Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1112 Modify Registry |
MalwareConficker | Conficker adds keys to the Registry at |
| T1112 Modify Registry |
MalwareDarkTortilla | DarkTortilla has modified registry keys for persistence. |
| T1112 Modify Registry |
MalwareROKRAT | ROKRAT can modify the `HKEY_CURRENT_USER\Software\Microsoft\Office\` registry key so it can bypass the VB object model (VBOM) on a compromised host. |
| T1112 Modify Registry |
MalwareDarkWatchman | DarkWatchman can modify Registry values to store configuration strings, keylogger, and output of components. |
| T1112 Modify Registry |
MalwarePlugX | PlugX has a module to create, delete, or modify Registry keys. |
| T1112 Modify Registry |
MalwareBisonal | Bisonal has deleted Registry keys to clean up its prior activity. |
| T1112 Modify Registry |
MalwareNOOPLDR | NOOPLDR can store its payload in the Registry using a random hex string in `HKCU\SOFTWARE\Microsoft\COM3`. |
| T1112 Modify Registry |
MalwareExplosive | Explosive has a function to write itself to Registry values. |
| T1112 Modify Registry |
MalwareRover | Rover has functionality to remove Registry Run key persistence as a cleanup procedure. |
| T1112 Modify Registry |
MalwareClambling | Clambling can set and delete Registry keys. |
| T1112 Modify Registry |
MalwareLockBit 3.0 | LockBit 3.0 can change the Registry values for Group Policy refresh time, to disable SmartScreen, and to disable Windows Defender. |
| T1112 Modify Registry |
MalwareHydraq | Hydraq creates a Registry subkey to register its created service, and can also uninstall itself later by deleting this value. Hydraq's backdoor also enables remote attackers to modify and delete subkeys. |
| T1112 Modify Registry |
MalwareFerocious | Ferocious has the ability to add a Class ID in the current user Registry hive to enable persistence mechanisms. |
| T1112 Modify Registry |
MalwareCaterpillar WebShell | Caterpillar WebShell has a command to modify a Registry key. |
| T1112 Modify Registry |
MalwareNetwalker | Netwalker can add the following registry entry: |
| T1112 Modify Registry |
MalwareChaes | Chaes can modify Registry values to stored information and establish persistence. |
| T1112 Modify Registry |
MalwareCharmPower | CharmPower can remove persistence-related artifacts from the Registry. |
| T1112 Modify Registry |
MalwareMuddyViper | MuddyViper has the ability to clear the Registry values in the Windows Startup folder that were previously set for persistence. |
| T1112 Modify Registry |
MalwareTYPEFRAME | TYPEFRAME can install encrypted configuration data under the Registry key |
| T1112 Modify Registry |
MalwareEVILNUM | EVILNUM can make modifications to the Regsitry for persistence. |
| T1112 Modify Registry |
MalwareSMOKEDHAM | SMOKEDHAM has modified registry keys for persistence, to enable credential caching for credential access, and to facilitate lateral movement via RDP. |
| T1112 Modify Registry |
MalwareMori | Mori can write data to `HKLM\Software\NFC\IPA` and `HKLM\Software\NFC\` and delete Registry values. |
| T1112 Modify Registry |
MalwareQUADAGENT | QUADAGENT modifies an HKCU Registry key to store a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications. |
| T1112 Modify Registry |
MalwareUroburos | Uroburos can store configuration information in the Registry including the initialization vector and AES key needed to find and decrypt other Uroburos components. |
| T1112 Modify Registry |
MalwareMetamorfo | Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key. |
| T1112 Modify Registry |
MalwareEmbargo | Embargo has modified and deleted Registry keys to add services, and to disable Security Solutions such as Windows Defender. |
| T1112 Modify Registry |
MalwarePipeMon | PipeMon has modified the Registry to store its encrypted payload. |
| T1112 Modify Registry |
MalwareKONNI | KONNI has modified registry keys of ComSysApp, Svchost, and xmlProv on the machine to gain persistence. |
| T1112 Modify Registry |
Malwaregh0st RAT | gh0st RAT has altered the InstallTime subkey. |
| T1112 Modify Registry |
MalwareShamoon | Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting |
| T1112 Modify Registry |
MalwareBlack Basta | Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence. |
| T1112 Modify Registry |
MalwareCatchamas | Catchamas creates three Registry keys to establish persistence by adding a Windows Service. |
| T1112 Modify Registry |
MalwareAttor | Attor's dispatcher can modify the Run registry key. |
| T1112 Modify Registry |
MalwareMegaCortex | MegaCortex has added entries to the Registry for ransom contact information. |
| T1112 Modify Registry |
MalwareStreamEx | StreamEx has the ability to modify the Registry. |
| T1112 Modify Registry |
MalwareNightClub | NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence. |
| T1112 Modify Registry |
MalwareMosquito | Mosquito can modify Registry keys under |
| T1112 Modify Registry |
MalwareRTM | RTM can delete all Registry entries created during its execution. |
| T1112 Modify Registry |
MalwareBlackByte Ransomware | BlackByte Ransomware modifies the victim Registry to prevent system recovery. |
| T1112 Modify Registry |
MalwareGrandoreiro | Grandoreiro can modify the Registry to store its configuration at `HKCU\Software\` under frequently changing names including |
| T1112 Modify Registry |
MalwareSibot | Sibot has modified the Registry to install a second-stage script in the |
| T1112 Modify Registry |
MalwareTarrask | Tarrask is able to delete the Security Descriptor (`SD`) registry subkey in order to “hide” scheduled tasks. |
| T1112 Modify Registry |
MalwareSOUNDBITE | SOUNDBITE is capable of modifying the Registry. |
| T1112 Modify Registry |
MalwareBADCALL | BADCALL modifies the firewall Registry key |
| T1112 Modify Registry |
MalwareHiddenFace | HiddenFace can store its configuration file in the Registry. |
| T1112 Modify Registry |
MalwareHermeticWiper | HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items. |
| T1112 Modify Registry |
MalwarePysa | Pysa has modified the registry key “SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System” and added the ransom note. |
| T1112 Modify Registry |
MalwareKapeka | Kapeka writes persistent configuration information to the victim host registry. |
| T1112 Modify Registry |
MalwareLockBit 2.0 | LockBit 2.0 can create Registry keys to bypass UAC and for persistence. |
| T1112 Modify Registry |
MalwarePandora | Pandora can write an encrypted token to the Registry to enable processing of remote commands. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.