Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1112 Modify Registry |
GroupBlue Mockingbird | Blue Mockingbird has used Windows Registry modifications to specify a DLL payload. |
| T1112 Modify Registry |
GroupTurla | Turla has modified Registry values to store payloads. |
| T1112 Modify Registry |
GroupTA505 | TA505 has used malware to disable Windows Defender through modification of the Registry. |
| T1112 Modify Registry |
GroupLotus Blossom | Lotus Blossom has installed tools such as Sagerunex by writing them to the Windows registry. |
| T1112 Modify Registry |
GroupMedusa Group | Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access. |
| T1112 Modify Registry |
GroupEmber Bear | Ember Bear modifies registry values for anti-forensics and defense evasion purposes. |
| T1112 Modify Registry |
GroupLuminousMoth | LuminousMoth has used malware that adds Registry keys for persistence. |
| T1112 Modify Registry |
GroupAPT42 | APT42 has modified Registry keys to maintain persistence. |
| T1112 Modify Registry |
GroupEarth Lusca | Earth Lusca modified the registry using the command |
| T1112 Modify Registry |
GroupSilence | Silence can create, delete, or modify a specified Registry key or value. |
| T1112 Modify Registry |
GroupWizard Spider | Wizard Spider has modified the Registry key |
| T1112 Modify Registry |
GroupMagic Hound | Magic Hound has modified Registry settings for security tools. |
| T1112 Modify Registry |
GroupThreat Group-3390 | A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`. |
| T1112 Modify Registry |
GroupFIN8 | FIN8 has deleted Registry keys during post compromise cleanup activities. |
| T1112 Modify Registry |
GroupAPT19 | APT19 uses a Port 22 malware variant to modify several Registry keys. |
| T1112 Modify Registry |
MalwareTrickBot | TrickBot can modify registry entries. |
| T1112 Modify Registry |
MalwareRCSession | RCSession can write its configuration file to the Registry. |
| T1112 Modify Registry |
MalwareSynAck | SynAck can manipulate Registry keys. |
| T1112 Modify Registry |
MalwareExaramel for Windows | Exaramel for Windows adds the configuration to the Registry in XML format. |
| T1112 Modify Registry |
MalwareAmadey | Amadey has overwritten registry keys for persistence. |
| T1112 Modify Registry |
MalwareOrz | Orz can perform Registry operations. |
| T1112 Modify Registry |
MalwareStuxnet | Stuxnet can create registry keys to load driver files. |
| T1112 Modify Registry |
MalwareKEYMARBLE | KEYMARBLE has a command to create Registry entries for storing data under |
| T1112 Modify Registry |
MalwareUrsnif | Ursnif has used Registry modifications as part of its installation routine. |
| T1112 Modify Registry |
MalwareThreatNeedle | ThreatNeedle can modify the Registry to save its configuration data as the following RC4-encrypted Registry key: `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`. |
| T1112 Modify Registry |
MalwareZeus Panda | Zeus Panda modifies several Registry keys under |
| T1112 Modify Registry |
MalwarePrestige | Prestige has the ability to register new registry keys for a new extension handler via `HKCR\.enc` and `HKCR\enc\shell\open\command`. |
| T1112 Modify Registry |
MalwareBankshot | Bankshot writes data into the Registry key |
| T1112 Modify Registry |
MalwarePLAINTEE | PLAINTEE uses |
| T1112 Modify Registry |
MalwareNETWIRE | NETWIRE can modify the Registry to store its configuration information. |
| T1112 Modify Registry |
MalwareTinyTurla | TinyTurla can set its configuration parameters in the Registry. |
| T1112 Modify Registry |
MalwareBOOKWORM | BOOKWORM has modified Registry key values as part of its created service `DeviceSync`. |
| T1112 Modify Registry |
MalwareHyperStack | HyperStack can add the name of its communication pipe to |
| T1112 Modify Registry |
MalwareGreyEnergy | GreyEnergy modifies conditions in the Registry and adds keys. |
| T1112 Modify Registry |
MalwareCrimson | Crimson can set a Registry key to determine how long it has been installed and possibly to indicate the version number. |
| T1112 Modify Registry |
MalwareTEARDROP | TEARDROP modified the Registry to create a Windows service for itself on a compromised host. |
| T1112 Modify Registry |
MalwareMafalda | Mafalda can manipulate the system registry on a compromised host. |
| T1112 Modify Registry |
MalwarePolyglotDuke | PolyglotDuke can write encrypted JSON configuration files to the Registry. |
| T1112 Modify Registry |
MalwareShrinkLocker | ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption. |
| T1112 Modify Registry |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware modifies the victim Registry to allow for elevated execution. |
| T1112 Modify Registry |
MalwareHOPLIGHT | HOPLIGHT has modified Managed Object Format (MOF) files within the Registry to run specific commands and create persistence on the system. |
| T1112 Modify Registry |
MalwareWastedLocker | WastedLocker can modify registry values within the |
| T1112 Modify Registry |
MalwareRegDuke | RegDuke can create seemingly legitimate Registry key to store its encryption key. |
| T1112 Modify Registry |
MalwareInvisiMole | InvisiMole has a command to create, set, copy, or delete a specified Registry key or value. |
| T1112 Modify Registry |
MalwareNaid | Naid creates Registry entries that store information about a created service and point to a malicious DLL dropped to disk. |
| T1112 Modify Registry |
MalwareVolgmer | Volgmer modifies the Registry to store an encoded configuration file in |
| T1112 Modify Registry |
MalwareTRANSLATEXT | TRANSLATEXT has modified the following registry key to install itself as the value, granting permission to install specified extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist`. |
| T1112 Modify Registry |
MalwareRegin | Regin appears to have functionality to modify remote Registry information. |
| T1112 Modify Registry |
MalwareNeoichor | Neoichor has the ability to configure browser settings by modifying Registry entries under `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer`. |
| T1112 Modify Registry |
MalwareBlackCat | BlackCat has the ability to add the following registry key on compromised networks to maintain persistence: `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services \LanmanServer\Paramenters` |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.