ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1547.001×

57 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
GroupBlackByte

BlackByte has used Registry Run keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT3

APT3 places scripts in the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupKimsuky

Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key.

T1547.001
Registry Run Keys / Startup Folder
GroupPatchwork

Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT41

APT41 created and modified startup files for persistence. APT41 added a registry key in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost to establish persistence for Cobalt Strike.

T1547.001
Registry Run Keys / Startup Folder
GroupDragonfly

Dragonfly has added the registry value ntdll to the Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupGorgon Group

Gorgon Group malware can create a .lnk file and add a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT32

APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly.

T1547.001
Registry Run Keys / Startup Folder
GroupMuddyWater

MuddyWater has added Registry Run key KCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemTextEncoding to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupNaikon

Naikon has modified a victim's Windows Run registry to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN6

FIN6 has used Registry Run keys to establish persistence for its downloader tools known as HARDTACK and SHIPBREAD.

T1547.001
Registry Run Keys / Startup Folder
GroupGamaredon Group

Gamaredon Group tools have registered Run keys in the registry to give malicious VBS files persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupStorm-1811

Storm-1811 has created Windows Registry Run keys that execute various batch scripts to establish persistence on victim devices.

T1547.001
Registry Run Keys / Startup Folder
GroupTeamTNT

TeamTNT has added batch scripts to the startup folder.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN7

FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT18

APT18 establishes persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key.

T1547.001
Registry Run Keys / Startup Folder
GroupSidewinder

Sidewinder has added paths to executables in the Registry to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupMustang Panda

Mustang Panda has created the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\AdobelmdyU to maintain persistence. Mustang Panda has also established persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
GroupZIRCONIUM

ZIRCONIUM has created a Registry Run key named Dropbox Update Setup to establish persistence for a malicious Python binary.

T1547.001
Registry Run Keys / Startup Folder
GroupRocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT39

APT39 has maintained persistence using the startup folder.

T1547.001
Registry Run Keys / Startup Folder
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to place a .bat file in the Startup Folder.

T1547.001
Registry Run Keys / Startup Folder
GroupTA2541

TA2541 has placed VBS files in the Startup folder and used Registry run keys to establish persistence for malicious payloads.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT37

APT37's has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\.

T1547.001
Registry Run Keys / Startup Folder
GroupHigaisa

Higaisa added a spoofed binary to the start-up folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupTropic Trooper

Tropic Trooper has created shortcuts in the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupPutter Panda

A dropper used by Putter Panda installs itself into the ASEP Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run with a value named McUpdate.

T1547.001
Registry Run Keys / Startup Folder
GroupKe3chang

Several Ke3chang backdoors achieved persistence by adding a Run key.

T1547.001
Registry Run Keys / Startup Folder
GroupConfucius

Confucius has dropped malicious files into the startup folder `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` on a compromised host in order to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupLeviathan

Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor.

T1547.001
Registry Run Keys / Startup Folder
GroupTurla

A Turla Javascript backdoor added a local_update_check value under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence. Additionally, a Turla custom executable containing Metasploit shellcode is saved to the Startup folder to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupRedCurl

RedCurl has established persistence by creating entries in `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT29

APT29 added Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupDark Caracal

Dark Caracal's version of Bandook adds a registry key to HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupBRONZE BUTLER

BRONZE BUTLER has used a batch script that adds a Registry Run key to establish malware persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupDarkhotel

Darkhotel has been known to establish persistence by adding programs to the Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
GroupLazyScripter

LazyScripter has achieved persistence via writing a PowerShell script to the autorun registry key.

T1547.001
Registry Run Keys / Startup Folder
GroupWindshift

Windshift has created LNK files in the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupLuminousMoth

LuminousMoth has used malicious DLLs that setup persistence in the Registry Key `HKCU\Software\Microsoft\Windows\Current Version\Run`.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT28

APT28 has deployed malware that has copied itself to the startup directory for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupRTM

RTM has used Registry run keys to establish persistence for the RTM Trojan and other tools, such as a modified version of TeamViewer remote desktop software.

T1547.001
Registry Run Keys / Startup Folder
GroupLazarus Group

Lazarus Group has maintained persistence by loading malicious code into a startup folder or by adding a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
GroupSilence

Silence has used HKCU\Software\Microsoft\Windows\CurrentVersion\Run, HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupCobalt Group

Cobalt Group has used Registry Run keys for persistence. The group has also set a Startup path to launch the PowerShell shell command and download Cobalt Strike.

T1547.001
Registry Run Keys / Startup Folder
GroupWizard Spider

Wizard Spider has established persistence via the Registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and a shortcut within the startup folder.

T1547.001
Registry Run Keys / Startup Folder
GroupMolerats

Molerats saved malicious files within the AppData and Startup folders to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupMoonstone Sleet

Moonstone Sleet used registry run keys for process execution during initial victim infection.

T1547.001
Registry Run Keys / Startup Folder
GroupInception

Inception has maintained persistence by modifying Registry run key value
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\.

T1547.001
Registry Run Keys / Startup Folder
GroupVOID MANTICORE

VOID MANTICORE has created Windows Registry entries to autorun stage two malware payloads to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupPROMETHIUM

PROMETHIUM has used Registry run keys to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.