ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1547.001×

201 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
MalwareEVILNUM

EVILNUM can achieve persistence through the Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareSMOKEDHAM

SMOKEDHAM has used reg.exe to create a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can copy itself into the current user’s Startup folder as “Narrator.exe” for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGlassWorm

GlassWorm has set registry run keys for persistence in both `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run\`.

T1547.001
Registry Run Keys / Startup Folder
MalwareMetamorfo

Metamorfo has configured persistence to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run, Spotify =% APPDATA%\Spotify\Spotify.exe and used .LNK files in the startup folder to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmbargo

Embargo has modified the Windows Registry to start a custom service named irnagentd in Safe Mode.

T1547.001
Registry Run Keys / Startup Folder
MalwareTrojan.Karagany

Trojan.Karagany can create a link to itself in the Startup folder to automatically start itself upon system restart.

T1547.001
Registry Run Keys / Startup Folder
MalwareMagicRAT

MagicRAT can persist using malicious LNK objects in the victim machine Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareTINYTYPHON

TINYTYPHON installs itself under Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareKONNI

A version of KONNI has dropped a Windows shortcut into the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
Malwaregh0st RAT

gh0st RAT has added a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareDnsSystem

DnsSystem can write itself to the Startup folder to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareMoleNet

MoleNet can achieve persitence on the infected machine by setting the Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareJHUHUGIT

JHUHUGIT has used a Registry Run key to establish persistence by executing JavaScript code within the rundll32.exe process.

T1547.001
Registry Run Keys / Startup Folder
MalwareSPACESHIP

SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareIxeshe

Ixeshe can achieve persistence by adding itself to the HKCU\Software\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareVBShower

VBShower used HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\[a-f0-9A-F]{8} to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareRogueRobin

RogueRobin created a shortcut in the Windows startup folder to launch a PowerShell script each time the user logs in to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSDBbot

SDBbot has the ability to add a value to the Registry Run key to establish persistence if it detects it is running with regular user privilege.

T1547.001
Registry Run Keys / Startup Folder
MalwareMosquito

Mosquito establishes persistence under the Registry key HKCU\Software\Run auto_update.

T1547.001
Registry Run Keys / Startup Folder
MalwareRTM

RTM tries to add a Registry Run key under the name "Windows Update" to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGrandoreiro

Grandoreiro can use run keys and create link files in the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareLiteDuke

LiteDuke can create persistence by adding a shortcut in the CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareSakula

Most Sakula samples maintain persistence by setting the Registry Run key SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ in the HKLM or HKCU hive, with the Registry value and file name varying by sample.

T1547.001
Registry Run Keys / Startup Folder
MalwareBazar

Bazar can create or add files to Registry Run Keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBadPatch

BadPatch establishes a foothold by adding a link to the malware executable in the startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareXLoader

XLoader establishes persistence by copying its executable in a subdirectory of `%APPDATA%` or `%PROGRAMFILES%`, and then modifies Windows Registry Run keys or policies keys to execute the executable on system start.

T1547.001
Registry Run Keys / Startup Folder
MalwareRyuk

Ryuk has used the Windows command line to create a Registry entry under HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareFinal1stspy

Final1stspy creates a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareLockBit 2.0

LockBit 2.0 can use a Registry Run key to establish persistence at startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareZebrocy

Zebrocy creates an entry in a Registry Run key for the malware to execute on startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareFinFisher

FinFisher establishes persistence by creating the Registry key HKCU\Software\Microsoft\Windows\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareCrossRAT

CrossRAT uses run keys for persistence on Windows.

T1547.001
Registry Run Keys / Startup Folder
MalwareEvilBunny

EvilBunny has created Registry keys for persistence in [HKLM|HKCU]\…\CurrentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareCobian RAT

Cobian RAT creates an autostart Registry key to ensure persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareServHelper

ServHelper may attempt to establish persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareJCry

JCry has created payloads in the Startup directory to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareUSBStealer

USBStealer registers itself under a Registry Run key with the name "USB Disk Security."

T1547.001
Registry Run Keys / Startup Folder
MalwareTaidoor

Taidoor has modified the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run key for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSHIPSHAPE

SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwarePoisonIvy

PoisonIvy creates run key Registry entries pointing to a malicious executable dropped to disk.

T1547.001
Registry Run Keys / Startup Folder
MalwareSeasalt

Seasalt creates a Registry entry to ensure infection after reboot under HKLM\Software\Microsoft\Windows\currentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareNanoCore

NanoCore creates a RunOnce key in the Registry to execute its VBS scripts each time the user logs on to the machine.

T1547.001
Registry Run Keys / Startup Folder
MalwareLoJax

LoJax has modified the Registry key ‘HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute’ from ‘autocheck autochk *’ to ‘autocheck autoche *’ in order to execute its payload during Windows startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareCardinal RAT

Cardinal RAT establishes Persistence by setting the HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load Registry key to point to its executable.

T1547.001
Registry Run Keys / Startup Folder
MalwarePisloader

Pisloader establishes persistence via a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareGold Dragon

Gold Dragon establishes persistence in the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareRamsay

Ramsay has created Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareCarberp

Carberp has maintained persistence by placing itself inside the current user's startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareFunnyDream

FunnyDream can use a Registry Run Key and the Startup folder to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.