ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
GroupLeviathan

Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor.

T1547.001
Registry Run Keys / Startup Folder
GroupTurla

A Turla Javascript backdoor added a local_update_check value under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence. Additionally, a Turla custom executable containing Metasploit shellcode is saved to the Startup folder to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupRedCurl

RedCurl has established persistence by creating entries in `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT29

APT29 added Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupDark Caracal

Dark Caracal's version of Bandook adds a registry key to HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupBRONZE BUTLER

BRONZE BUTLER has used a batch script that adds a Registry Run key to establish malware persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupDarkhotel

Darkhotel has been known to establish persistence by adding programs to the Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
GroupLazyScripter

LazyScripter has achieved persistence via writing a PowerShell script to the autorun registry key.

T1547.001
Registry Run Keys / Startup Folder
GroupWindshift

Windshift has created LNK files in the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupLuminousMoth

LuminousMoth has used malicious DLLs that setup persistence in the Registry Key `HKCU\Software\Microsoft\Windows\Current Version\Run`.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT28

APT28 has deployed malware that has copied itself to the startup directory for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupRTM

RTM has used Registry run keys to establish persistence for the RTM Trojan and other tools, such as a modified version of TeamViewer remote desktop software.

T1547.001
Registry Run Keys / Startup Folder
GroupLazarus Group

Lazarus Group has maintained persistence by loading malicious code into a startup folder or by adding a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
GroupSilence

Silence has used HKCU\Software\Microsoft\Windows\CurrentVersion\Run, HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupCobalt Group

Cobalt Group has used Registry Run keys for persistence. The group has also set a Startup path to launch the PowerShell shell command and download Cobalt Strike.

T1547.001
Registry Run Keys / Startup Folder
GroupWizard Spider

Wizard Spider has established persistence via the Registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and a shortcut within the startup folder.

T1547.001
Registry Run Keys / Startup Folder
GroupMolerats

Molerats saved malicious files within the AppData and Startup folders to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupMoonstone Sleet

Moonstone Sleet used registry run keys for process execution during initial victim infection.

T1547.001
Registry Run Keys / Startup Folder
GroupInception

Inception has maintained persistence by modifying Registry run key value
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\.

T1547.001
Registry Run Keys / Startup Folder
GroupVOID MANTICORE

VOID MANTICORE has created Windows Registry entries to autorun stage two malware payloads to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupPROMETHIUM

PROMETHIUM has used Registry run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupMagic Hound

Magic Hound malware has used Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupThreat Group-3390

Threat Group-3390's malware can add a Registry key to `Software\Microsoft\Windows\CurrentVersion\Run` for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT33

APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN10

FIN10 has established persistence by using the Registry option in PowerShell Empire to add a Run key.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN13

FIN13 has used Windows Registry run keys such as, `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\hosts` to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT19

An APT19 HTTP malware variant establishes persistence by setting the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Debug Tools-%LOCALAPPDATA%\.

T1547.001
Registry Run Keys / Startup Folder
MalwareTrickBot

TrickBot establishes persistence in the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwarePowerDuke

PowerDuke achieves persistence by using various Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwarePikabot

Pikabot maintains persistence following system checks through the Run key in the registry.

T1547.001
Registry Run Keys / Startup Folder
MalwareRCSession

RCSession has the ability to modify a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGRIFFON

GRIFFON has used a persistence module that stores the implant inside the Registry, which executes at logon.

T1547.001
Registry Run Keys / Startup Folder
MalwareAmadey

Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareNOKKI

NOKKI has established persistence by writing the payload to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareBackdoor.Oldrea

Backdoor.Oldrea adds Registry Run keys to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareAvosLocker

AvosLocker has been executed via the `RunOnce` Registry key to run itself on safe mode.

T1547.001
Registry Run Keys / Startup Folder
MalwareChinoxy

Chinoxy has established persistence via the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` registry key and by loading a dropper to `(%COMMON_ STARTUP%\\eoffice.exe)`.

T1547.001
Registry Run Keys / Startup Folder
MalwareSharpStage

SharpStage has the ability to create persistence for the malware using the Registry autorun key and startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareSmoke Loader

Smoke Loader adds a Registry Run key for persistence and adds a script in the Startup folder to deploy the payload.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmissary

Variants of Emissary have added Run Registry keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareHeartCrypt

HeartCrypt can set the `CurrentVersion\Run` key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareUrsnif

Ursnif has used Registry Run keys to establish automatic execution at system startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareThreatNeedle

ThreatNeedle can be loaded into the Startup folder (`%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\OneDrives.lnk`) as a Shortcut file for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareRansomHub

RansomHub has created an autorun Registry key through the `-safeboot-instance -pass` command line argument.

T1547.001
Registry Run Keys / Startup Folder
MalwareRedLeaves

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. If this fails, it attempts to add Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwarePOWERSOURCE

POWERSOURCE achieves persistence by setting a Registry Run key, with the path depending on whether the victim account has user or administrator access.

T1547.001
Registry Run Keys / Startup Folder
MalwareTsundere Botnet

Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login.

T1547.001
Registry Run Keys / Startup Folder
MalwareZeus Panda

Zeus Panda adds persistence by creating Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareMatryoshka

Matryoshka can establish persistence by adding Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareInvisibleFerret

InvisibleFerret has established persistence within Windows devices by creating a .bat file “queue.bat” within the Startup folder to run a Python script.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.