T1059.005Visual Basic
T1059.005 — Visual Basic is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 17 detection use cases covering it and 91 threat-intel articles citing it.
Execution
17Use cases
91Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (17)
Office app spawning script/LOLBin child process Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI Cisco NVM - Susp Script From Archive Triggering Network Activity Execute Javascript With Jscript COM CLSID Vbscript Execution Using Wscript App Windows Outlook Macro Created by Suspicious Process Suspicious Process DNS Query Known Abuse Web Services Suspicious Process With Discord DNS Query [LLM] Earth Dahu / Gamaredon HTA-to-VBScript chain (mshta.exe spawning wscript/cscript) [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging [LLM] cscript/wscript executing a script from .laravel_locale temp directory [LLM] cscript.exe launching .vbs from .laravel_locale temp directory [LLM] Kimsuky JSE dropper: wscript -> powershell hidden + certutil -decode chain [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) [LLM] PowerShell copy masqueraded as Windows Terminal in %PROGRAMDATA% running 6202033.ps1 [LLM] APT28 MacroMaze: schtasks creating wscript-launched persistence with 20/30/61-minute repeat [LLM] SnakeStealer Startup-Folder Persistence (ageless.vbs / .exe drop in Programs\Startup)Articles citing this technique (91)
high Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility art-74
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-220
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-537
crit ESET Threat Report H2 2025 art-647
high Defense in Depth art-1278