Picus Security Explains MITRE ATT&CK Technique T1059.007 JavaScript
Cybersecurity firm Picus Security has released an analysis of the MITRE ATT&CK technique T1059.007 JavaScript, detailing how adversaries use JavaScript to execute malicious code across various environments.

Picus Security, a cybersecurity firm, has published a detailed analysis of T1059.007 JavaScript, a sub-technique within the MITRE ATT&CK framework's "Command and Scripting Interpreter" category.
This technique describes how threat actors leverage JavaScript-based scripting languages to execute malicious code across browsers, operating systems, and application environments. The widespread adoption and embedded nature of JavaScript in numerous software platforms make it a favored tool for attackers seeking to conceal their activities within legitimate traffic.
The report clarifies that T1059.007 also encompasses Microsoft's JScript and macOS's JavaScript for Automation (JXA). These tools enable code execution in both Windows and macOS environments, for instance, by manipulating COM objects or operating system interfaces.
The analysis also presents examples of attack campaigns that have utilized T1059.007 JavaScript. One observed campaign from June 2025 involved the injection of obfuscated JavaScript into websites. The objective was to redirect users to malicious sites and serve as a conduit for malware delivery, using a hidden iFrame-based redirector that activated only for users arriving from search engines.