ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1112×

139 examples

TechniqueUsed byProcedure example
T1112
Modify Registry
MalwareTajMahal

TajMahal can set the KeepPrintedJobs attribute for configured printers in SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Print\\Printers to enable document stealing.

T1112
Modify Registry
MalwareIPsec Helper

IPsec Helper can make arbitrary changes to registry keys based on provided input.

T1112
Modify Registry
MalwareLoJax

LoJax has modified the Registry key ‘HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute’ from ‘autocheck autochk *’ to ‘autocheck autoche *’.

T1112
Modify Registry
MalwareCardinal RAT

Cardinal RAT sets HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load to point to its executable.

T1112
Modify Registry
MalwarePillowmint

Pillowmint has modified the Registry key HKLM\SOFTWARE\Microsoft\DRM to store a malicious payload.

T1112
Modify Registry
MalwareSysUpdate

SysUpdate can write its configuration file to Software\Classes\scConfig in either HKEY_LOCAL_MACHINE or HKEY_CURRENT_USER.

T1112
Modify Registry
MalwareNerex

Nerex creates a Registry subkey that registers a new service.

T1112
Modify Registry
MalwareClop

Clop can make modifications to Registry keys.

T1112
Modify Registry
MalwareLokibot

Lokibot has modified the Registry as part of its UAC bypass process.

T1112
Modify Registry
MalwarePoetRAT

PoetRAT has made registry modifications to alter its behavior upon execution.

T1112
Modify Registry
MalwareCHOPSTICK

CHOPSTICK may modify Registry keys to store RC4 encrypted configuration information.

T1112
Modify Registry
MalwareFELIXROOT

FELIXROOT deletes the Registry key HKCU\Software\Classes\Applications\rundll32.exe\shell\open.

T1112
Modify Registry
MalwareZxShell

ZxShell can create Registry entries to enable services to run.

T1112
Modify Registry
MalwarenjRAT

njRAT can create, delete, or modify a specified Registry key or value.

T1112
Modify Registry
MalwareHIUPAN

HIUPAN has modified registry keys to ensure hidden files and extensions are not visible through the modification of `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced`.

T1112
Modify Registry
MalwareComRAT

ComRAT has modified Registry values to store encrypted orchestrator code and payloads.

T1112
Modify Registry
MalwaremetaMain

metaMain can write the process ID of a target process into the `HKEY_LOCAL_MACHINE\SOFTWARE\DDE\tpid` Registry value as part of its reflective loading activity.

T1112
Modify Registry
MalwareKOCTOPUS

KOCTOPUS has added and deleted keys from the Registry.

T1112
Modify Registry
MalwareQilin

Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client. Qilin can also modify `HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper` to enable posting of ransom messages.

T1112
Modify Registry
MalwareAgent Tesla

Agent Tesla can achieve persistence by modifying Registry key entries.

T1112
Modify Registry
MalwareShadowPad

ShadowPad can modify the Registry to store and maintain a configuration block and virtual file system.

T1112
Modify Registry
MalwareQakBot

QakBot can modify the Registry to store its configuration information in a randomly named subkey under HKCU\Software\Microsoft.

T1112
Modify Registry
MalwareGelsemium

Gelsemium can modify the Registry to store its components.

T1112
Modify Registry
MalwareWaterbear

Waterbear has deleted certain values from the Registry to load a malicious DLL.

T1112
Modify Registry
MalwarePHOREAL

PHOREAL is capable of manipulating the Registry.

T1112
Modify Registry
MalwareBitPaymer

BitPaymer can set values in the Registry to help in execution.

T1112
Modify Registry
MalwareBACKSPACE

BACKSPACE is capable of deleting Registry keys, sub-keys, and values on a victim system.

T1112
Modify Registry
MalwareADVSTORESHELL

ADVSTORESHELL is capable of setting and deleting Registry values.

T1112
Modify Registry
MalwareWarzoneRAT

WarzoneRAT can create `HKCU\Software\Classes\Folder\shell\open\command` as a new registry key during privilege escalation.

T1112
Modify Registry
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can add, modify, and/or delete registry keys. It has changed the proxy configuration of a victim system by modifying the HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap registry.

T1112
Modify Registry
ToolNPPSPY

NPPSPY modifies the Registry to record the malicious listener for output from the Winlogon process.

T1112
Modify Registry
ToolSILENTTRINITY

SILENTTRINITY can modify registry keys, including to enable or disable Remote Desktop Protocol (RDP).

T1112
Modify Registry
ToolAADInternals

AADInternals can modify registry keys as part of setting a new pass-through authentication agent.

T1112
Modify Registry
ToolPcShare

PcShare can delete its persistence mechanisms from the registry.

T1112
Modify Registry
ToolCSPY Downloader

CSPY Downloader can write to the Registry under the %windir% variable to execute tasks.

T1112
Modify Registry
ToolRemcos

Remcos has full control of the Registry, including the ability to modify it.

T1112
Modify Registry
ToolCrackMapExec

CrackMapExec can create a registry key using wdigest.

T1112
Modify Registry
ToolReg

Reg may be used to interact with and modify the Windows Registry of a local or remote system at the command-line interface.

T1112
Modify Registry
ToolQuasarRAT

QuasarRAT has a command to edit the Registry on the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.