ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
MalwareLucifer

Lucifer can persist by setting Registry key values HKLM\Software\Microsoft\Windows\CurrentVersion\Run\QQMusic and HKCU\Software\Microsoft\Windows\CurrentVersion\Run\QQMusic.

T1547.001
Registry Run Keys / Startup Folder
MalwareBlackEnergy

The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareShimRat

ShimRat has installed a registry based start-up key HKCU\Software\microsoft\windows\CurrentVersion\Run to maintain persistence should other methods fail.

T1547.001
Registry Run Keys / Startup Folder
MalwareObliqueRAT

ObliqueRAT can gain persistence by a creating a shortcut in the infected user's Startup directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareAvaddon

Avaddon uses registry run keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareConficker

Conficker adds Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareFlagpro

Flagpro has dropped an executable file to the startup directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareHi-Zor

Hi-Zor creates a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePUNCHBUGGY

PUNCHBUGGY has been observed using a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwarePteranodon

Pteranodon copies itself to the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkTortilla

DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Run` registry key and by creating a .lnk shortcut file in the Windows startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareCORESHELL

CORESHELL has established persistence by creating autostart extensibility point (ASEP) Registry entries in the Run key and other Registry keys, as well as by creating shortcuts in the Internet Explorer Quick Start folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareRunningRAT

RunningRAT adds itself to the Registry key Software\Microsoft\Windows\CurrentVersion\Run to establish persistence upon reboot.

T1547.001
Registry Run Keys / Startup Folder
MalwareBBSRAT

BBSRAT has been loaded through DLL side-loading of a legitimate Citrix executable that is set to persist through the Registry Run key location HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ssonsvr.exe.

T1547.001
Registry Run Keys / Startup Folder
MalwarePlugX

PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareReaver

Reaver creates a shortcut file and saves it in a Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBisonal

Bisonal has added itself to the Registry key HKEY_CURRENT_USER\Software\Microsoft\CurrentVersion\Run\ for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareS-Type

S-Type may create a .lnk file to itself that is saved in the Start menu folder. It may also create the Registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ IMJPMIJ8.1{3 characters of Unique Identifier}.

T1547.001
Registry Run Keys / Startup Folder
MalwareLumma Stealer

Lumma Stealer has created registry keys to maintain persistence using `HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareSeaDuke

SeaDuke is capable of persisting via the Registry Run key or a .lnk file stored in the Startup directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareDustySky

DustySky achieves persistence by creating a Registry entry in HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareTruvasys

Truvasys adds a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSykipot

Sykipot has been known to establish persistence by adding programs to the Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareXbash

Xbash can create a Startup item for persistence if it determines it is on a Windows system.

T1547.001
Registry Run Keys / Startup Folder
MalwareRover

Rover persists by creating a Registry entry in HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\.

T1547.001
Registry Run Keys / Startup Folder
MalwareClambling

Clambling can establish persistence by adding a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwarePureCrypter

PureCrypter can set multiple Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkGate

DarkGate installation includes AutoIt script execution creating a shortcut to itself as an LNK object, such as bill.lnk, in the victim startup folder. DarkGate installation finishes with the creation of a registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareMongall

Mongall can establish persistence with the auto start function including using the value `EverNoteTrayUService`.

T1547.001
Registry Run Keys / Startup Folder
MalwareNanHaiShu

NanHaiShu modifies the %regrun% Registry to point itself to an autostart mechanism.

T1547.001
Registry Run Keys / Startup Folder
MalwareCarbanak

Carbanak stores a configuration files in the startup directory to automatically execute commands in order to persist across reboots.

T1547.001
Registry Run Keys / Startup Folder
MalwareElise

If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svchost : %APPDATA%\Microsoft\Network\svchost.exe. Other variants have set the following Registry keys for persistence: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\imejp : [self] and HKCU\Software\Microsoft\Windows\CurrentVersion\Run\IAStorD.

T1547.001
Registry Run Keys / Startup Folder
MalwareGazer

Gazer can establish persistence by creating a .lnk file in the Start menu.

T1547.001
Registry Run Keys / Startup Folder
MalwareLatrodectus

Latrodectus can set an AutoRun key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSaint Bot

Saint Bot has established persistence by being copied to the Startup directory or through the `\Software\Microsoft\Windows\CurrentVersion\Run` registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareChaes

Chaes has added persistence via the Registry key software\microsoft\windows\currentversion\run\microsoft windows html help.

T1547.001
Registry Run Keys / Startup Folder
MalwareLODEINFO

LODEINFO has used Registry run keys to set persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBriba

Briba creates run key Registry entries pointing to malicious DLLs dropped to disk.

T1547.001
Registry Run Keys / Startup Folder
MalwareMuddyViper

MuddyViper has the ability to establish persistence by configuring its installation directory as a Windows Startup folder by setting the following Registry values to `%APPDATALOCAL%\Microsoft\Windows\PPBCompatCache\ManagerCache`:  `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup`.

T1547.001
Registry Run Keys / Startup Folder
MalwareEVILNUM

EVILNUM can achieve persistence through the Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareSMOKEDHAM

SMOKEDHAM has used reg.exe to create a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can copy itself into the current user’s Startup folder as “Narrator.exe” for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGlassWorm

GlassWorm has set registry run keys for persistence in both `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run\`.

T1547.001
Registry Run Keys / Startup Folder
MalwareMetamorfo

Metamorfo has configured persistence to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run, Spotify =% APPDATA%\Spotify\Spotify.exe and used .LNK files in the startup folder to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmbargo

Embargo has modified the Windows Registry to start a custom service named irnagentd in Safe Mode.

T1547.001
Registry Run Keys / Startup Folder
MalwareTrojan.Karagany

Trojan.Karagany can create a link to itself in the Startup folder to automatically start itself upon system restart.

T1547.001
Registry Run Keys / Startup Folder
MalwareMagicRAT

MagicRAT can persist using malicious LNK objects in the victim machine Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareTINYTYPHON

TINYTYPHON installs itself under Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareKONNI

A version of KONNI has dropped a Windows shortcut into the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
Malwaregh0st RAT

gh0st RAT has added a Registry Run key to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.