1200KM / simulation
T1059.005 Visual Basic — Attack Simulation
Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as Component Object Model and the Native API through the Windows API. Although tagged as legacy with no planned future evolutions, VB is integrated and supported in the .NET Framework and cross-platform .NET Core. Derivative languages based on VB have also been created, such as Visual…
Technique description
Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as Component Object Model and the Native API through the Windows API. Although tagged as legacy with no planned future evolutions, VB is integrated and supported in the .NET Framework and cross-platform .NET Core. Derivative languages based on VB have also been created, such as Visual…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Visual Basic script execution to gather local computer information
Procedure 1620de42-160a-4fe5-bbaf-d3fef0181ce9; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Extract Memory via VBA
Procedure 8faff437-a114-4547-9a60-749652a03df6; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Encoded VBS code execution
Procedure e8209d5f-e42d-45e6-9c2f-633ac4f1eefa; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Molerats · G0021
- Lazarus Group · G0032
- Sandworm Team · G0034
- Patchwork · G0040
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- TA459 · G0062
- APT33 · G0064
- Leviathan · G0065
- APT37 · G0067
- MuddyWater · G0069
- Rancor · G0075
- Gorgon Group · G0078
- Cobalt Group · G0080
- APT38 · G0082
- FIN4 · G0085
- APT39 · G0087
- WIRTE · G0090
- Silence · G0091
- TA505 · G0092
- Kimsuky · G0094
- Machete · G0095
- APT-C-36 · G0099
- Inception · G0100
- Windshift · G0112
- Sidewinder · G0121
- Higaisa · G0126
- Mustang Panda · G0129
- Transparent Tribe · G0134
- LazyScripter · G0140
- Confucius · G0142
- HEXANE · G1001
- Earth Lusca · G1006
- SideCopy · G1008
- FIN13 · G1016
- TA2541 · G1018
- Malteiro · G1026
- RedCurl · G1039
- APT42 · G1044
- Contagious Interview · G1052
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.