T1059.004 Unix Shell — ATT&CK Technique
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges. Unix shells also support scripts that enable sequential execution of commands as well as other typical programming operations such as conditionals and loops. Common uses of shell scripts include long or repetitive tasks, or the need to run the same set of commands on multiple systems. Adversaries may abuse Unix shells to execute various commands or payloads. Interactive shells may be accessed through command and control channels or during lateral movement such as with SSH. Adversaries may also leverage shell scripts to deliver and execute multiple commands on victims or as part of payloads used for persistence. Some systems, such as embedded devices, lightweight Linux distributions, and ESXi servers, may leverage stripped-down Unix shells via Busybox, a small executable that contains a variety of tools, including a simple shell.
Detection coverage (29)
- Axios NPM Compromise Indicators - Linux high
- Axios NPM Compromise Indicators - macOS high
- Potentially Suspicious Long Filename Pattern - Linux low
- AWS EC2 Startup Shell Script Change high
- Suspicious Download and Execute Pattern via Curl/Wget high
- Equation Group Indicators high
- Suspicious Activity in Shell Commands high
- Suspicious Reverse Shell Command Line high
- JexBoss Command Sequence high
- Suspicious Commands Linux medium
- Suspicious Filename with Embedded Base64 Commands high
- Linux Reverse Shell Indicator critical
- BPFtrace Unsafe Option Usage medium
- Shell Invocation via Env Command - Linux high
- Nohup Execution medium
- Interactive Bash Suspicious Children medium
- Script Interpreter Spawning Credential Scanner - Linux high
- Potential Abuse of Linux Magic System Request Key medium
- Linux Decode Base64 to Shell
- Linux Magic SysRq Key Abuse
- Linux Suspicious React or Next.js Child Process
- Linux Unix Shell Enable All SysRq Functions
- MacOS LOLbin
- Suspicious Linux Discovery Commands
- Linux MOTD Script Added
- Linux Netcat Outbound Connection
- Linux Possible System Binary Backdoor
- Linux Suspicious Privileged Container Execution
- Linux Suspicious XDG Autostart
Malware using this technique
- BRICKSTORM
- COATHANGER
- WindTail
- Exaramel for Linux
- CASTLETAP
- NETWIRE
- J-magic
- Gomir
- BOLDMOVE
- Turian
- Hildegard
- Cuckoo Stealer
- Skidmap
- REPTILE
- Doki
- Kazuar
- Green Lambert
- SnappyTCP
- Chaos
- Anchor
- PULSECHECK
- Kobalos
- PACEMAKER
- Bundlore
- BPFDoor
- Derusbi
- Drovorub
- OSX_OCEANLOTUS.D
- NKAbuse
- MacMa
- Proton
- CallMe
- RIFLESPINE
- CoinTicker
- Penquin
- Ebury
- Kinsing
- PITSTOP
- ZIPLINE
- Shai-Hulud
- VIRTUALPITA
- XCSSET
- AppleJeus
- TeamPCP Cloud Stealer
- CookieMiner
- OSX/Shlayer
- LoudMiner
- CanisterWorm
- Fysbis