Real-world descriptions of how a group, tool or campaign used a technique.
201 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEVILNUM | EVILNUM can achieve persistence through the Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSMOKEDHAM | SMOKEDHAM has used |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can copy itself into the current user’s Startup folder as “Narrator.exe” for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGlassWorm | GlassWorm has set registry run keys for persistence in both `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run\`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMetamorfo | Metamorfo has configured persistence to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEmbargo | Embargo has modified the Windows Registry to start a custom service named irnagentd in Safe Mode. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTrojan.Karagany | Trojan.Karagany can create a link to itself in the Startup folder to automatically start itself upon system restart. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMagicRAT | MagicRAT can persist using malicious LNK objects in the victim machine Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTINYTYPHON | TINYTYPHON installs itself under Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKONNI | A version of KONNI has dropped a Windows shortcut into the Startup folder to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
Malwaregh0st RAT | gh0st RAT has added a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDnsSystem | DnsSystem can write itself to the Startup folder to gain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMoleNet | MoleNet can achieve persitence on the infected machine by setting the Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareJHUHUGIT | JHUHUGIT has used a Registry Run key to establish persistence by executing JavaScript code within the rundll32.exe process. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSPACESHIP | SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareIxeshe | Ixeshe can achieve persistence by adding itself to the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareVBShower | VBShower used |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRogueRobin | RogueRobin created a shortcut in the Windows startup folder to launch a PowerShell script each time the user logs in to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSDBbot | SDBbot has the ability to add a value to the Registry Run key to establish persistence if it detects it is running with regular user privilege. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMosquito | Mosquito establishes persistence under the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRTM | RTM tries to add a Registry Run key under the name "Windows Update" to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGrandoreiro | Grandoreiro can use run keys and create link files in the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLiteDuke | LiteDuke can create persistence by adding a shortcut in the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSakula | Most Sakula samples maintain persistence by setting the Registry Run key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBazar | Bazar can create or add files to Registry Run Keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBadPatch | BadPatch establishes a foothold by adding a link to the malware executable in the startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareXLoader | XLoader establishes persistence by copying its executable in a subdirectory of `%APPDATA%` or `%PROGRAMFILES%`, and then modifies Windows Registry Run keys or policies keys to execute the executable on system start. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRyuk | Ryuk has used the Windows command line to create a Registry entry under |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFinal1stspy | Final1stspy creates a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLockBit 2.0 | LockBit 2.0 can use a Registry Run key to establish persistence at startup. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareZebrocy | Zebrocy creates an entry in a Registry Run key for the malware to execute on startup. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFinFisher | FinFisher establishes persistence by creating the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCrossRAT | CrossRAT uses run keys for persistence on Windows. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEvilBunny | EvilBunny has created Registry keys for persistence in |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCobian RAT | Cobian RAT creates an autostart Registry key to ensure persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareServHelper | ServHelper may attempt to establish persistence via the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareJCry | JCry has created payloads in the Startup directory to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareUSBStealer | USBStealer registers itself under a Registry Run key with the name "USB Disk Security." |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTaidoor | Taidoor has modified the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSHIPSHAPE | SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePoisonIvy | PoisonIvy creates run key Registry entries pointing to a malicious executable dropped to disk. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSeasalt | Seasalt creates a Registry entry to ensure infection after reboot under |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNanoCore | NanoCore creates a RunOnce key in the Registry to execute its VBS scripts each time the user logs on to the machine. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLoJax | LoJax has modified the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCardinal RAT | Cardinal RAT establishes Persistence by setting the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePisloader | Pisloader establishes persistence via a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGold Dragon | Gold Dragon establishes persistence in the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRamsay | Ramsay has created Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCarberp | Carberp has maintained persistence by placing itself inside the current user's startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFunnyDream | FunnyDream can use a Registry Run Key and the Startup folder to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.