ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
CampaignC0032

During the C0032 campaign, TEMP.Veles used scheduled task XML triggers.

T1053.005
Scheduled Task
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted.

T1053.005
Scheduled Task
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used scheduled tasks to execute batch scripts for lateral movement with the following command: `SCHTASKS /Create /S <IP Address> /U <Username> /p <Password> /SC ONCE /TN test /TR <Path to a Batch File> /ST <Time> /RU SYSTEM.`

T1053.005
Scheduled Task
CampaignOperation Wocao

During Operation Wocao, threat actors used scheduled tasks to execute malicious PowerShell code on remote systems.

T1053.005
Scheduled Task
CampaignC0017

During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

T1053.005
Scheduled Task
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1053.005
Scheduled Task
CampaignCostaRicto

During CostaRicto, the threat actors used scheduled tasks to download backdoor tools.

T1053.005
Scheduled Task
GroupAPT38

APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task.

T1053.005
Scheduled Task
GroupBlackByte

BlackByte created scheduled tasks for payload execution.

T1053.005
Scheduled Task
GroupGALLIUM

GALLIUM established persistence for PoisonIvy by created a scheduled task.

T1053.005
Scheduled Task
GroupAPT3

An APT3 downloader creates persistence by creating the following scheduled task: schtasks /create /tn "mysc" /tr C:\Users\Public\test.exe /sc ONLOGON /ru "System".

T1053.005
Scheduled Task
GroupKimsuky

Kimsuky has downloaded additional malware with scheduled tasks. Kimsuky has established persistence by creating a scheduled task named “ChromeUpdateTaskMachine” through the PowerShell cmdlet `Register-ScheduleTask` which was set to execute another PowerShell script once, then five minutes after its creation and periodically repeat every 30 minutes. Kimsuky has also set scheduled tasks that run periodically using the PT1M repetition pattern leveraging naming conventions of Anti-Virus software to include "AhnlabUpdate".

T1053.005
Scheduled Task
GroupPatchwork

A Patchwork file stealer can run a TaskScheduler DLL to add persistence.

T1053.005
Scheduled Task
GroupAPT41

APT41 used a compromised account to create a scheduled task on a system.

T1053.005
Scheduled Task
GroupDragonfly

Dragonfly has used scheduled tasks to automatically log out of created accounts every 8 hours as well as to execute malicious files.

T1053.005
Scheduled Task
GroupmenuPass

menuPass has used a script (atexec.py) to execute a command on a target machine via Task Scheduler.

T1053.005
Scheduled Task
GroupAPT32

APT32 has used scheduled tasks to persist on victim systems.

T1053.005
Scheduled Task
GroupMuddyWater

MuddyWater has used scheduled tasks to establish persistence.

T1053.005
Scheduled Task
GroupNaikon

Naikon has used schtasks.exe for lateral movement in compromised networks.

T1053.005
Scheduled Task
GroupFIN6

FIN6 has used scheduled tasks to establish persistence for various malware it uses, including downloaders known as HARDTACK and SHIPBREAD and FrameworkPOS.

T1053.005
Scheduled Task
GroupGamaredon Group

Gamaredon Group has created scheduled tasks to launch executables after a designated number of minutes have passed.

T1053.005
Scheduled Task
GroupFIN7

FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence.

T1053.005
Scheduled Task
GroupSandworm Team

Sandworm Team leveraged SHARPIVORY, a .NET dropper that writes embedded payload to disk and uses scheduled tasks to persist on victim machines.

T1053.005
Scheduled Task
GroupMachete

Machete has created scheduled tasks to maintain Machete's persistence.

T1053.005
Scheduled Task
GroupMustang Panda

Mustang Panda has created a scheduled task to execute additional malicious software, as well as maintain persistence. Mustang Panda has also created a scheduled task that creates a reverse shell.

T1053.005
Scheduled Task
GroupAPT39

APT39 has created scheduled tasks for persistence.

T1053.005
Scheduled Task
GroupTA2541

TA2541 has used scheduled tasks to establish persistence for installed tools.

T1053.005
Scheduled Task
GroupAPT37

APT37 has created scheduled tasks to run malicious scripts on a compromised host.

T1053.005
Scheduled Task
GroupOilRig

OilRig has created scheduled tasks that run a VBScript to execute a payload on victim machines.

T1053.005
Scheduled Task
GroupHigaisa

Higaisa dropped and added officeupdate.exe to scheduled tasks.

T1053.005
Scheduled Task
GroupConfucius

Confucius has created scheduled tasks to maintain persistence on a compromised host.

T1053.005
Scheduled Task
GroupBlue Mockingbird

Blue Mockingbird has used Windows Scheduled Tasks to establish persistence on local and remote hosts.

T1053.005
Scheduled Task
GroupWinter Vivern

Winter Vivern executed PowerShell scripts that would subsequently attempt to establish persistence by creating scheduled tasks objects to periodically retrieve and execute remotely-hosted payloads.

T1053.005
Scheduled Task
GroupStorm-0501

Storm-0501 had used a scheduled task named “SysUpdate” that was registered via GPO on devices in the network to distribute the Embargo ransomware.

T1053.005
Scheduled Task
GroupBITTER

BITTER has used scheduled tasks for persistence and execution.

T1053.005
Scheduled Task
GroupRedCurl

RedCurl has created scheduled tasks for persistence.

T1053.005
Scheduled Task
GroupStealth Falcon

Stealth Falcon malware creates a scheduled task entitled “IE Web Cache” to execute a malicious file hourly.

T1053.005
Scheduled Task
GroupAPT29

APT29 has used named and hijacked scheduled tasks to establish persistence.

T1053.005
Scheduled Task
GroupChimera

Chimera has used scheduled tasks to invoke Cobalt Strike including through batch script schtasks /create /ru "SYSTEM" /tn "update" /tr "cmd /c c:\windows\temp\update.bat" /sc once /f /st and to maintain persistence.

T1053.005
Scheduled Task
GroupBRONZE BUTLER

BRONZE BUTLER has used schtasks to register a scheduled task to execute malware during lateral movement.

T1053.005
Scheduled Task
GroupEmber Bear

Ember Bear uses remotely scheduled tasks to facilitate remote command execution on victim machines.

T1053.005
Scheduled Task
GroupToddyCat

ToddyCat has used scheduled tasks to execute discovery commands and scripts for collection.

T1053.005
Scheduled Task
GroupLuminousMoth

LuminousMoth has created scheduled tasks to establish persistence for their tools.

T1053.005
Scheduled Task
GroupAPT42

APT42 has used scheduled tasks for persistence.

T1053.005
Scheduled Task
GroupFox Kitten

Fox Kitten has used Scheduled Tasks for persistence and to load and execute a reverse proxy binary.

T1053.005
Scheduled Task
GroupAPT-C-36

APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google.

T1053.005
Scheduled Task
GroupLazarus Group

Lazarus Group has used schtasks for persistence including through the periodic execution of a remote XSL script or a dropped VBS payload.

T1053.005
Scheduled Task
GroupEarth Lusca

Earth Lusca used the command schtasks /Create /SC ONLOgon /TN WindowsUpdateCheck /TR “[file path]” /ru system for persistence.

T1053.005
Scheduled Task
GroupSilence

Silence has used scheduled tasks to stage its operation.

T1053.005
Scheduled Task
GroupCobalt Group

Cobalt Group has created Windows tasks to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.