Real-world descriptions of how a group, tool or campaign used a technique.
139 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1112 Modify Registry |
MalwareRover | Rover has functionality to remove Registry Run key persistence as a cleanup procedure. |
| T1112 Modify Registry |
MalwareClambling | Clambling can set and delete Registry keys. |
| T1112 Modify Registry |
MalwareLockBit 3.0 | LockBit 3.0 can change the Registry values for Group Policy refresh time, to disable SmartScreen, and to disable Windows Defender. |
| T1112 Modify Registry |
MalwareHydraq | Hydraq creates a Registry subkey to register its created service, and can also uninstall itself later by deleting this value. Hydraq's backdoor also enables remote attackers to modify and delete subkeys. |
| T1112 Modify Registry |
MalwareFerocious | Ferocious has the ability to add a Class ID in the current user Registry hive to enable persistence mechanisms. |
| T1112 Modify Registry |
MalwareCaterpillar WebShell | Caterpillar WebShell has a command to modify a Registry key. |
| T1112 Modify Registry |
MalwareNetwalker | Netwalker can add the following registry entry: |
| T1112 Modify Registry |
MalwareChaes | Chaes can modify Registry values to stored information and establish persistence. |
| T1112 Modify Registry |
MalwareCharmPower | CharmPower can remove persistence-related artifacts from the Registry. |
| T1112 Modify Registry |
MalwareMuddyViper | MuddyViper has the ability to clear the Registry values in the Windows Startup folder that were previously set for persistence. |
| T1112 Modify Registry |
MalwareTYPEFRAME | TYPEFRAME can install encrypted configuration data under the Registry key |
| T1112 Modify Registry |
MalwareEVILNUM | EVILNUM can make modifications to the Regsitry for persistence. |
| T1112 Modify Registry |
MalwareSMOKEDHAM | SMOKEDHAM has modified registry keys for persistence, to enable credential caching for credential access, and to facilitate lateral movement via RDP. |
| T1112 Modify Registry |
MalwareMori | Mori can write data to `HKLM\Software\NFC\IPA` and `HKLM\Software\NFC\` and delete Registry values. |
| T1112 Modify Registry |
MalwareQUADAGENT | QUADAGENT modifies an HKCU Registry key to store a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications. |
| T1112 Modify Registry |
MalwareUroburos | Uroburos can store configuration information in the Registry including the initialization vector and AES key needed to find and decrypt other Uroburos components. |
| T1112 Modify Registry |
MalwareMetamorfo | Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key. |
| T1112 Modify Registry |
MalwareEmbargo | Embargo has modified and deleted Registry keys to add services, and to disable Security Solutions such as Windows Defender. |
| T1112 Modify Registry |
MalwarePipeMon | PipeMon has modified the Registry to store its encrypted payload. |
| T1112 Modify Registry |
MalwareKONNI | KONNI has modified registry keys of ComSysApp, Svchost, and xmlProv on the machine to gain persistence. |
| T1112 Modify Registry |
Malwaregh0st RAT | gh0st RAT has altered the InstallTime subkey. |
| T1112 Modify Registry |
MalwareShamoon | Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting |
| T1112 Modify Registry |
MalwareBlack Basta | Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence. |
| T1112 Modify Registry |
MalwareCatchamas | Catchamas creates three Registry keys to establish persistence by adding a Windows Service. |
| T1112 Modify Registry |
MalwareAttor | Attor's dispatcher can modify the Run registry key. |
| T1112 Modify Registry |
MalwareMegaCortex | MegaCortex has added entries to the Registry for ransom contact information. |
| T1112 Modify Registry |
MalwareStreamEx | StreamEx has the ability to modify the Registry. |
| T1112 Modify Registry |
MalwareNightClub | NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence. |
| T1112 Modify Registry |
MalwareMosquito | Mosquito can modify Registry keys under |
| T1112 Modify Registry |
MalwareRTM | RTM can delete all Registry entries created during its execution. |
| T1112 Modify Registry |
MalwareBlackByte Ransomware | BlackByte Ransomware modifies the victim Registry to prevent system recovery. |
| T1112 Modify Registry |
MalwareGrandoreiro | Grandoreiro can modify the Registry to store its configuration at `HKCU\Software\` under frequently changing names including |
| T1112 Modify Registry |
MalwareSibot | Sibot has modified the Registry to install a second-stage script in the |
| T1112 Modify Registry |
MalwareTarrask | Tarrask is able to delete the Security Descriptor (`SD`) registry subkey in order to “hide” scheduled tasks. |
| T1112 Modify Registry |
MalwareSOUNDBITE | SOUNDBITE is capable of modifying the Registry. |
| T1112 Modify Registry |
MalwareBADCALL | BADCALL modifies the firewall Registry key |
| T1112 Modify Registry |
MalwareHiddenFace | HiddenFace can store its configuration file in the Registry. |
| T1112 Modify Registry |
MalwareHermeticWiper | HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items. |
| T1112 Modify Registry |
MalwarePysa | Pysa has modified the registry key “SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System” and added the ransom note. |
| T1112 Modify Registry |
MalwareKapeka | Kapeka writes persistent configuration information to the victim host registry. |
| T1112 Modify Registry |
MalwareLockBit 2.0 | LockBit 2.0 can create Registry keys to bypass UAC and for persistence. |
| T1112 Modify Registry |
MalwarePandora | Pandora can write an encrypted token to the Registry to enable processing of remote commands. |
| T1112 Modify Registry |
MalwareCobalt Strike | Cobalt Strike can modify Registry values within |
| T1112 Modify Registry |
MalwareSUNBURST | SUNBURST had commands that allow an attacker to write or delete registry keys, and was observed stopping services by setting their |
| T1112 Modify Registry |
MalwareREvil | REvil can modify the Registry to save encryption parameters and system information. |
| T1112 Modify Registry |
MalwareValak | Valak has the ability to modify the Registry key |
| T1112 Modify Registry |
MalwareSamurai | The Samurai loader component can create multiple Registry keys to force the svchost.exe process to load the final backdoor. |
| T1112 Modify Registry |
MalwareTaidoor | Taidoor has the ability to modify the Registry on compromised hosts using |
| T1112 Modify Registry |
MalwarePoisonIvy | PoisonIvy creates a Registry subkey that registers a new system device. |
| T1112 Modify Registry |
MalwareNanoCore | NanoCore has the capability to edit the Registry. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.