ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareRevenge RAT

Revenge RAT schedules tasks to run malicious scripts at different intervals.

T1053.005
Scheduled Task
MalwareBackConfig

BackConfig has the ability to use scheduled tasks to repeatedly execute malicious payloads on a compromised host.

T1053.005
Scheduled Task
MalwareMango

Mango can create a scheduled task to run every 32 seconds to communicate with C2 and execute received commands.

T1053.005
Scheduled Task
MalwareGrimAgent

GrimAgent has the ability to set persistence using the Task Scheduler.

T1053.005
Scheduled Task
MalwareLokibot

Lokibot embedded the commands schtasks /Run /TN \Microsoft\Windows\DiskCleanup\SilentCleanup /I inside a batch script.

T1053.005
Scheduled Task
MalwareBabyShark

BabyShark has used scheduled tasks to maintain persistence.

T1053.005
Scheduled Task
MalwareBONDUPDATER

BONDUPDATER persists using a scheduled task that executes every minute.

T1053.005
Scheduled Task
MalwareMeteor

Meteor execution begins from a scheduled task named `Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeAll` and it creates a separate scheduled task called `mstask` to run the wiper only once at 23:55:00.

T1053.005
Scheduled Task
MalwareMaze

Maze has created scheduled tasks using name variants such as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update", to launch Maze at a specific time.

T1053.005
Scheduled Task
MalwareComRAT

ComRAT has used a scheduled task to launch its PowerShell loader.

T1053.005
Scheduled Task
MalwareDisco

Disco can create a scheduled task to run every minute for persistence.

T1053.005
Scheduled Task
MalwareQilin

Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument.

T1053.005
Scheduled Task
MalwareAppleJeus

AppleJeus has created a scheduled SYSTEM task that runs when a user logs in.

T1053.005
Scheduled Task
MalwareSoreFang

SoreFang can gain persistence through use of scheduled tasks.

T1053.005
Scheduled Task
MalwareCozyCar

One persistence mechanism used by CozyCar is to register itself as a scheduled task.

T1053.005
Scheduled Task
MalwareAgent Tesla

Agent Tesla has achieved persistence via scheduled tasks.

T1053.005
Scheduled Task
MalwarePOWERSTATS

POWERSTATS has established persistence through a scheduled task using the command ”C:\Windows\system32\schtasks.exe” /Create /F /SC DAILY /ST 12:00 /TN MicrosoftEdge /TR “c:\Windows\system32\wscript.exe C:\Windows\temp\Windows.vbe”.

T1053.005
Scheduled Task
MalwareBADNEWS

BADNEWS creates a scheduled task to establish by executing a malicious payload every subsequent minute.

T1053.005
Scheduled Task
MalwareGoopy

Goopy has the ability to maintain persistence by creating scheduled tasks set to run every hour.

T1053.005
Scheduled Task
MalwareRemexi

Remexi utilizes scheduled tasks as a persistence mechanism.

T1053.005
Scheduled Task
MalwareQakBot

QakBot has the ability to create scheduled tasks for persistence.

T1053.005
Scheduled Task
MalwareHelminth

Helminth has used a scheduled task for persistence.

T1053.005
Scheduled Task
MalwareDridex

Dridex can maintain persistence via the creation of scheduled tasks within system directories such as `windows\system32\`, `windows\syswow64,` `winnt\system32`, and `winnt\syswow64`.

T1053.005
Scheduled Task
MalwareJSS Loader

JSS Loader has the ability to launch scheduled tasks to establish persistence.

T1053.005
Scheduled Task
MalwareStrifeWater

StrifeWater has create a scheduled task named `Mozilla\Firefox Default Browser Agent 409046Z0FF4A39CB` for persistence.

T1053.005
Scheduled Task
ToolPowerSploit

PowerSploit's New-UserPersistenceOption Persistence argument can be used to establish via a Scheduled Task/Job.

T1053.005
Scheduled Task
ToolEmpire

Empire has modules to interact with the Windows task scheduler.

T1053.005
Scheduled Task
ToolCSPY Downloader

CSPY Downloader can use the schtasks utility to bypass UAC.

T1053.005
Scheduled Task
ToolAsyncRAT

AsyncRAT can create a scheduled task to maintain persistence on system start-up.

T1053.005
Scheduled Task
ToolMCMD

MCMD can use scheduled tasks for persistence.

T1053.005
Scheduled Task
ToolIronNetInjector

IronNetInjector has used a task XML file named mssch.xml to run an IronPython script when a user logs in or when specific system events are created.

T1053.005
Scheduled Task
ToolKoadic

Koadic has used scheduled tasks to add persistence.

T1053.005
Scheduled Task
Toolschtasks

schtasks is used to schedule tasks on a Windows system to run at a specific date and time.

T1053.005
Scheduled Task
ToolQuasarRAT

QuasarRAT contains a .NET wrapper DLL for creating and managing scheduled tasks for maintaining persistence upon reboot.

T1053.005
Scheduled Task
MalwareDuqu

Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware.

T1053.006
Systemd Timers
MalwareMini Shai-Hulud

Mini Shai-Hulud has obtained persistence on Linux devices by writing the `gh-token-monitor` daemon within `~/.config/systemd/user/gh-token-monitor.service` that polls GitHub every 60 seconds. Mini Shai-Hulud has also leveraged a daemon called “kitty-monitor.service” to maintain persistence within Linux hosts.

T1053.006
Systemd Timers
MalwareCanisterWorm

CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes.

T1055
Process Injection
CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes.

T1055
Process Injection
CampaignOperation Sharpshooter

During Operation Sharpshooter, threat actors leveraged embedded shellcode to inject a downloader into the memory of Word.

T1055
Process Injection
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team loaded BlackEnergy into svchost.exe, which then launched iexplore.exe for their C2.

T1055
Process Injection
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL uses process injection to inject the C2 communication module code in the first found process instance of Chrome, Firefox, or Edge web browsers. It also monitors the established named pipe and re-injects the C2 communication module if necessary.

T1055
Process Injection
CampaignCutting Edge

During Cutting Edge, threat actors used malicious SparkGateway plugins to inject shared objects into web process memory on compromised Ivanti Secure Connect VPNs to enable deployment of backdoors.

T1055
Process Injection
CampaignArcaneDoor

ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices.

T1055
Process Injection
CampaignOperation Wocao

During Operation Wocao, threat actors injected code into a selected process, which in turn launches a command as a child process of the original.

T1055
Process Injection
GroupAPT38

APT38 has injected malicious payloads into the `explorer.exe` process.

T1055
Process Injection
GroupBlackByte

BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption.

T1055
Process Injection
GroupKimsuky

Kimsuky has used Win7Elevate to inject malicious code into explorer.exe.

T1055
Process Injection
GroupAPT41

APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process.

T1055
Process Injection
GroupAPT32

APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe.

T1055
Process Injection
GroupGamaredon Group

Gamaredon Group has injected Remcos into explorer.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.