Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRunningRAT | RunningRAT adds itself to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBBSRAT | BBSRAT has been loaded through DLL side-loading of a legitimate Citrix executable that is set to persist through the Registry Run key location |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePlugX | PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareReaver | Reaver creates a shortcut file and saves it in a Startup folder to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBisonal | Bisonal has added itself to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareS-Type | S-Type may create a .lnk file to itself that is saved in the Start menu folder. It may also create the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLumma Stealer | Lumma Stealer has created registry keys to maintain persistence using `HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSeaDuke | SeaDuke is capable of persisting via the Registry Run key or a .lnk file stored in the Startup directory. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDustySky | DustySky achieves persistence by creating a Registry entry in |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTruvasys | Truvasys adds a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSykipot | Sykipot has been known to establish persistence by adding programs to the Run Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareXbash | Xbash can create a Startup item for persistence if it determines it is on a Windows system. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRover | Rover persists by creating a Registry entry in |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareClambling | Clambling can establish persistence by adding a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePureCrypter | PureCrypter can set multiple Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDarkGate | DarkGate installation includes AutoIt script execution creating a shortcut to itself as an LNK object, such as bill.lnk, in the victim startup folder. DarkGate installation finishes with the creation of a registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMongall | Mongall can establish persistence with the auto start function including using the value `EverNoteTrayUService`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNanHaiShu | NanHaiShu modifies the %regrun% Registry to point itself to an autostart mechanism. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCarbanak | Carbanak stores a configuration files in the startup directory to automatically execute commands in order to persist across reboots. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareElise | If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGazer | Gazer can establish persistence by creating a .lnk file in the Start menu. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLatrodectus | Latrodectus can set an AutoRun key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSaint Bot | Saint Bot has established persistence by being copied to the Startup directory or through the `\Software\Microsoft\Windows\CurrentVersion\Run` registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareChaes | Chaes has added persistence via the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLODEINFO | LODEINFO has used Registry run keys to set persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBriba | Briba creates run key Registry entries pointing to malicious DLLs dropped to disk. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMuddyViper | MuddyViper has the ability to establish persistence by configuring its installation directory as a Windows Startup folder by setting the following Registry values to `%APPDATALOCAL%\Microsoft\Windows\PPBCompatCache\ManagerCache`: `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEVILNUM | EVILNUM can achieve persistence through the Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSMOKEDHAM | SMOKEDHAM has used |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can copy itself into the current user’s Startup folder as “Narrator.exe” for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGlassWorm | GlassWorm has set registry run keys for persistence in both `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run\`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMetamorfo | Metamorfo has configured persistence to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEmbargo | Embargo has modified the Windows Registry to start a custom service named irnagentd in Safe Mode. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTrojan.Karagany | Trojan.Karagany can create a link to itself in the Startup folder to automatically start itself upon system restart. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMagicRAT | MagicRAT can persist using malicious LNK objects in the victim machine Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTINYTYPHON | TINYTYPHON installs itself under Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKONNI | A version of KONNI has dropped a Windows shortcut into the Startup folder to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
Malwaregh0st RAT | gh0st RAT has added a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDnsSystem | DnsSystem can write itself to the Startup folder to gain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMoleNet | MoleNet can achieve persitence on the infected machine by setting the Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareJHUHUGIT | JHUHUGIT has used a Registry Run key to establish persistence by executing JavaScript code within the rundll32.exe process. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSPACESHIP | SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareIxeshe | Ixeshe can achieve persistence by adding itself to the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareVBShower | VBShower used |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRogueRobin | RogueRobin created a shortcut in the Windows startup folder to launch a PowerShell script each time the user logs in to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSDBbot | SDBbot has the ability to add a value to the Registry Run key to establish persistence if it detects it is running with regular user privilege. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMosquito | Mosquito establishes persistence under the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRTM | RTM tries to add a Registry Run key under the name "Windows Update" to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGrandoreiro | Grandoreiro can use run keys and create link files in the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLiteDuke | LiteDuke can create persistence by adding a shortcut in the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.