99. [99]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  100. [100]
    ANSSI Sandworm January 2021

    ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.

    Open source URL
  101. [101]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  102. [102]
    Mandiant Pulse Secure Zero-Day April 2021

    Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.

    Open source URL
  103. [103]
    ORB Mandiant

    Raggi, Michael. (2024, May 22). IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders. Retrieved July 8, 2024.

    Open source URL
  104. [104]
    Microsoft PowerShell CLM

    PowerShell Team. (2017, November 2). PowerShell Constrained Language Mode. Retrieved March 27, 2023.

    Open source URL
  105. [105]
    CheckPoint Bandook Nov 2020

    Check Point. (2020, November 26). Bandook: Signed & Delivered. Retrieved May 31, 2021.

    Open source URL
  106. [106]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  107. [107]
    Lumen Versa 2024

    Black Lotus Labs. (2024, August 27). Taking The Crossroads: The Versa Director Zero-Day Exploitaiton. Retrieved August 27, 2024.

    Open source URL
  108. [108]
    Symantec Whitefly March 2019

    Symantec. (2019, March 6). Whitefly: Espionage Group has Singapore in Its Sights. Retrieved May 26, 2020.

    Open source URL
  109. [109]
    GDATA Zeus Panda June 2017

    Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

    Open source URL
  110. [110]
    Mandiant APT42-untangling

    Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved October 9, 2024.

    Open source URL
  111. [111]
    CheckPoint SpeakUp Feb 2019

    Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan. Retrieved April 17, 2019.

    Open source URL
  112. [112]
    FBI FLASH APT39 September 2020

    FBI. (2020, September 17). Indicators of Compromise Associated with Rana Intelligence Computing, also known as Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, and ITG07. Retrieved December 10, 2020.

    Open source URL
  113. [113]
    FireEye APT39 Jan 2019

    Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.

    Open source URL
  114. [114]
    Mandiant Operation Ke3chang November 2014

    Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.

    Open source URL
  115. [115]
    NCC Group APT15 Alive and Strong

    Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.

    Open source URL
  116. [116]
    Microsoft PS JEA

    Microsoft. (2022, November 17). Just Enough Administration. Retrieved March 27, 2023.

    Open source URL
  117. [117]
    Netspi PowerShell Execution Policy Bypass

    Sutherland, S. (2014, September 9). 15 Ways to Bypass the PowerShell Execution Policy. Retrieved September 12, 2024.

    Open source URL
  118. [118]
    Cisco ArcaneDoor 2024

    Cisco Talos. (2024, April 24). ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices. Retrieved January 6, 2025.

    Open source URL
  119. [119]
    Volexity InkySquid RokRAT August 2021

    Cash, D., Grunzweig, J., Adair, S., Lancaster, T. (2021, August 25). North Korean BLUELIGHT Special: InkySquid Deploys RokRAT. Retrieved October 1, 2021.

    Open source URL
  120. [120]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  121. [121]
    ESET ForSSHe December 2018

    Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

    Open source URL
  122. [122]
    ESET ForSSHe December 2018

    Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

    Open source URL
  123. [123]
    Proofpoint TA505 October 2019

    Schwarz, D. et al. (2019, October 16). TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader. Retrieved May 29, 2020.

    Open source URL
  124. [124]
    ESET_MuddyWater_Dec2025

    ESET Research. (2025, December 2). MuddyWater: Snakes by the riverbank. Retrieved February 17, 2026.

    Open source URL
  125. [125]
    ESET ForSSHe December 2018

    Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.