Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1543.001 Launch Agent |
MalwareThiefQuest | ThiefQuest installs a launch item using an embedded encrypted launch agent property list template. The plist file is installed in the |
| T1543.001 Launch Agent |
MalwareBundlore | Bundlore can persist via a LaunchAgent. |
| T1543.001 Launch Agent |
MalwareGlassWorm | GlassWorm has established persistence on macOS via a LaunchAgent by writing a plist under `/library/LaunchAgents`. |
| T1543.001 Launch Agent |
MalwareCrossRAT | CrossRAT creates a Launch Agent on macOS. |
| T1543.001 Launch Agent |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can create a persistence file in the folder |
| T1543.001 Launch Agent |
MalwareCalisto | Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence. |
| T1543.001 Launch Agent |
MalwareMacMa | MacMa installs a `com.apple.softwareupdate.plist` file in the `/LaunchAgents` folder with the `RunAtLoad` value set to `true`. Upon user login, MacMa is executed from `/var/root/.local/softwareupdate` with root privileges. Some variations also include the `LimitLoadToSessionType` key with the value `Aqua`, ensuring the MacMa only runs when there is a logged in GUI user. |
| T1543.001 Launch Agent |
MalwareProton | Proton persists via Launch Agent. |
| T1543.001 Launch Agent |
MalwareCoinTicker | CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence. |
| T1543.001 Launch Agent |
MalwareCookieMiner | CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software. |
| T1543.001 Launch Agent |
MalwareKomplex | The Komplex trojan creates a persistent launch agent called with |
| T1543.001 Launch Agent |
MalwareDok | Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format |
| T1543.001 Launch Agent |
MalwareMacSpy | MacSpy persists via a Launch Agent. |
| T1543.001 Launch Agent |
MalwareMini Shai-Hulud | Mini Shai-Hulud has established persistence on macOS hosts by installing a gh-token-monitor daemon through LaunchAgent that polls GitHub every 60 seconds. |
| T1543.002 Systemd Service |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team configured Systemd to maintain persistence of GOGETTER, specifying the `WantedBy=multi-user.target` configuration to run GOGETTER when the system begins accepting user logins. |
| T1543.002 Systemd Service |
GroupTeamTNT | TeamTNT has established persistence through the creation of a cryptocurrency mining system service using |
| T1543.002 Systemd Service |
GroupRocke | Rocke has installed a systemd service script to maintain persistence. |
| T1543.002 Systemd Service |
GroupScattered Spider | Scattered Spider has run `SYSTEMD_UNIT_PATH="/lib/systemd/ |
| T1543.002 Systemd Service |
MalwareRotaJakiro | Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.service` file under the `/lib/systemd/system/` folder. |
| T1543.002 Systemd Service |
MalwareExaramel for Linux | Exaramel for Linux has a hardcoded location under systemd that it uses to achieve persistence if it is running as root. |
| T1543.002 Systemd Service |
MalwareGomir | Gomir creates a systemd service named `syslogd` for persistence. |
| T1543.002 Systemd Service |
MalwareHildegard | Hildegard has started a monero service. |
| T1543.002 Systemd Service |
MalwareFysbis | Fysbis has established persistence using a systemd service. |
| T1543.002 Systemd Service |
MalwareSysUpdate | SysUpdate can copy a script to the user owned `/usr/lib/systemd/system/` directory with a symlink mapped to a `root` owned directory, `/etc/ystem/system`, in the unit configuration file's `ExecStart` directive to establish persistence and elevate privileges. |
| T1543.002 Systemd Service |
MalwareRIFLESPINE | RIFLESPINE can create a systemd service file for execution. |
| T1543.002 Systemd Service |
MalwareShai-Hulud | Shai-Hulud has stopped `systemd-resolved` in order to manipulate DNS and firewalls. |
| T1543.002 Systemd Service |
ToolPupy | Pupy can be used to establish persistence using a systemd service. |
| T1543.002 Systemd Service |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a systemd unit to execute a python script for persistence. |
| T1543.002 Systemd Service |
MalwareMini Shai-Hulud | Mini Shai-Hulud has created .service files using Systemd on victim Linux hosts to establish persistence. |
| T1543.002 Systemd Service |
GroupTeamPCP | TeamPCP has used the systemd user service for malware persistence in targeted environments. |
| T1543.003 Windows Service |
CampaignOperation Honeybee | During Operation Honeybee, threat actors installed DLLs and backdoors as Windows services. |
| T1543.003 Windows Service |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors created a service named Visual Studio Code Service to run Visual Studio code. |
| T1543.003 Windows Service |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors modified the `IKEEXT` and `PrintNotify` Windows services for persistence. |
| T1543.003 Windows Service |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary. |
| T1543.003 Windows Service |
CampaignAPT41 DUST | APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN. |
| T1543.003 Windows Service |
GroupAPT38 | APT38 has installed a new Windows service to establish persistence. |
| T1543.003 Windows Service |
GroupBlackByte | BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines. |
| T1543.003 Windows Service |
GroupAPT3 | APT3 has a tool that creates a new service for persistence. |
| T1543.003 Windows Service |
GroupKimsuky | Kimsuky has created new services for persistence. |
| T1543.003 Windows Service |
GroupAPT41 | APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike. |
| T1543.003 Windows Service |
GroupAPT32 | APT32 modified Windows Services to ensure PowerShell scripts were loaded on the system. APT32 also creates a Windows service to establish persistence. |
| T1543.003 Windows Service |
GroupTeamTNT | TeamTNT has used malware that adds cryptocurrency miners as a service. |
| T1543.003 Windows Service |
GroupFIN7 | FIN7 created new Windows services and added them to the startup directories for persistence. |
| T1543.003 Windows Service |
GroupOilRig | OilRig has used a compromised Domain Controller to create a service on a remote host. |
| T1543.003 Windows Service |
GroupCarbanak | Carbanak malware installs itself as a service to provide persistence and SYSTEM privileges. |
| T1543.003 Windows Service |
GroupTropic Trooper | Tropic Trooper has installed a service pointing to a malicious DLL dropped to disk. |
| T1543.003 Windows Service |
GroupAquatic Panda | Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change. |
| T1543.003 Windows Service |
GroupKe3chang | Ke3chang backdoor RoyalDNS established persistence through adding a service called |
| T1543.003 Windows Service |
GroupBlue Mockingbird | Blue Mockingbird has made their XMRIG payloads persistent as a Windows Service. |
| T1543.003 Windows Service |
GroupDarkVishnya | DarkVishnya created new services for shellcode loaders distribution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.