Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDnsSystem | DnsSystem can write itself to the Startup folder to gain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMoleNet | MoleNet can achieve persitence on the infected machine by setting the Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareJHUHUGIT | JHUHUGIT has used a Registry Run key to establish persistence by executing JavaScript code within the rundll32.exe process. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSPACESHIP | SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareIxeshe | Ixeshe can achieve persistence by adding itself to the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareVBShower | VBShower used |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRogueRobin | RogueRobin created a shortcut in the Windows startup folder to launch a PowerShell script each time the user logs in to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSDBbot | SDBbot has the ability to add a value to the Registry Run key to establish persistence if it detects it is running with regular user privilege. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMosquito | Mosquito establishes persistence under the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRTM | RTM tries to add a Registry Run key under the name "Windows Update" to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGrandoreiro | Grandoreiro can use run keys and create link files in the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLiteDuke | LiteDuke can create persistence by adding a shortcut in the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSakula | Most Sakula samples maintain persistence by setting the Registry Run key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBazar | Bazar can create or add files to Registry Run Keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBadPatch | BadPatch establishes a foothold by adding a link to the malware executable in the startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareXLoader | XLoader establishes persistence by copying its executable in a subdirectory of `%APPDATA%` or `%PROGRAMFILES%`, and then modifies Windows Registry Run keys or policies keys to execute the executable on system start. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRyuk | Ryuk has used the Windows command line to create a Registry entry under |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFinal1stspy | Final1stspy creates a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLockBit 2.0 | LockBit 2.0 can use a Registry Run key to establish persistence at startup. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareZebrocy | Zebrocy creates an entry in a Registry Run key for the malware to execute on startup. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFinFisher | FinFisher establishes persistence by creating the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCrossRAT | CrossRAT uses run keys for persistence on Windows. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEvilBunny | EvilBunny has created Registry keys for persistence in |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCobian RAT | Cobian RAT creates an autostart Registry key to ensure persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareServHelper | ServHelper may attempt to establish persistence via the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareJCry | JCry has created payloads in the Startup directory to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareUSBStealer | USBStealer registers itself under a Registry Run key with the name "USB Disk Security." |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTaidoor | Taidoor has modified the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSHIPSHAPE | SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePoisonIvy | PoisonIvy creates run key Registry entries pointing to a malicious executable dropped to disk. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSeasalt | Seasalt creates a Registry entry to ensure infection after reboot under |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNanoCore | NanoCore creates a RunOnce key in the Registry to execute its VBS scripts each time the user logs on to the machine. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLoJax | LoJax has modified the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCardinal RAT | Cardinal RAT establishes Persistence by setting the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePisloader | Pisloader establishes persistence via a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGold Dragon | Gold Dragon establishes persistence in the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRamsay | Ramsay has created Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCarberp | Carberp has maintained persistence by placing itself inside the current user's startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFunnyDream | FunnyDream can use a Registry Run Key and the Startup folder to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareROADSWEEP | ROADSWEEP has been placed in the start up folder to trigger execution upon user login. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSysUpdate | SysUpdate can use a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTinyZBot | TinyZBot can create a shortcut in the Windows startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBoomBox | BoomBox can establish persistence by writing the Registry value |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareInnaputRAT | Some InnaputRAT variants establish persistence by modifying the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGrimAgent | GrimAgent can set persistence with a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLookBack | LookBack sets up a Registry Run key to establish a persistence mechanism. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePoetRAT | PoetRAT has added a registry key in the <RUN> hive for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFELIXROOT | FELIXROOT adds a shortcut file to the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBabyShark | BabyShark has added a Registry key to ensure all future macros are enabled for Microsoft Word and Excel as well as for additional persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
Malwarebuild_downer | build_downer has the ability to add itself to the Registry Run key for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.