Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1546.015 Component Object Model Hijacking |
MalwareADVSTORESHELL | Some variants of ADVSTORESHELL achieve persistence by registering the payload as a Shell Icon Overlay handler COM object. |
| T1546.015 Component Object Model Hijacking |
MalwareWarzoneRAT | WarzoneRAT can perform COM hijacking by setting the path to itself to the `HKCU\Software\Classes\Folder\shell\open\command` key with a `DelegateExecute` parameter. |
| T1546.015 Component Object Model Hijacking |
ToolSILENTTRINITY | SILENTTRINITY can add a CLSID key for payload execution through `Registry.CurrentUser.CreateSubKey("Software\\Classes\\CLSID\\{" + clsid + "}\\InProcServer32")`. |
| T1546.015 Component Object Model Hijacking |
ToolPcShare | PcShare has created the `HKCU\\Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InprocServer32` Registry key for persistence. |
| T1546.016 Installer Packages |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus added a malicious .dylib file to a .dmg installer package for the macOS 3CX application. |
| T1546.016 Installer Packages |
MalwareShai-Hulud | Shai-Hulud has inserted a new lifecycle hook to include `postinstall`. Shai-Hulud has also leveraged the NPM lifecycle hook `preinstall`. |
| T1546.016 Installer Packages |
MalwareAppleJeus | During AppleJeus's installation process, it uses `postinstall` scripts to extract a hidden plist from the application's `/Resources` folder and execute the `plist` file as a Launch Daemon with elevated permissions. |
| T1546.016 Installer Packages |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can inject malicious pre or post-install scripts within package.json for payload execution. |
| T1546.016 Installer Packages |
GroupTeamPCP | TeamPCP has modified software packages with preinstall scripts to download and execute malicious payloads. |
| T1546.017 Udev Rules |
MalwareREPTILE | REPTILE has used udev for persistence. |
| T1546.018 Python Startup Hooks |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has used .pth files to establish persistence on compromised hosts due to the Python interpreter's automatic processing of .pth files at startup. |
| T1546.018 Python Startup Hooks |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized Python startup hooks to include the .pth import mechanism for execution. |
| T1547 Boot or Logon Autostart Execution |
GroupAPT42 | APT42 has modified the Registry to maintain persistence. |
| T1547 Boot or Logon Autostart Execution |
MalwareMisdat | Misdat has created registry keys for persistence, including `HKCU\Software\dnimtsoleht\StubPath`, `HKCU\Software\snimtsOleht\StubPath`, `HKCU\Software\Backtsaleht\StubPath`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed. Components\{3bf41072-b2b1-21c8-b5c1-bd56d32fbda7}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3ef41072-a2f1-21c8-c5c1-70c2c3bc7905}`. |
| T1547 Boot or Logon Autostart Execution |
MalwarexCaon | xCaon has added persistence via the Registry key |
| T1547 Boot or Logon Autostart Execution |
MalwareBoxCaon | BoxCaon established persistence by setting the |
| T1547 Boot or Logon Autostart Execution |
MalwareMis-Type | Mis-Type has created registry keys for persistence, including `HKCU\Software\bkfouerioyou`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6afa8072-b2b1-31a8-b5c1-{Unique Identifier}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3BF41072-B2B1-31A8-B5C1-{Unique Identifier}`. |
| T1547 Boot or Logon Autostart Execution |
MalwareDtrack | Dtrack’s RAT makes a persistent target file with auto execution on the host start. |
| T1547.001 Registry Run Keys / Startup Folder |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group placed LNK files into the victims' startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used Run registry keys with names such as `OneNote Update` to execute legitimate executables that would load through search-order hijacking malicious DLLS to ensure persistence during RedDelta Modified PlugX Infection Chain Operations. |
| T1547.001 Registry Run Keys / Startup Folder |
CampaignOperation Sharpshooter | During Operation Sharpshooter, a first-stage downloader installed Rising Sun to `%Startup%\mssync.exe` on a compromised host. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupBlackByte | BlackByte has used Registry Run keys for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT3 | APT3 places scripts in the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKimsuky | Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupPatchwork | Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT41 | APT41 created and modified startup files for persistence. APT41 added a registry key in |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDragonfly | Dragonfly has added the registry value ntdll to the Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupGorgon Group | Gorgon Group malware can create a .lnk file and add a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT32 | APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMuddyWater | MuddyWater has added Registry Run key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupNaikon | Naikon has modified a victim's Windows Run registry to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN6 | FIN6 has used Registry Run keys to establish persistence for its downloader tools known as HARDTACK and SHIPBREAD. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupGamaredon Group | Gamaredon Group tools have registered Run keys in the registry to give malicious VBS files persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupStorm-1811 | Storm-1811 has created Windows Registry Run keys that execute various batch scripts to establish persistence on victim devices. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTeamTNT | TeamTNT has added batch scripts to the startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN7 | FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT18 | APT18 establishes persistence via the |
| T1547.001 Registry Run Keys / Startup Folder |
GroupSidewinder | Sidewinder has added paths to executables in the Registry to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMustang Panda | Mustang Panda has created the registry key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupZIRCONIUM | ZIRCONIUM has created a Registry Run key named |
| T1547.001 Registry Run Keys / Startup Folder |
GroupRocke | Rocke's miner has created UPX-packed files in the Windows Start Menu Folder. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT39 | APT39 has maintained persistence using the startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupContagious Interview | Contagious Interview has established persistence using InvisibleFerret malware to place a .bat file in the Startup Folder. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTA2541 | TA2541 has placed VBS files in the Startup folder and used Registry run keys to establish persistence for malicious payloads. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT37 | APT37's has added persistence via the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupHigaisa | Higaisa added a spoofed binary to the start-up folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTropic Trooper | Tropic Trooper has created shortcuts in the Startup folder to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupPutter Panda | A dropper used by Putter Panda installs itself into the ASEP Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKe3chang | Several Ke3chang backdoors achieved persistence by adding a Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupConfucius | Confucius has dropped malicious files into the startup folder `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` on a compromised host in order to maintain persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.