Real-world descriptions of how a group, tool or campaign used a technique.
201 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTrickBot | TrickBot establishes persistence in the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePowerDuke | PowerDuke achieves persistence by using various Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePikabot | Pikabot maintains persistence following system checks through the Run key in the registry. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRCSession | RCSession has the ability to modify a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGRIFFON | GRIFFON has used a persistence module that stores the implant inside the Registry, which executes at logon. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAmadey | Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNOKKI | NOKKI has established persistence by writing the payload to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBackdoor.Oldrea | Backdoor.Oldrea adds Registry Run keys to achieve persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAvosLocker | AvosLocker has been executed via the `RunOnce` Registry key to run itself on safe mode. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareChinoxy | Chinoxy has established persistence via the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` registry key and by loading a dropper to `(%COMMON_ STARTUP%\\eoffice.exe)`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSharpStage | SharpStage has the ability to create persistence for the malware using the Registry autorun key and startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSmoke Loader | Smoke Loader adds a Registry Run key for persistence and adds a script in the Startup folder to deploy the payload. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEmissary | Variants of Emissary have added Run Registry keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHeartCrypt | HeartCrypt can set the `CurrentVersion\Run` key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareUrsnif | Ursnif has used Registry Run keys to establish automatic execution at system startup. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareThreatNeedle | ThreatNeedle can be loaded into the Startup folder (`%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\OneDrives.lnk`) as a Shortcut file for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRansomHub | RansomHub has created an autorun Registry key through the `-safeboot-instance -pass` command line argument. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRedLeaves | RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. If this fails, it attempts to add Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePOWERSOURCE | POWERSOURCE achieves persistence by setting a Registry Run key, with the path depending on whether the victim account has user or administrator access. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTsundere Botnet | Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareZeus Panda | Zeus Panda adds persistence by creating Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMatryoshka | Matryoshka can establish persistence by adding Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareInvisibleFerret | InvisibleFerret has established persistence within Windows devices by creating a .bat file “queue.bat” within the Startup folder to run a Python script. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareStrongPity | StrongPity can use the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePLAINTEE | PLAINTEE gains persistence by adding the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNebulae | Nebulae can achieve persistence through a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTONESHELL | TONESHELL has added Registry Run keys to achieve persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKasidet | Kasidet creates a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAppleSeed | AppleSeed has the ability to create the Registry key name |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNETWIRE | NETWIRE creates a Registry start-up entry to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEvilGrab | EvilGrab adds a Registry Run key for ctfmon.exe to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSslMM | To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAria-body | Aria-body has established persistence via the Startup folder or Run Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEmotet | Emotet has been observed adding the downloaded payload to the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSNUGRIDE | SNUGRIDE establishes persistence through a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCrimson | Crimson can add Registry run keys for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTurian | Turian can establish persistence by adding Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMachete | Machete used the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePrikormka | Prikormka adds itself to a Registry Run key with the name guidVGA or guidVSA. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePUBLOAD | PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGootloader | Gootloader can create an autorun entry for a PowerShell script to run at reboot. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAuTo Stealer | AuTo Stealer can place malicious executables in a victim's AutoRun registry key or StartUp directory, depending on the AV product installed, to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFLASHFLOOD | FLASHFLOOD achieves persistence by making an entry in the Registry's Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFlawedAmmyy | FlawedAmmyy has established persistence via the `HKCU\SOFTWARE\microsoft\windows\currentversion\run` registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSnip3 | Snip3 can create a VBS file in startup to persist after system restarts. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRifdoor | Rifdoor has created a new registry entry at |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGuLoader | GuLoader can establish persistence via the Registry under |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareInvisiMole | InvisiMole can place a lnk file in the Startup Folder to achieve persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCLAIMLOADER | CLAIMLOADER has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareOkrum | Okrum establishes persistence by creating a .lnk shortcut to itself in the Startup folder. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.