T1059.006 Python
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the python.exe interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.1
Python comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Adversaries can use these libraries to download and execute commands or other scripts as well as perform various malicious behaviors.
| Item | Value |
|---|---|
| ID | T1059.006 |
| Sub-techniques | T1059.001, T1059.002, T1059.003, T1059.004, T1059.005, T1059.006, T1059.007, T1059.008, T1059.009, T1059.010, T1059.011, T1059.012, T1059.013 |
| Tactics | TA0002 |
| Platforms | ESXi, Linux, Windows, macOS |
| Version | 1.1 |
| Created | 09 March 2020 |
| Last Modified | 24 October 2025 |
Procedure Examples
| ID | Name | Description |
|---|---|---|
| G0016 | APT29 | APT29 has developed malware variants written in Python.57 |
| G0067 | APT37 | APT37 has used Python scripts to execute payloads.47 |
| G0087 | APT39 | APT39 has used a command line utility and a network scanner written in python.5958 |
| S0234 | Bandook | Bandook can support commands to execute Python-based payloads.32 |
| G0060 | BRONZE BUTLER | BRONZE BUTLER has made use of Python-based remote access tools.48 |
| S0482 | Bundlore | Bundlore has used Python scripts to execute payloads.19 |
| S0631 | Chaes | Chaes has used Python scripts for execution and the installation of additional files.22 |
| G1021 | Cinnamon Tempest | Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files.56 |
| S0154 | Cobalt Strike | Cobalt Strike can use Python to perform execution.38403941 |
| S0369 | CoinTicker | CoinTicker executes a Python script to download its second stage.30 |
| G1052 | Contagious Interview | Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules.252729 |
| S0492 | CookieMiner | CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre.44 |
| C0029 | Cutting Edge | During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool.6766 |
| S0695 | Donut | Donut can generate shellcode outputs that execute via Python.3 |
| G0035 | Dragonfly | Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim.61 |
| S0547 | DropBook | DropBook is a Python-based backdoor compiled with PyInstaller.8 |
| G1006 | Earth Lusca | Earth Lusca used Python scripts for port scanning or building reverse shells.54 |
| S0377 | Ebury | Ebury has used Python to implement its DGA.31 |
| S1120 | FRAMESTING | FRAMESTING is a Python web shell that can embed in the Ivanti Connect Secure CAV Python package.36 |
| S1245 | InvisibleFerret | InvisibleFerret is written in Python and has used Python scripts for execution.2526272829 |
| S0581 | IronNetInjector | IronNetInjector can use IronPython scripts to load payloads with the help of a .NET injector.2 |
| S0387 | KeyBoy | KeyBoy uses Python scripts for installing files and performing execution.17 |
| S0276 | Keydnap | Keydnap uses Python for scripting to execute additional commands.45 |
| G0094 | Kimsuky | Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data.6263 |
| S0681 | Lizar | Lizar has used Python scripts (ps2x.py script and ps2p.py) to execute files on remote hosts using the Impacket library.12 |
| S1213 | Lumma Stealer | Lumma Stealer has used malicious Python scripts to execute payloads.46 |
| S0409 | Machete | Machete is written in Python and is used in conjunction with additional Python scripts.333435 |
| G0095 | Machete | Machete used multiple compiled Python scripts on the victim’s system. Machete’s main backdoor Machete is also written in Python.523335 |
| S0459 | MechaFlounder | MechaFlounder uses a python-based payload.23 |
| G0069 | MuddyWater | MuddyWater has developed tools in Python including Out1.55 |
| S1189 | Neo-reGeorg | Neo-reGeorg is a Python-based web shell.18 |
| C0014 | Operation Wocao | During Operation Wocao, threat actors’ backdoors were written in Python and compiled with py2exe.65 |
| S0428 | PoetRAT | PoetRAT was executed with a Python script and worked in conjunction with additional Python-based post-exploitation tools.37 |
| S0196 | PUNCHBUGGY | PUNCHBUGGY has used python scripts.11 |
| S0192 | Pupy | Pupy can use an add on feature when creating payloads that allows you to create custom Python scripts (“scriptlets”) to perform tasks offline (without requiring a session) such as sandbox detection, adding persistence, etc.7 |
| S1032 | PyDCrypt | PyDCrypt, along with its functions, is written in Python.15 |
| S0583 | Pysa | Pysa has used Python scripts to deploy ransomware.16 |
| G1039 | RedCurl | RedCurl has used a Python script to establish outbound communication and to execute commands using SMB port 445.60 |
| S1187 | reGeorg | reGeorg is a Python-based web shell.14 |
| S0332 | Remcos | Remcos uses Python scripts.4 |
| G0106 | Rocke | Rocke has used Python-based malware to install and spread their coinminer.51 |
| C0059 | Salesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used custom applications developed in python.64 |
| C0045 | ShadowRay | During ShadowRay, threat actors used the Python pty module to open reverse shells.68 |
| S0692 | SILENTTRINITY | SILENTTRINITY is written in Python and can use multiple Python scripts for execution on targeted systems.56 |
| S1035 | Small Sieve | Small Sieve can use Python scripts to execute commands.20 |
| S0374 | SpeakUp | SpeakUp uses Python scripts.13 |
| S1223 | THINCRUST | THINCRUST can use Python scripts for command execution.21 |
| G0131 | Tonto Team | Tonto Team has used Python-based tools for execution.49 |
| S0647 | Turian | Turian has the ability to use Python to spawn a Unix shell.24 |
| G0010 | Turla | Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads.2 |
| G1048 | UNC3886 | UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs.53 |
| S1164 | UPSTYLE | UPSTYLE is a Python-based application.4342 |
| S1218 | VIRTUALPIE | VIRTUALPIE is a Python-based backdoor malware.109 |
| S1217 | VIRTUALPITA | VIRTUALPITA can call a Python script to run commands on a targeted guest virtual machine.10 |
| G0128 | ZIRCONIUM | ZIRCONIUM has used Python-based implants to interact with compromised hosts.501 |
Mitigations
| ID | Mitigation | Description |
|---|---|---|
| M1049 | Antivirus/Antimalware | Anti-virus can be used to automatically quarantine suspicious files. |
| M1047 | Audit | Inventory systems for unauthorized Python installations. |
| M1038 | Execution Prevention | Denylist Python where not required. |
| M1033 | Limit Software Installation | Prevent users from installing Python where not required. |
References
-
Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021. ↩↩
-
Reichel, D. (2021, February 19). IronNetInjector: Turla’s New Malware Loading Tool. Retrieved February 24, 2021. ↩↩
-
Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018. ↩
-
Salvati, M (2019, August 6). SILENTTRINITY. Retrieved March 23, 2022. ↩
-
Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022. ↩
-
Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020. ↩
-
Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024. ↩
-
Alexander Marvi, Jeremy Koppen, Tufail Ahmed, and Jonathan Lepore. (2022, September 29). Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors. Retrieved March 26, 2025. ↩↩
-
Gorelik, M.. (2019, June 10). SECURITY ALERT: FIN8 IS BACK IN BUSINESS, TARGETING THE HOSPITALITY INDUSTRY. Retrieved June 13, 2019. ↩
-
BI.ZONE Cyber Threats Research Team. (2021, May 13). From pentest to APT attack: cybercriminal group FIN7 disguises its malware as an ethical hacker’s toolkit. Retrieved February 2, 2022. ↩
-
Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan. Retrieved April 17, 2019. ↩
-
xl7dev. (2016). reGeorg-master. Retrieved December 3, 2024. ↩
-
Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022. ↩
-
CERT-FR. (2020, April 1). ATTACKS INVOLVING THE MESPINOZA/PYSA RANSOMWARE. Retrieved March 1, 2021. ↩
-
Hulcoop, A., et al. (2016, November 17). It’s Parliamentary KeyBoy and the targeting of the Tibetan Community. Retrieved June 13, 2019. ↩
-
Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020. ↩
-
NCSC GCHQ. (2022, January 27). Small Sieve Malware Analysis Report. Retrieved August 22, 2022. ↩
-
Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023. ↩
-
Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021. ↩
-
Falcone, R. (2019, March 4). New Python-Based Payload MechaFlounder Used by Chafer. Retrieved May 27, 2020. ↩
-
Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021 ↩
-
eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025. ↩↩
-
Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025. ↩
-
Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025. ↩↩
-
Seongsu Park. (2024, November 4). From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West. Retrieved October 17, 2025. ↩
-
Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025. ↩↩
-
Thomas Reed. (2018, October 29). Mac cryptocurrency ticker app installs backdoors. Retrieved April 23, 2019. ↩
-
Vachon, F. (2017, October 30). Windigo Still not Windigone: An Ebury Update . Retrieved February 10, 2021. ↩
-
Check Point. (2020, November 26). Bandook: Signed & Delivered. Retrieved May 31, 2021. ↩
-
ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019. ↩↩
-
Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019. ↩
-
kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020. ↩↩
-
Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024. ↩
-
Mercer, W, et al. (2020, April 16). PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectors. Retrieved April 27, 2020. ↩
-
Cobalt Strike. (2017, December 8). Tactics, Techniques, and Procedures. Retrieved November 17, 2024. ↩
-
Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024. ↩
-
Mudge, R. (2017, May 23). Cobalt Strike 3.8 – Who’s Your Daddy?. Retrieved June 4, 2019. ↩
-
Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021. ↩
-
Unit 42. (2024, April 12). Threat Brief: Operation MidnightEclipse, Post-Exploitation Activity Related to CVE-2024-3400 . Retrieved January 15, 2025. ↩
-
Volexity Threat Research. (2024, April 12). Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400). Retrieved November 20, 2024. ↩
-
Chen, y., et al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved July 22, 2020. ↩
-
Patrick Wardle. (2017, January 1). Mac Malware of 2016. Retrieved September 21, 2018. ↩
-
Cybereaon Security Services Team. (n.d.). Your Data Is Under New Lummanagement: The Rise of LummaStealer. Retrieved March 22, 2025. ↩
-
Cash, D., Grunzweig, J., Adair, S., Lancaster, T. (2021, August 25). North Korean BLUELIGHT Special: InkySquid Deploys RokRAT. Retrieved October 1, 2021. ↩
-
Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020. ↩
-
Daniel Lughi, Jaromir Horejsi. (2020, October 2). Tonto Team - Exploring the TTPs of an advanced threat actor operating a large infrastructure. Retrieved October 17, 2021. ↩
-
Huntley, S. (2020, October 16). How We’re Tackling Evolving Online Threats. Retrieved March 24, 2021. ↩
-
Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019. ↩
-
The Cylance Threat Research Team. (2017, March 22). El Machete’s Malware Attacks Cut Through LATAM. Retrieved September 13, 2019. ↩
-
Alexander Marvi, Brad Slaybaugh, Ron Craft, and Rufus Brown. (2023, June 13). VMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors. Retrieved March 26, 2025. ↩
-
Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022. ↩
-
Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021. ↩
-
Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023. ↩
-
Symantec Security Response. (2015, July 13). “Forkmeiamfamous”: Seaduke, latest weapon in the Duke armory. Retrieved July 22, 2015. ↩
-
FBI. (2020, September 17). Indicators of Compromise Associated with Rana Intelligence Computing, also known as Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, and ITG07. Retrieved December 10, 2020. ↩
-
Rusu, B. (2020, May 21). Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia. Retrieved May 22, 2020. ↩
-
Tancio et al. (2024, March 6). Unveiling Earth Kapre aka RedCurl’s Cyberespionage Tactics With Trend Micro MDR, Threat Intelligence. Retrieved August 9, 2024. ↩
-
US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018. ↩
-
CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020. ↩
-
KISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024. ↩
-
Google Threat Intelligence Group. (2025, June 4). The Cost of a Call: From Voice Phishing to Data Extortion. Retrieved October 22, 2025. ↩
-
Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020. ↩
-
Lin, M. et al. (2024, February 27). Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts. Retrieved March 1, 2024. ↩
-
Meltzer, M. et al. (2024, January 10). Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN. Retrieved February 27, 2024. ↩
-
Lumelsly, A. et al. (2024, March 26). ShadowRay: First Known Attack Campaign Targeting AI Workloads Actively Exploited In The Wild. Retrieved December 2, 2024. ↩