Real-world descriptions of how a group, tool or campaign used a technique.
201 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRaspberry Robin | Raspberry Robin will use a Registry key to achieve persistence through reboot, setting a RunOnce key such as: |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMispadu | Mispadu creates a link in the startup folder for persistence. Mispadu adds persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRustyWater | RustyWater has established persistence by adding `C:\ProgramData\CertificationKit.ini` to a Windows startup Registry key or to a Run or RunOnce Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareIcedID | IcedID has established persistence by creating a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMarkiRAT | MarkiRAT can drop its payload into the Startup directory to ensure it automatically runs when the compromised system is started. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePowerShower | PowerShower sets up persistence with a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKazuar | Kazuar adds a sub-key under several Registry run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNavRAT | NavRAT creates a Registry key to ensure a file gets executed upon reboot in order to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDarkComet | DarkComet adds several Registry entries to enable automatic execution at every system startup. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNETEAGLE | The "SCOUT" variant of NETEAGLE achieves persistence by adding itself to the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFatDuke | FatDuke has used |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLucifer | Lucifer can persist by setting Registry key values |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBlackEnergy | The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareShimRat | ShimRat has installed a registry based start-up key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareObliqueRAT | ObliqueRAT can gain persistence by a creating a shortcut in the infected user's Startup directory. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAvaddon | Avaddon uses registry run keys for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareConficker | Conficker adds Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFlagpro | Flagpro has dropped an executable file to the startup directory. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHi-Zor | Hi-Zor creates a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePUNCHBUGGY | PUNCHBUGGY has been observed using a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePteranodon | Pteranodon copies itself to the Startup folder to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDarkTortilla | DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Run` registry key and by creating a .lnk shortcut file in the Windows startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCORESHELL | CORESHELL has established persistence by creating autostart extensibility point (ASEP) Registry entries in the Run key and other Registry keys, as well as by creating shortcuts in the Internet Explorer Quick Start folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRunningRAT | RunningRAT adds itself to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBBSRAT | BBSRAT has been loaded through DLL side-loading of a legitimate Citrix executable that is set to persist through the Registry Run key location |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePlugX | PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareReaver | Reaver creates a shortcut file and saves it in a Startup folder to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBisonal | Bisonal has added itself to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareS-Type | S-Type may create a .lnk file to itself that is saved in the Start menu folder. It may also create the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLumma Stealer | Lumma Stealer has created registry keys to maintain persistence using `HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSeaDuke | SeaDuke is capable of persisting via the Registry Run key or a .lnk file stored in the Startup directory. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDustySky | DustySky achieves persistence by creating a Registry entry in |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTruvasys | Truvasys adds a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSykipot | Sykipot has been known to establish persistence by adding programs to the Run Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareXbash | Xbash can create a Startup item for persistence if it determines it is on a Windows system. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRover | Rover persists by creating a Registry entry in |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareClambling | Clambling can establish persistence by adding a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePureCrypter | PureCrypter can set multiple Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDarkGate | DarkGate installation includes AutoIt script execution creating a shortcut to itself as an LNK object, such as bill.lnk, in the victim startup folder. DarkGate installation finishes with the creation of a registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMongall | Mongall can establish persistence with the auto start function including using the value `EverNoteTrayUService`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNanHaiShu | NanHaiShu modifies the %regrun% Registry to point itself to an autostart mechanism. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCarbanak | Carbanak stores a configuration files in the startup directory to automatically execute commands in order to persist across reboots. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareElise | If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGazer | Gazer can establish persistence by creating a .lnk file in the Start menu. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLatrodectus | Latrodectus can set an AutoRun key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSaint Bot | Saint Bot has established persistence by being copied to the Startup directory or through the `\Software\Microsoft\Windows\CurrentVersion\Run` registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareChaes | Chaes has added persistence via the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLODEINFO | LODEINFO has used Registry run keys to set persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBriba | Briba creates run key Registry entries pointing to malicious DLLs dropped to disk. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMuddyViper | MuddyViper has the ability to establish persistence by configuring its installation directory as a Windows Startup folder by setting the following Registry values to `%APPDATALOCAL%\Microsoft\Windows\PPBCompatCache\ManagerCache`: `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.