Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
GroupLeviathan | Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTurla | A Turla Javascript backdoor added a local_update_check value under the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupRedCurl | RedCurl has established persistence by creating entries in `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT29 | APT29 added Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDark Caracal | Dark Caracal's version of Bandook adds a registry key to |
| T1547.001 Registry Run Keys / Startup Folder |
GroupBRONZE BUTLER | BRONZE BUTLER has used a batch script that adds a Registry Run key to establish malware persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDarkhotel | Darkhotel has been known to establish persistence by adding programs to the Run Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLazyScripter | LazyScripter has achieved persistence via writing a PowerShell script to the autorun registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupWindshift | Windshift has created LNK files in the Startup folder to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLuminousMoth | LuminousMoth has used malicious DLLs that setup persistence in the Registry Key `HKCU\Software\Microsoft\Windows\Current Version\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT28 | APT28 has deployed malware that has copied itself to the startup directory for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupRTM | RTM has used Registry run keys to establish persistence for the RTM Trojan and other tools, such as a modified version of TeamViewer remote desktop software. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLazarus Group | Lazarus Group has maintained persistence by loading malicious code into a startup folder or by adding a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupSilence | Silence has used |
| T1547.001 Registry Run Keys / Startup Folder |
GroupCobalt Group | Cobalt Group has used Registry Run keys for persistence. The group has also set a Startup path to launch the PowerShell shell command and download Cobalt Strike. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupWizard Spider | Wizard Spider has established persistence via the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMolerats | Molerats saved malicious files within the AppData and Startup folders to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMoonstone Sleet | Moonstone Sleet used registry run keys for process execution during initial victim infection. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupInception | Inception has maintained persistence by modifying Registry run key value |
| T1547.001 Registry Run Keys / Startup Folder |
GroupVOID MANTICORE | VOID MANTICORE has created Windows Registry entries to autorun stage two malware payloads to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupPROMETHIUM | PROMETHIUM has used Registry run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMagic Hound | Magic Hound malware has used Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupThreat Group-3390 | Threat Group-3390's malware can add a Registry key to `Software\Microsoft\Windows\CurrentVersion\Run` for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT33 | APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN10 | FIN10 has established persistence by using the Registry option in PowerShell Empire to add a Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN13 | FIN13 has used Windows Registry run keys such as, `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\hosts` to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT19 | An APT19 HTTP malware variant establishes persistence by setting the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTrickBot | TrickBot establishes persistence in the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePowerDuke | PowerDuke achieves persistence by using various Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePikabot | Pikabot maintains persistence following system checks through the Run key in the registry. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRCSession | RCSession has the ability to modify a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGRIFFON | GRIFFON has used a persistence module that stores the implant inside the Registry, which executes at logon. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAmadey | Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNOKKI | NOKKI has established persistence by writing the payload to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBackdoor.Oldrea | Backdoor.Oldrea adds Registry Run keys to achieve persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAvosLocker | AvosLocker has been executed via the `RunOnce` Registry key to run itself on safe mode. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareChinoxy | Chinoxy has established persistence via the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` registry key and by loading a dropper to `(%COMMON_ STARTUP%\\eoffice.exe)`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSharpStage | SharpStage has the ability to create persistence for the malware using the Registry autorun key and startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSmoke Loader | Smoke Loader adds a Registry Run key for persistence and adds a script in the Startup folder to deploy the payload. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEmissary | Variants of Emissary have added Run Registry keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHeartCrypt | HeartCrypt can set the `CurrentVersion\Run` key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareUrsnif | Ursnif has used Registry Run keys to establish automatic execution at system startup. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareThreatNeedle | ThreatNeedle can be loaded into the Startup folder (`%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\OneDrives.lnk`) as a Shortcut file for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRansomHub | RansomHub has created an autorun Registry key through the `-safeboot-instance -pass` command line argument. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRedLeaves | RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. If this fails, it attempts to add Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePOWERSOURCE | POWERSOURCE achieves persistence by setting a Registry Run key, with the path depending on whether the victim account has user or administrator access. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTsundere Botnet | Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareZeus Panda | Zeus Panda adds persistence by creating Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMatryoshka | Matryoshka can establish persistence by adding Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareInvisibleFerret | InvisibleFerret has established persistence within Windows devices by creating a .bat file “queue.bat” within the Startup folder to run a Python script. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.