T1059.005Visual Basic
T1059.005 — Visual Basic is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 18 detection use cases covering it and 155 threat-intel articles citing it.
Execution
18Use cases
155Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (18)
Office app spawning script/LOLBin child process Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI Cisco NVM - Susp Script From Archive Triggering Network Activity Execute Javascript With Jscript COM CLSID Vbscript Execution Using Wscript App Windows Outlook Macro Created by Suspicious Process Suspicious Process DNS Query Known Abuse Web Services Suspicious Process With Discord DNS Query [LLM] ClickFix PowerShell loader spawning wscript to run downloaded VBScript [LLM] BusySnake VBScript persistence: wh_selfdelete.vbs / run.vbs in WindowsHelper [LLM] Gamaredon HTA downloader auto-executing from Startup folder at logon (mshta.exe) [LLM] Gamaredon stealer exfiltration to S3-compatible cloud storage (Wasabi/Tebi/Intercolo) [LLM] axios RAT Windows payload drop (6202033.vbs/.ps1, ProgramData\wt) during npm install [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging [LLM] cscript/wscript executing a script from .laravel_locale temp directory [LLM] cscript.exe launching .vbs from .laravel_locale temp directory [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) [LLM] PowerShell copy masqueraded as Windows Terminal in %PROGRAMDATA% running 6202033.ps1Articles citing this technique (155)
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-06
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
crit Begun, the Patch Wars have art-150
crit Winning 54% of the time art-214
crit ESET Threat Report H1 2026 art-221
crit When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website art-246
high Catan and Mouse art-261
high The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration art-312
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-402
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
crit ESET Threat Report H2 2025 art-732
crit CISA KEV: CVE-2024-38226 — Microsoft Publisher Protection Mechanism Failure Vulnerability art-1230
high Defense in Depth art-1391
high Ethical hacking techniques art-1698
high Ethical Hacking: Top Tools art-1702
crit API Security Guide art-1751
high Securing the web (forward) art-1803
high Cybersecurity Hygiene 101 art-1824
crit Secure Python URL validation art-1937
high Securing PHP containers art-2082
crit CISA KEV: CVE-2014-6287 — Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability art-2438
med Python Poetry package manager and security integration with software composition analysis tool art-3260
crit XSS Attacks: The Next Wave art-3641
high A CEO's guide to Emacs art-3693