Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1543.003 Windows Service |
MalwareInnaputRAT | Some InnaputRAT variants create a new Windows service to establish persistence. |
| T1543.003 Windows Service |
MalwareZxShell | ZxShell can create a new service using the service parser function ProcessScCommand. |
| T1543.003 Windows Service |
MalwareWinnti for Windows | Winnti for Windows sets its DLL file as a new service in the Registry to establish persistence. |
| T1543.003 Windows Service |
MalwareAppleJeus | AppleJeus can install itself as a service. |
| T1543.003 Windows Service |
MalwareSTARWHALE | STARWHALE has the ability to create the following Windows service to establish persistence on an infected host: `sc create Windowscarpstss binpath= "cmd.exe /c cscript.exe c:\\windows\\system32\\w7_1.wsf humpback_whale" start= "auto" obj= "LocalSystem"`. |
| T1543.003 Windows Service |
MalwareIndustroyer | Industroyer can use an arbitrary system service to load at system boot for persistence and replaces the ImagePath registry value of a Windows service with a new backdoor binary. |
| T1543.003 Windows Service |
MalwareCozyCar | One persistence mechanism used by CozyCar is to register itself as a Windows service. |
| T1543.003 Windows Service |
MalwareQakBot | QakBot can remotely create a temporary service on a target host. |
| T1543.003 Windows Service |
MalwareGelsemium | Gelsemium can drop itself in `C:\Windows\System32\spool\prtprocs\x64\winprint.dll` as an alternative Print Processor to be loaded automatically when the spoolsv Windows service starts. |
| T1543.003 Windows Service |
MalwareDtrack | Dtrack can add a service called WBService to establish persistence. |
| T1543.003 Windows Service |
MalwareLoudMiner | LoudMiner can automatically launch a Linux virtual machine as a service at startup if the AutoStart option is enabled in the VBoxVmService configuration file. |
| T1543.003 Windows Service |
MalwareBitPaymer | BitPaymer has attempted to install itself as a service to maintain persistence. |
| T1543.003 Windows Service |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has created a service on victim machines named "TaskFrame" to establish persistence. |
| T1543.003 Windows Service |
MalwareFALLCHILL | FALLCHILL has been installed as a Windows service. |
| T1543.003 Windows Service |
ToolSILENTTRINITY | SILENTTRINITY can establish persistence by creating a new service. |
| T1543.003 Windows Service |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and replace/modify service binaries, paths, and configs. |
| T1543.003 Windows Service |
ToolEmpire | Empire can utilize built-in modules to modify service binaries and restore them to their original state. |
| T1543.003 Windows Service |
ToolRemcos | Remcos can terminate, suspend, and resume a process by PID. |
| T1543.003 Windows Service |
ToolPsExec | PsExec can leverage Windows services to escalate privileges from administrator to SYSTEM with the |
| T1543.003 Windows Service |
MalwareDuqu | Duqu creates a new service that loads a malicious driver when the system starts. When Duqu is active, the operating system believes that the driver is legitimate, as it has been signed with a valid private key. |
| T1543.004 Launch Daemon |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus installs a Launch Daemon to execute the POOLRAT macOS backdoor software. |
| T1543.004 Launch Daemon |
MalwareCOATHANGER | COATHANGER will create a daemon for timed check-ins with command and control infrastructure. |
| T1543.004 Launch Daemon |
MalwareDacls | Dacls can establish persistence via a Launch Daemon. |
| T1543.004 Launch Daemon |
MalwareREPTILE | The REPTILE launcher can daemonize a process. |
| T1543.004 Launch Daemon |
MalwareGreen Lambert | Green Lambert can add a plist file in the `Library/LaunchDaemons` to establish persistence. |
| T1543.004 Launch Daemon |
MalwareThiefQuest | When running with root privileges after a Launch Agent is installed, ThiefQuest installs a plist file to the |
| T1543.004 Launch Daemon |
MalwareBundlore | Bundlore can persist via a LaunchDaemon. |
| T1543.004 Launch Daemon |
MalwareOSX_OCEANLOTUS.D | If running with |
| T1543.004 Launch Daemon |
MalwareXCSSET | XCSSET uses the ssh launchdaemon to elevate privileges, bypass system controls, and enable remote access to the victim. |
| T1543.004 Launch Daemon |
MalwareAppleJeus | AppleJeus has placed a plist file within the |
| T1543.004 Launch Daemon |
MalwareLoudMiner | LoudMiner adds plist files with the naming format |
| T1546 Event Triggered Execution |
CampaignKV Botnet Activity | KV Botnet Activity involves managing events on victim systems via |
| T1546 Event Triggered Execution |
MalwareUPSTYLE | UPSTYLE creates a `.pth` file beginning with the text `import` so that any time another process or script attempts to reference the modified item the malicious code will also run. |
| T1546 Event Triggered Execution |
MalwareXCSSET | XCSSET's `dfhsebxzod` module searches for `.xcodeproj` directories within the user’s home folder and subdirectories. For each match, it locates the corresponding `project.pbxproj` file and embeds an encoded payload into a build rule, target configuration, or project setting. The payload is later executed during the build process. |
| T1546 Event Triggered Execution |
ToolPacu | Pacu can set up S3 bucket notifications to trigger a malicious Lambda function when a CloudFormation template is uploaded to the bucket. It can also create Lambda functions that trigger upon the creation of users, roles, and groups. |
| T1546 Event Triggered Execution |
MalwareMini Shai-Hulud | Mini Shai-Hulud has modified settings and configuration files of AI coding agents and other coding applications in order to create event triggered executions through creating hooks and runOn conditions. |
| T1546.001 Change Default File Association |
GroupKimsuky | Kimsuky has a HWP document stealer module which changes the default program association in the registry to open HWP documents. |
| T1546.001 Change Default File Association |
ToolSILENTTRINITY | SILENTTRINITY can conduct an image hijack of an `.msc` file extension as part of its UAC bypass process. |
| T1546.002 Screensaver |
MalwareGazer | Gazer can establish persistence through the system screensaver by configuring it to execute the malware. |
| T1546.003 Windows Management Instrumentation Event Subscription |
CampaignOperation Ghost | During Operation Ghost, APT29 used WMI event subscriptions to establish persistence for malware. |
| T1546.003 Windows Management Instrumentation Event Subscription |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used a WMI event filter to invoke a command-line event consumer at system boot time to launch a backdoor with `rundll32.exe`. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupMustang Panda | Mustang Panda's custom ORat tool uses a WMI event consumer to maintain persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupLeviathan | Leviathan has used WMI for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupBlue Mockingbird | Blue Mockingbird has used mofcomp.exe to establish WMI Event Subscription persistence mechanisms configured from a *.mof file. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupTurla | Turla has used WMI event filters and consumers to establish persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupAPT29 | APT29 has used WMI event subscriptions for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupMetador | Metador has established persistence through the use of a WMI event subscription combined with unusual living-off-the-land binaries such as `cdb.exe`. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupHEXANE | HEXANE has used WMI event subscriptions for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupRancor | Rancor has complied VBScript-generated MOF files into WMI event subscriptions for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupAPT33 | APT33 has attempted to use WMI event subscriptions to establish persistence on compromised hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.