ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1112×

139 examples

TechniqueUsed byProcedure example
T1112
Modify Registry
MalwareRover

Rover has functionality to remove Registry Run key persistence as a cleanup procedure.

T1112
Modify Registry
MalwareClambling

Clambling can set and delete Registry keys.

T1112
Modify Registry
MalwareLockBit 3.0

LockBit 3.0 can change the Registry values for Group Policy refresh time, to disable SmartScreen, and to disable Windows Defender.

T1112
Modify Registry
MalwareHydraq

Hydraq creates a Registry subkey to register its created service, and can also uninstall itself later by deleting this value. Hydraq's backdoor also enables remote attackers to modify and delete subkeys.

T1112
Modify Registry
MalwareFerocious

Ferocious has the ability to add a Class ID in the current user Registry hive to enable persistence mechanisms.

T1112
Modify Registry
MalwareCaterpillar WebShell

Caterpillar WebShell has a command to modify a Registry key.

T1112
Modify Registry
MalwareNetwalker

Netwalker can add the following registry entry: HKEY_CURRENT_USER\SOFTWARE\{8 random characters}.

T1112
Modify Registry
MalwareChaes

Chaes can modify Registry values to stored information and establish persistence.

T1112
Modify Registry
MalwareCharmPower

CharmPower can remove persistence-related artifacts from the Registry.

T1112
Modify Registry
MalwareMuddyViper

MuddyViper has the ability to clear the Registry values in the Windows Startup folder that were previously set for persistence.

T1112
Modify Registry
MalwareTYPEFRAME

TYPEFRAME can install encrypted configuration data under the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\laxhost.dll and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PrintConfigs.

T1112
Modify Registry
MalwareEVILNUM

EVILNUM can make modifications to the Regsitry for persistence.

T1112
Modify Registry
MalwareSMOKEDHAM

SMOKEDHAM has modified registry keys for persistence, to enable credential caching for credential access, and to facilitate lateral movement via RDP.

T1112
Modify Registry
MalwareMori

Mori can write data to `HKLM\Software\NFC\IPA` and `HKLM\Software\NFC\` and delete Registry values.

T1112
Modify Registry
MalwareQUADAGENT

QUADAGENT modifies an HKCU Registry key to store a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications.

T1112
Modify Registry
MalwareUroburos

Uroburos can store configuration information in the Registry including the initialization vector and AES key needed to find and decrypt other Uroburos components.

T1112
Modify Registry
MalwareMetamorfo

Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key.

T1112
Modify Registry
MalwareEmbargo

Embargo has modified and deleted Registry keys to add services, and to disable Security Solutions such as Windows Defender.

T1112
Modify Registry
MalwarePipeMon

PipeMon has modified the Registry to store its encrypted payload.

T1112
Modify Registry
MalwareKONNI

KONNI has modified registry keys of ComSysApp, Svchost, and xmlProv on the machine to gain persistence.

T1112
Modify Registry
Malwaregh0st RAT

gh0st RAT has altered the InstallTime subkey.

T1112
Modify Registry
MalwareShamoon

Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy to 1.

T1112
Modify Registry
MalwareBlack Basta

Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence.

T1112
Modify Registry
MalwareCatchamas

Catchamas creates three Registry keys to establish persistence by adding a Windows Service.

T1112
Modify Registry
MalwareAttor

Attor's dispatcher can modify the Run registry key.

T1112
Modify Registry
MalwareMegaCortex

MegaCortex has added entries to the Registry for ransom contact information.

T1112
Modify Registry
MalwareStreamEx

StreamEx has the ability to modify the Registry.

T1112
Modify Registry
MalwareNightClub

NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence.

T1112
Modify Registry
MalwareMosquito

Mosquito can modify Registry keys under HKCU\Software\Microsoft\[dllname] to store configuration values. Mosquito also modifies Registry keys under HKCR\CLSID\...\InprocServer32 with a path to the launcher.

T1112
Modify Registry
MalwareRTM

RTM can delete all Registry entries created during its execution.

T1112
Modify Registry
MalwareBlackByte Ransomware

BlackByte Ransomware modifies the victim Registry to prevent system recovery.

T1112
Modify Registry
MalwareGrandoreiro

Grandoreiro can modify the Registry to store its configuration at `HKCU\Software\` under frequently changing names including %USERNAME% and ToolTech-RM.

T1112
Modify Registry
MalwareSibot

Sibot has modified the Registry to install a second-stage script in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot.

T1112
Modify Registry
MalwareTarrask

Tarrask is able to delete the Security Descriptor (`SD`) registry subkey in order to “hide” scheduled tasks.

T1112
Modify Registry
MalwareSOUNDBITE

SOUNDBITE is capable of modifying the Registry.

T1112
Modify Registry
MalwareBADCALL

BADCALL modifies the firewall Registry key SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfileGloballyOpenPorts\\List.

T1112
Modify Registry
MalwareHiddenFace

HiddenFace can store its configuration file in the Registry.

T1112
Modify Registry
MalwareHermeticWiper

HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items.

T1112
Modify Registry
MalwarePysa

Pysa has modified the registry key “SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System” and added the ransom note.

T1112
Modify Registry
MalwareKapeka

Kapeka writes persistent configuration information to the victim host registry.

T1112
Modify Registry
MalwareLockBit 2.0

LockBit 2.0 can create Registry keys to bypass UAC and for persistence.

T1112
Modify Registry
MalwarePandora

Pandora can write an encrypted token to the Registry to enable processing of remote commands.

T1112
Modify Registry
MalwareCobalt Strike

Cobalt Strike can modify Registry values within HKEY_CURRENT_USER\Software\Microsoft\Office\<Excel Version>\Excel\Security\AccessVBOM\ to enable the execution of additional code.

T1112
Modify Registry
MalwareSUNBURST

SUNBURST had commands that allow an attacker to write or delete registry keys, and was observed stopping services by setting their HKLM\SYSTEM\CurrentControlSet\services\\[service_name]\\Start registry entries to value 4. It also deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.

T1112
Modify Registry
MalwareREvil

REvil can modify the Registry to save encryption parameters and system information.

T1112
Modify Registry
MalwareValak

Valak has the ability to modify the Registry key HKCU\Software\ApplicationContainer\Appsw64 to store information regarding the C2 server and downloads.

T1112
Modify Registry
MalwareSamurai

The Samurai loader component can create multiple Registry keys to force the svchost.exe process to load the final backdoor.

T1112
Modify Registry
MalwareTaidoor

Taidoor has the ability to modify the Registry on compromised hosts using RegDeleteValueA and RegCreateKeyExA.

T1112
Modify Registry
MalwarePoisonIvy

PoisonIvy creates a Registry subkey that registers a new system device.

T1112
Modify Registry
MalwareNanoCore

NanoCore has the capability to edit the Registry.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.