1200KM / simulation
T1059.007 JavaScript — Attack Simulation
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser. JScript is the Microsoft implementation of the same scripting standard. JScript is interpreted via the Windows Script engine and thus integrated with many…
Technique description
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser. JScript is the Microsoft implementation of the same scripting standard. JScript is interpreted via the Windows Script engine and thus integrated with many…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- JScript execution to gather local computer information via cscript
Procedure 01d75adf-ca1b-4dd1-ac96-7c9550ad1035; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Turla KopiLuwak RC4 Decryption Stager
Procedure 02428cbe-c230-4353-b31d-61c9d328b153; elevation not declared required; cleanup not declared. Not executed or individually validated.
- JScript execution to gather local computer information via wscript
Procedure 0709945e-4fec-4c49-9faf-c3c292a74484; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Turla KopiLuwak Registry JavaScript Payload Execution
Procedure 9be739ec-b1ba-4950-94d0-e62444b23645; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Turla Kopiluwak Windows Enumeration
Procedure e65e6772-bfd3-4f25-934b-861d5caa34db; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Molerats · G0021
- FIN6 · G0037
- FIN7 · G0046
- APT32 · G0050
- MuddyWater · G0069
- Leafminer · G0077
- Cobalt Group · G0080
- Silence · G0091
- TA505 · G0092
- Kimsuky · G0094
- APT-C-36 · G0099
- Indrik Spider · G0119
- Evilnum · G0120
- Sidewinder · G0121
- Higaisa · G0126
- Mustang Panda · G0129
- LazyScripter · G0140
- Earth Lusca · G1006
- MoustachedBouncer · G1019
- Saint Bear · G1031
- Star Blizzard · G1033
- Winter Vivern · G1035
- TA577 · G1037
- TA578 · G1038
- Contagious Interview · G1052
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.