ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1547.001×

201 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
MalwareTrickBot

TrickBot establishes persistence in the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwarePowerDuke

PowerDuke achieves persistence by using various Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwarePikabot

Pikabot maintains persistence following system checks through the Run key in the registry.

T1547.001
Registry Run Keys / Startup Folder
MalwareRCSession

RCSession has the ability to modify a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGRIFFON

GRIFFON has used a persistence module that stores the implant inside the Registry, which executes at logon.

T1547.001
Registry Run Keys / Startup Folder
MalwareAmadey

Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareNOKKI

NOKKI has established persistence by writing the payload to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareBackdoor.Oldrea

Backdoor.Oldrea adds Registry Run keys to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareAvosLocker

AvosLocker has been executed via the `RunOnce` Registry key to run itself on safe mode.

T1547.001
Registry Run Keys / Startup Folder
MalwareChinoxy

Chinoxy has established persistence via the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` registry key and by loading a dropper to `(%COMMON_ STARTUP%\\eoffice.exe)`.

T1547.001
Registry Run Keys / Startup Folder
MalwareSharpStage

SharpStage has the ability to create persistence for the malware using the Registry autorun key and startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareSmoke Loader

Smoke Loader adds a Registry Run key for persistence and adds a script in the Startup folder to deploy the payload.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmissary

Variants of Emissary have added Run Registry keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareHeartCrypt

HeartCrypt can set the `CurrentVersion\Run` key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareUrsnif

Ursnif has used Registry Run keys to establish automatic execution at system startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareThreatNeedle

ThreatNeedle can be loaded into the Startup folder (`%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\OneDrives.lnk`) as a Shortcut file for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareRansomHub

RansomHub has created an autorun Registry key through the `-safeboot-instance -pass` command line argument.

T1547.001
Registry Run Keys / Startup Folder
MalwareRedLeaves

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. If this fails, it attempts to add Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwarePOWERSOURCE

POWERSOURCE achieves persistence by setting a Registry Run key, with the path depending on whether the victim account has user or administrator access.

T1547.001
Registry Run Keys / Startup Folder
MalwareTsundere Botnet

Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login.

T1547.001
Registry Run Keys / Startup Folder
MalwareZeus Panda

Zeus Panda adds persistence by creating Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareMatryoshka

Matryoshka can establish persistence by adding Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareInvisibleFerret

InvisibleFerret has established persistence within Windows devices by creating a .bat file “queue.bat” within the Startup folder to run a Python script.

T1547.001
Registry Run Keys / Startup Folder
MalwareStrongPity

StrongPity can use the HKCU\Software\Microsoft\Windows\CurrentVersion\Run Registry key for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePLAINTEE

PLAINTEE gains persistence by adding the Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce.

T1547.001
Registry Run Keys / Startup Folder
MalwareNebulae

Nebulae can achieve persistence through a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareTONESHELL

TONESHELL has added Registry Run keys to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareKasidet

Kasidet creates a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareAppleSeed

AppleSeed has the ability to create the Registry key name EstsoftAutoUpdate at HKCU\Software\Microsoft/Windows\CurrentVersion\RunOnce to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETWIRE

NETWIRE creates a Registry start-up entry to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareEvilGrab

EvilGrab adds a Registry Run key for ctfmon.exe to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSslMM

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1547.001
Registry Run Keys / Startup Folder
MalwareAria-body

Aria-body has established persistence via the Startup folder or Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmotet

Emotet has been observed adding the downloaded payload to the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run key to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSNUGRIDE

SNUGRIDE establishes persistence through a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareCrimson

Crimson can add Registry run keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareTurian

Turian can establish persistence by adding Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareMachete

Machete used the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePrikormka

Prikormka adds itself to a Registry Run key with the name guidVGA or guidVSA.

T1547.001
Registry Run Keys / Startup Folder
MalwarePUBLOAD

PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareGootloader

Gootloader can create an autorun entry for a PowerShell script to run at reboot.

T1547.001
Registry Run Keys / Startup Folder
MalwareAuTo Stealer

AuTo Stealer can place malicious executables in a victim's AutoRun registry key or StartUp directory, depending on the AV product installed, to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareFLASHFLOOD

FLASHFLOOD achieves persistence by making an entry in the Registry's Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareFlawedAmmyy

FlawedAmmyy has established persistence via the `HKCU\SOFTWARE\microsoft\windows\currentversion\run` registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareSnip3

Snip3 can create a VBS file in startup to persist after system restarts.

T1547.001
Registry Run Keys / Startup Folder
MalwareRifdoor

Rifdoor has created a new registry entry at HKEY_CURRENT_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Graphics with a value of C:\ProgramData\Initech\Initech.exe /run.

T1547.001
Registry Run Keys / Startup Folder
MalwareGuLoader

GuLoader can establish persistence via the Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce.

T1547.001
Registry Run Keys / Startup Folder
MalwareInvisiMole

InvisiMole can place a lnk file in the Startup Folder to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareCLAIMLOADER

CLAIMLOADER has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareOkrum

Okrum establishes persistence by creating a .lnk shortcut to itself in the Startup folder.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.