ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
MalwareRunningRAT

RunningRAT adds itself to the Registry key Software\Microsoft\Windows\CurrentVersion\Run to establish persistence upon reboot.

T1547.001
Registry Run Keys / Startup Folder
MalwareBBSRAT

BBSRAT has been loaded through DLL side-loading of a legitimate Citrix executable that is set to persist through the Registry Run key location HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ssonsvr.exe.

T1547.001
Registry Run Keys / Startup Folder
MalwarePlugX

PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareReaver

Reaver creates a shortcut file and saves it in a Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBisonal

Bisonal has added itself to the Registry key HKEY_CURRENT_USER\Software\Microsoft\CurrentVersion\Run\ for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareS-Type

S-Type may create a .lnk file to itself that is saved in the Start menu folder. It may also create the Registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ IMJPMIJ8.1{3 characters of Unique Identifier}.

T1547.001
Registry Run Keys / Startup Folder
MalwareLumma Stealer

Lumma Stealer has created registry keys to maintain persistence using `HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareSeaDuke

SeaDuke is capable of persisting via the Registry Run key or a .lnk file stored in the Startup directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareDustySky

DustySky achieves persistence by creating a Registry entry in HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareTruvasys

Truvasys adds a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSykipot

Sykipot has been known to establish persistence by adding programs to the Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareXbash

Xbash can create a Startup item for persistence if it determines it is on a Windows system.

T1547.001
Registry Run Keys / Startup Folder
MalwareRover

Rover persists by creating a Registry entry in HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\.

T1547.001
Registry Run Keys / Startup Folder
MalwareClambling

Clambling can establish persistence by adding a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwarePureCrypter

PureCrypter can set multiple Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkGate

DarkGate installation includes AutoIt script execution creating a shortcut to itself as an LNK object, such as bill.lnk, in the victim startup folder. DarkGate installation finishes with the creation of a registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareMongall

Mongall can establish persistence with the auto start function including using the value `EverNoteTrayUService`.

T1547.001
Registry Run Keys / Startup Folder
MalwareNanHaiShu

NanHaiShu modifies the %regrun% Registry to point itself to an autostart mechanism.

T1547.001
Registry Run Keys / Startup Folder
MalwareCarbanak

Carbanak stores a configuration files in the startup directory to automatically execute commands in order to persist across reboots.

T1547.001
Registry Run Keys / Startup Folder
MalwareElise

If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svchost : %APPDATA%\Microsoft\Network\svchost.exe. Other variants have set the following Registry keys for persistence: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\imejp : [self] and HKCU\Software\Microsoft\Windows\CurrentVersion\Run\IAStorD.

T1547.001
Registry Run Keys / Startup Folder
MalwareGazer

Gazer can establish persistence by creating a .lnk file in the Start menu.

T1547.001
Registry Run Keys / Startup Folder
MalwareLatrodectus

Latrodectus can set an AutoRun key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSaint Bot

Saint Bot has established persistence by being copied to the Startup directory or through the `\Software\Microsoft\Windows\CurrentVersion\Run` registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareChaes

Chaes has added persistence via the Registry key software\microsoft\windows\currentversion\run\microsoft windows html help.

T1547.001
Registry Run Keys / Startup Folder
MalwareLODEINFO

LODEINFO has used Registry run keys to set persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBriba

Briba creates run key Registry entries pointing to malicious DLLs dropped to disk.

T1547.001
Registry Run Keys / Startup Folder
MalwareMuddyViper

MuddyViper has the ability to establish persistence by configuring its installation directory as a Windows Startup folder by setting the following Registry values to `%APPDATALOCAL%\Microsoft\Windows\PPBCompatCache\ManagerCache`:  `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup`.

T1547.001
Registry Run Keys / Startup Folder
MalwareEVILNUM

EVILNUM can achieve persistence through the Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareSMOKEDHAM

SMOKEDHAM has used reg.exe to create a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can copy itself into the current user’s Startup folder as “Narrator.exe” for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGlassWorm

GlassWorm has set registry run keys for persistence in both `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run\`.

T1547.001
Registry Run Keys / Startup Folder
MalwareMetamorfo

Metamorfo has configured persistence to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run, Spotify =% APPDATA%\Spotify\Spotify.exe and used .LNK files in the startup folder to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmbargo

Embargo has modified the Windows Registry to start a custom service named irnagentd in Safe Mode.

T1547.001
Registry Run Keys / Startup Folder
MalwareTrojan.Karagany

Trojan.Karagany can create a link to itself in the Startup folder to automatically start itself upon system restart.

T1547.001
Registry Run Keys / Startup Folder
MalwareMagicRAT

MagicRAT can persist using malicious LNK objects in the victim machine Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareTINYTYPHON

TINYTYPHON installs itself under Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareKONNI

A version of KONNI has dropped a Windows shortcut into the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
Malwaregh0st RAT

gh0st RAT has added a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareDnsSystem

DnsSystem can write itself to the Startup folder to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareMoleNet

MoleNet can achieve persitence on the infected machine by setting the Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareJHUHUGIT

JHUHUGIT has used a Registry Run key to establish persistence by executing JavaScript code within the rundll32.exe process.

T1547.001
Registry Run Keys / Startup Folder
MalwareSPACESHIP

SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareIxeshe

Ixeshe can achieve persistence by adding itself to the HKCU\Software\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareVBShower

VBShower used HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\[a-f0-9A-F]{8} to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareRogueRobin

RogueRobin created a shortcut in the Windows startup folder to launch a PowerShell script each time the user logs in to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSDBbot

SDBbot has the ability to add a value to the Registry Run key to establish persistence if it detects it is running with regular user privilege.

T1547.001
Registry Run Keys / Startup Folder
MalwareMosquito

Mosquito establishes persistence under the Registry key HKCU\Software\Run auto_update.

T1547.001
Registry Run Keys / Startup Folder
MalwareRTM

RTM tries to add a Registry Run key under the name "Windows Update" to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGrandoreiro

Grandoreiro can use run keys and create link files in the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareLiteDuke

LiteDuke can create persistence by adding a shortcut in the CurrentVersion\Run Registry key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.