ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1546.015
Component Object Model Hijacking
MalwareADVSTORESHELL

Some variants of ADVSTORESHELL achieve persistence by registering the payload as a Shell Icon Overlay handler COM object.

T1546.015
Component Object Model Hijacking
MalwareWarzoneRAT

WarzoneRAT can perform COM hijacking by setting the path to itself to the `HKCU\Software\Classes\Folder\shell\open\command` key with a `DelegateExecute` parameter.

T1546.015
Component Object Model Hijacking
ToolSILENTTRINITY

SILENTTRINITY can add a CLSID key for payload execution through `Registry.CurrentUser.CreateSubKey("Software\\Classes\\CLSID\\{" + clsid + "}\\InProcServer32")`.

T1546.015
Component Object Model Hijacking
ToolPcShare

PcShare has created the `HKCU\\Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InprocServer32` Registry key for persistence.

T1546.016
Installer Packages
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus added a malicious .dylib file to a .dmg installer package for the macOS 3CX application.

T1546.016
Installer Packages
MalwareShai-Hulud

Shai-Hulud has inserted a new lifecycle hook to include `postinstall`. Shai-Hulud has also leveraged the NPM lifecycle hook `preinstall`.

T1546.016
Installer Packages
MalwareAppleJeus

During AppleJeus's installation process, it uses `postinstall` scripts to extract a hidden plist from the application's `/Resources` folder and execute the `plist` file as a Launch Daemon with elevated permissions.

T1546.016
Installer Packages
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can inject malicious pre or post-install scripts within package.json for payload execution.

T1546.016
Installer Packages
GroupTeamPCP

TeamPCP has modified software packages with preinstall scripts to download and execute malicious payloads.

T1546.017
Udev Rules
MalwareREPTILE

REPTILE has used udev for persistence.

T1546.018
Python Startup Hooks
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has used .pth files to establish persistence on compromised hosts due to the Python interpreter's automatic processing of .pth files at startup.

T1546.018
Python Startup Hooks
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Python startup hooks to include the .pth import mechanism for execution.

T1547
Boot or Logon Autostart Execution
GroupAPT42

APT42 has modified the Registry to maintain persistence.

T1547
Boot or Logon Autostart Execution
MalwareMisdat

Misdat has created registry keys for persistence, including `HKCU\Software\dnimtsoleht\StubPath`, `HKCU\Software\snimtsOleht\StubPath`, `HKCU\Software\Backtsaleht\StubPath`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed. Components\{3bf41072-b2b1-21c8-b5c1-bd56d32fbda7}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3ef41072-a2f1-21c8-c5c1-70c2c3bc7905}`.

T1547
Boot or Logon Autostart Execution
MalwarexCaon

xCaon has added persistence via the Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load which causes the malware to run each time any user logs in.

T1547
Boot or Logon Autostart Execution
MalwareBoxCaon

BoxCaon established persistence by setting the HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load registry key to point to its executable.

T1547
Boot or Logon Autostart Execution
MalwareMis-Type

Mis-Type has created registry keys for persistence, including `HKCU\Software\bkfouerioyou`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6afa8072-b2b1-31a8-b5c1-{Unique Identifier}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3BF41072-B2B1-31A8-B5C1-{Unique Identifier}`.

T1547
Boot or Logon Autostart Execution
MalwareDtrack

Dtrack’s RAT makes a persistent target file with auto execution on the host start.

T1547.001
Registry Run Keys / Startup Folder
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group placed LNK files into the victims' startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used Run registry keys with names such as `OneNote Update` to execute legitimate executables that would load through search-order hijacking malicious DLLS to ensure persistence during RedDelta Modified PlugX Infection Chain Operations.

T1547.001
Registry Run Keys / Startup Folder
CampaignOperation Sharpshooter

During Operation Sharpshooter, a first-stage downloader installed Rising Sun to `%Startup%\mssync.exe` on a compromised host.

T1547.001
Registry Run Keys / Startup Folder
GroupBlackByte

BlackByte has used Registry Run keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT3

APT3 places scripts in the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupKimsuky

Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key.

T1547.001
Registry Run Keys / Startup Folder
GroupPatchwork

Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT41

APT41 created and modified startup files for persistence. APT41 added a registry key in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost to establish persistence for Cobalt Strike.

T1547.001
Registry Run Keys / Startup Folder
GroupDragonfly

Dragonfly has added the registry value ntdll to the Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupGorgon Group

Gorgon Group malware can create a .lnk file and add a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT32

APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly.

T1547.001
Registry Run Keys / Startup Folder
GroupMuddyWater

MuddyWater has added Registry Run key KCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemTextEncoding to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupNaikon

Naikon has modified a victim's Windows Run registry to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN6

FIN6 has used Registry Run keys to establish persistence for its downloader tools known as HARDTACK and SHIPBREAD.

T1547.001
Registry Run Keys / Startup Folder
GroupGamaredon Group

Gamaredon Group tools have registered Run keys in the registry to give malicious VBS files persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupStorm-1811

Storm-1811 has created Windows Registry Run keys that execute various batch scripts to establish persistence on victim devices.

T1547.001
Registry Run Keys / Startup Folder
GroupTeamTNT

TeamTNT has added batch scripts to the startup folder.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN7

FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT18

APT18 establishes persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key.

T1547.001
Registry Run Keys / Startup Folder
GroupSidewinder

Sidewinder has added paths to executables in the Registry to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupMustang Panda

Mustang Panda has created the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\AdobelmdyU to maintain persistence. Mustang Panda has also established persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
GroupZIRCONIUM

ZIRCONIUM has created a Registry Run key named Dropbox Update Setup to establish persistence for a malicious Python binary.

T1547.001
Registry Run Keys / Startup Folder
GroupRocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT39

APT39 has maintained persistence using the startup folder.

T1547.001
Registry Run Keys / Startup Folder
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to place a .bat file in the Startup Folder.

T1547.001
Registry Run Keys / Startup Folder
GroupTA2541

TA2541 has placed VBS files in the Startup folder and used Registry run keys to establish persistence for malicious payloads.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT37

APT37's has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\.

T1547.001
Registry Run Keys / Startup Folder
GroupHigaisa

Higaisa added a spoofed binary to the start-up folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupTropic Trooper

Tropic Trooper has created shortcuts in the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupPutter Panda

A dropper used by Putter Panda installs itself into the ASEP Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run with a value named McUpdate.

T1547.001
Registry Run Keys / Startup Folder
GroupKe3chang

Several Ke3chang backdoors achieved persistence by adding a Run key.

T1547.001
Registry Run Keys / Startup Folder
GroupConfucius

Confucius has dropped malicious files into the startup folder `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` on a compromised host in order to maintain persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.