FORENSIA

ATT&CK · T1059.007 · sub-technique

JavaScript

Tactics: execution

About

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser. JScript is the Microsoft implementation of the same scripting standard. JScript is interpreted via the Windows Script engine and thus integrated with many components of Windows such as the Component Object Model and Internet Explorer HTML Application (HTA) pages. JavaScript for Automation (JXA) is a macOS scripting language based on JavaScript, included as part of Apple’s Open Scripting Architecture (OSA), that was introduced in OSX 10.10. Apple’s OSA provides scripting capabilities to control applications, interface with the operating system, and bridge access into the rest of Apple’s internal APIs. As of OSX 10.10, OSA only supports two languages, JXA and AppleScript. Scripts can be executed via the command line utility <code>osascript</code>, they can be compiled into applications or script files via <code>osacompile</code>, and they can be compiled and executed in memory of other programs by leveraging the OSAKit Framework. Adversaries may abuse various implementations of JavaScript to execute various behaviors. Common uses include hosting malicious scripts on websites as part of a Drive-by Compromise or downloading and executing these script files as secondary payloads. Since these payloads are text-based, it is also very common for adversaries to obfuscate their content as part of Obfuscated Files or Information.

Platforms: Linux, macOS, WindowsParent: T1059 Command and Scripting InterpreterMITRE ATT&CK ↗

Used by actors

26 known groups

Software

38 malware/tools implement this

Cobalt StrikePOWERSTATSNanHaiShuInvisiMolejRATRemcosXbashKONNIAstarothGRIFFONMetamorfoValakBundloreAppleSeedChaesEnvyScoutAvaddonSpicyOmeletteJSS LoaderQakBotDarkWatchmanDonutKOPILUWAKWARPWIRESocGholishGootloaderFRPLatrodectusBlackByte RansomwareStrelaStealerBeaverTailXORIndex LoaderHexEval Loaderevilginx2Shai-HuludGlassWormAshTagTsundere Botnet

Corpus indicators tagged with this technique

1,122 indicators in the corpus carry T1059.007.

IndicatorTypeFamilySevSrc
cve-2026-1969cve851
cve-2025-7852cve851
cve-2025-7443cve851
cve-2026-3844cve851
cve-2021-29441cve851
cve-2025-12057cve851
cve-2026-0740cve851
cve-2025-34085cve851
1aaf59f05bb724d501cc9bcd6642ab8fd7347cf274d46c24719c9dced9b22beasha256phishing802
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801
e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95sha256phishing801
670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92sha256phishing801
f79d05065a2ba7937b8781e69b5859d78d5f65f01fb291ae27d28277a5e37f9bhash801
83b7a106a5e810a1781e62b278909396hash801
1b25c3d56fdb195b427a9c3bfc1f0e98e77a15322e8d3fc53a18edcc4891847fsha256phishing802
1fc0a876a121882ffaad6677f444cf5bhash801
248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51dbsha256phishing802
7b297f18ece81e87608e158288cc9c06cb9f4a8f1b2d2256aecf7bba8d7be2absha256phishing802
86db2530298e6335d3ecc66c2818cfbd0a6b11fcdfcb75f575b9fcce1faa00f1hash801
43d597783af656a35184021f5e20686896463a1712f9216e0217a2ca740e3935sha256phishing802
4ce45e016a304d813e67b29a08265b2101c2e15a09ace5de6539cad02567affesha256supply_chain801
b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173sha256phishing801
22de84e8f29cba932cf65cf4dc1d333cb8b2e468204f97030712bee32691ac3bsha256phishing802
44a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695fsha256phishing802
50ebf107d522326c9a9db8821fe3263aa5136964faaf5dd183657bbb52725f84sha256phishing802
07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841sha256phishing801
5115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35dsha256phishing802
5272917261d7091a59e00f9d09cd7eb1d3e111115a5b367f79a66d0d7c7b01f4sha256phishing802
5ab41cf20315d2ea1385967d588159873a65ef5581a0b78de06c0d8617894194sha256phishing802
771a47120b935e218322046e838347d722d265b91f1afdef91194a5bec86a97asha256phishing802

Showing the top 30 by severity of 1,122.