Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.005 Scheduled Task |
GroupMuddyWater | MuddyWater has used scheduled tasks to establish persistence. |
| T1053.005 Scheduled Task |
GroupNaikon | Naikon has used schtasks.exe for lateral movement in compromised networks. |
| T1053.005 Scheduled Task |
GroupFIN6 | FIN6 has used scheduled tasks to establish persistence for various malware it uses, including downloaders known as HARDTACK and SHIPBREAD and FrameworkPOS. |
| T1053.005 Scheduled Task |
GroupGamaredon Group | Gamaredon Group has created scheduled tasks to launch executables after a designated number of minutes have passed. |
| T1053.005 Scheduled Task |
GroupFIN7 | FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence. |
| T1053.005 Scheduled Task |
GroupSandworm Team | Sandworm Team leveraged SHARPIVORY, a .NET dropper that writes embedded payload to disk and uses scheduled tasks to persist on victim machines. |
| T1053.005 Scheduled Task |
GroupMachete | Machete has created scheduled tasks to maintain Machete's persistence. |
| T1053.005 Scheduled Task |
GroupMustang Panda | Mustang Panda has created a scheduled task to execute additional malicious software, as well as maintain persistence. Mustang Panda has also created a scheduled task that creates a reverse shell. |
| T1053.005 Scheduled Task |
GroupAPT39 | APT39 has created scheduled tasks for persistence. |
| T1053.005 Scheduled Task |
GroupTA2541 | TA2541 has used scheduled tasks to establish persistence for installed tools. |
| T1053.005 Scheduled Task |
GroupAPT37 | APT37 has created scheduled tasks to run malicious scripts on a compromised host. |
| T1053.005 Scheduled Task |
GroupOilRig | OilRig has created scheduled tasks that run a VBScript to execute a payload on victim machines. |
| T1053.005 Scheduled Task |
GroupHigaisa | Higaisa dropped and added |
| T1053.005 Scheduled Task |
GroupConfucius | Confucius has created scheduled tasks to maintain persistence on a compromised host. |
| T1053.005 Scheduled Task |
GroupBlue Mockingbird | Blue Mockingbird has used Windows Scheduled Tasks to establish persistence on local and remote hosts. |
| T1053.005 Scheduled Task |
GroupWinter Vivern | Winter Vivern executed PowerShell scripts that would subsequently attempt to establish persistence by creating scheduled tasks objects to periodically retrieve and execute remotely-hosted payloads. |
| T1053.005 Scheduled Task |
GroupStorm-0501 | Storm-0501 had used a scheduled task named “SysUpdate” that was registered via GPO on devices in the network to distribute the Embargo ransomware. |
| T1053.005 Scheduled Task |
GroupBITTER | BITTER has used scheduled tasks for persistence and execution. |
| T1053.005 Scheduled Task |
GroupRedCurl | RedCurl has created scheduled tasks for persistence. |
| T1053.005 Scheduled Task |
GroupStealth Falcon | Stealth Falcon malware creates a scheduled task entitled “IE Web Cache” to execute a malicious file hourly. |
| T1053.005 Scheduled Task |
GroupAPT29 | APT29 has used named and hijacked scheduled tasks to establish persistence. |
| T1053.005 Scheduled Task |
GroupChimera | Chimera has used scheduled tasks to invoke Cobalt Strike including through batch script |
| T1053.005 Scheduled Task |
GroupBRONZE BUTLER | BRONZE BUTLER has used schtasks to register a scheduled task to execute malware during lateral movement. |
| T1053.005 Scheduled Task |
GroupEmber Bear | Ember Bear uses remotely scheduled tasks to facilitate remote command execution on victim machines. |
| T1053.005 Scheduled Task |
GroupToddyCat | ToddyCat has used scheduled tasks to execute discovery commands and scripts for collection. |
| T1053.005 Scheduled Task |
GroupLuminousMoth | LuminousMoth has created scheduled tasks to establish persistence for their tools. |
| T1053.005 Scheduled Task |
GroupAPT42 | APT42 has used scheduled tasks for persistence. |
| T1053.005 Scheduled Task |
GroupFox Kitten | Fox Kitten has used Scheduled Tasks for persistence and to load and execute a reverse proxy binary. |
| T1053.005 Scheduled Task |
GroupAPT-C-36 | APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google. |
| T1053.005 Scheduled Task |
GroupLazarus Group | Lazarus Group has used |
| T1053.005 Scheduled Task |
GroupEarth Lusca | Earth Lusca used the command |
| T1053.005 Scheduled Task |
GroupSilence | Silence has used scheduled tasks to stage its operation. |
| T1053.005 Scheduled Task |
GroupCobalt Group | Cobalt Group has created Windows tasks to establish persistence. |
| T1053.005 Scheduled Task |
GroupWizard Spider | Wizard Spider has used scheduled tasks to establish persistence for TrickBot and other malware. |
| T1053.005 Scheduled Task |
GroupMolerats | Molerats has created scheduled tasks to persistently run VBScripts. |
| T1053.005 Scheduled Task |
GroupMoonstone Sleet | Moonstone Sleet used scheduled tasks for program execution during initial access to victim machines. |
| T1053.005 Scheduled Task |
GroupHEXANE | HEXANE has used a scheduled task to establish persistence for a keylogger. |
| T1053.005 Scheduled Task |
GroupDaggerfly | Daggerfly has attempted to use scheduled tasks for persistence in victim environments. |
| T1053.005 Scheduled Task |
GroupRancor | Rancor launched a scheduled task to gain persistence using the |
| T1053.005 Scheduled Task |
GroupMagic Hound | Magic Hound has used scheduled tasks to establish persistence and execution. |
| T1053.005 Scheduled Task |
GroupAPT33 | APT33 has created a scheduled task to execute a .vbe file multiple times a day. |
| T1053.005 Scheduled Task |
GroupFIN10 | FIN10 has established persistence by using S4U tasks as well as the Scheduled Task option in PowerShell Empire. |
| T1053.005 Scheduled Task |
GroupFIN8 | FIN8 has used scheduled tasks to maintain RDP backdoors. |
| T1053.005 Scheduled Task |
GroupFIN13 | FIN13 has created scheduled tasks in the `C:\Windows` directory of the compromised network. |
| T1055 Process Injection |
GroupAPT38 | APT38 has injected malicious payloads into the `explorer.exe` process. |
| T1055 Process Injection |
GroupBlackByte | BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption. |
| T1055 Process Injection |
GroupKimsuky | Kimsuky has used Win7Elevate to inject malicious code into explorer.exe. |
| T1055 Process Injection |
GroupAPT41 | APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process. |
| T1055 Process Injection |
GroupAPT32 | APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe. |
| T1055 Process Injection |
GroupGamaredon Group | Gamaredon Group has injected Remcos into explorer.exe. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.