ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1547.001×

201 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
MalwareRaspberry Robin

Raspberry Robin will use a Registry key to achieve persistence through reboot, setting a RunOnce key such as: HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce
{random value name} = “rundll32 shell32 ShellExec_RunDLLA REGSVR /u /s “{dropped copy path and file name}””
.

T1547.001
Registry Run Keys / Startup Folder
MalwareMispadu

Mispadu creates a link in the startup folder for persistence. Mispadu adds persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareRustyWater

RustyWater has established persistence by adding `C:\ProgramData\CertificationKit.ini` to a Windows startup Registry key or to a Run or RunOnce Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareIcedID

IcedID has established persistence by creating a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareMarkiRAT

MarkiRAT can drop its payload into the Startup directory to ensure it automatically runs when the compromised system is started.

T1547.001
Registry Run Keys / Startup Folder
MalwarePowerShower

PowerShower sets up persistence with a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareKazuar

Kazuar adds a sub-key under several Registry run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareNavRAT

NavRAT creates a Registry key to ensure a file gets executed upon reboot in order to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkComet

DarkComet adds several Registry entries to enable automatic execution at every system startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETEAGLE

The "SCOUT" variant of NETEAGLE achieves persistence by adding itself to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareFatDuke

FatDuke has used HKLM\SOFTWARE\Microsoft\CurrentVersion\Run to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareLucifer

Lucifer can persist by setting Registry key values HKLM\Software\Microsoft\Windows\CurrentVersion\Run\QQMusic and HKCU\Software\Microsoft\Windows\CurrentVersion\Run\QQMusic.

T1547.001
Registry Run Keys / Startup Folder
MalwareBlackEnergy

The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareShimRat

ShimRat has installed a registry based start-up key HKCU\Software\microsoft\windows\CurrentVersion\Run to maintain persistence should other methods fail.

T1547.001
Registry Run Keys / Startup Folder
MalwareObliqueRAT

ObliqueRAT can gain persistence by a creating a shortcut in the infected user's Startup directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareAvaddon

Avaddon uses registry run keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareConficker

Conficker adds Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareFlagpro

Flagpro has dropped an executable file to the startup directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareHi-Zor

Hi-Zor creates a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePUNCHBUGGY

PUNCHBUGGY has been observed using a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwarePteranodon

Pteranodon copies itself to the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkTortilla

DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Run` registry key and by creating a .lnk shortcut file in the Windows startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareCORESHELL

CORESHELL has established persistence by creating autostart extensibility point (ASEP) Registry entries in the Run key and other Registry keys, as well as by creating shortcuts in the Internet Explorer Quick Start folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareRunningRAT

RunningRAT adds itself to the Registry key Software\Microsoft\Windows\CurrentVersion\Run to establish persistence upon reboot.

T1547.001
Registry Run Keys / Startup Folder
MalwareBBSRAT

BBSRAT has been loaded through DLL side-loading of a legitimate Citrix executable that is set to persist through the Registry Run key location HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ssonsvr.exe.

T1547.001
Registry Run Keys / Startup Folder
MalwarePlugX

PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareReaver

Reaver creates a shortcut file and saves it in a Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBisonal

Bisonal has added itself to the Registry key HKEY_CURRENT_USER\Software\Microsoft\CurrentVersion\Run\ for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareS-Type

S-Type may create a .lnk file to itself that is saved in the Start menu folder. It may also create the Registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ IMJPMIJ8.1{3 characters of Unique Identifier}.

T1547.001
Registry Run Keys / Startup Folder
MalwareLumma Stealer

Lumma Stealer has created registry keys to maintain persistence using `HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareSeaDuke

SeaDuke is capable of persisting via the Registry Run key or a .lnk file stored in the Startup directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareDustySky

DustySky achieves persistence by creating a Registry entry in HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareTruvasys

Truvasys adds a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSykipot

Sykipot has been known to establish persistence by adding programs to the Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareXbash

Xbash can create a Startup item for persistence if it determines it is on a Windows system.

T1547.001
Registry Run Keys / Startup Folder
MalwareRover

Rover persists by creating a Registry entry in HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\.

T1547.001
Registry Run Keys / Startup Folder
MalwareClambling

Clambling can establish persistence by adding a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwarePureCrypter

PureCrypter can set multiple Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkGate

DarkGate installation includes AutoIt script execution creating a shortcut to itself as an LNK object, such as bill.lnk, in the victim startup folder. DarkGate installation finishes with the creation of a registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareMongall

Mongall can establish persistence with the auto start function including using the value `EverNoteTrayUService`.

T1547.001
Registry Run Keys / Startup Folder
MalwareNanHaiShu

NanHaiShu modifies the %regrun% Registry to point itself to an autostart mechanism.

T1547.001
Registry Run Keys / Startup Folder
MalwareCarbanak

Carbanak stores a configuration files in the startup directory to automatically execute commands in order to persist across reboots.

T1547.001
Registry Run Keys / Startup Folder
MalwareElise

If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svchost : %APPDATA%\Microsoft\Network\svchost.exe. Other variants have set the following Registry keys for persistence: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\imejp : [self] and HKCU\Software\Microsoft\Windows\CurrentVersion\Run\IAStorD.

T1547.001
Registry Run Keys / Startup Folder
MalwareGazer

Gazer can establish persistence by creating a .lnk file in the Start menu.

T1547.001
Registry Run Keys / Startup Folder
MalwareLatrodectus

Latrodectus can set an AutoRun key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSaint Bot

Saint Bot has established persistence by being copied to the Startup directory or through the `\Software\Microsoft\Windows\CurrentVersion\Run` registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareChaes

Chaes has added persistence via the Registry key software\microsoft\windows\currentversion\run\microsoft windows html help.

T1547.001
Registry Run Keys / Startup Folder
MalwareLODEINFO

LODEINFO has used Registry run keys to set persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBriba

Briba creates run key Registry entries pointing to malicious DLLs dropped to disk.

T1547.001
Registry Run Keys / Startup Folder
MalwareMuddyViper

MuddyViper has the ability to establish persistence by configuring its installation directory as a Windows Startup folder by setting the following Registry values to `%APPDATALOCAL%\Microsoft\Windows\PPBCompatCache\ManagerCache`:  `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.