TACTIC: EXECUTION
PowerShell (T1059.001): real cases
MITRE Definition ↗ Adversaries abuse the Windows PowerShell command environment to execute commands and download malicious payloads.
Key Facts
Technique ID
T1059.001
Execution
Mapped Cases
2
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1059.001.
- Tactical Phase: Execution.
- Substantiated in 2 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)
sentenced 2018-03-27
Primary Source Evidence Excerpt: Indictment ¶ 16, Page 9
"Malicious macros embedded in the documents launched hidden PowerShell scripts to download the Carbanak malware suite."
U.S. District Court for the Western District of Washington
View full case dossier →
U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)
fugitive 2018-07-13
Primary Source Evidence Excerpt: Indictment ¶ 33, Page 14
"Defendants used custom X-Agent malware and executed PowerShell scripts to automate file collection across internal exchange servers."
U.S. District Court for the District of Columbia
View full case dossier →