Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.005 Scheduled Task |
MalwareRevenge RAT | Revenge RAT schedules tasks to run malicious scripts at different intervals. |
| T1053.005 Scheduled Task |
MalwareBackConfig | BackConfig has the ability to use scheduled tasks to repeatedly execute malicious payloads on a compromised host. |
| T1053.005 Scheduled Task |
MalwareMango | Mango can create a scheduled task to run every 32 seconds to communicate with C2 and execute received commands. |
| T1053.005 Scheduled Task |
MalwareGrimAgent | GrimAgent has the ability to set persistence using the Task Scheduler. |
| T1053.005 Scheduled Task |
MalwareLokibot | Lokibot embedded the commands |
| T1053.005 Scheduled Task |
MalwareBabyShark | BabyShark has used scheduled tasks to maintain persistence. |
| T1053.005 Scheduled Task |
MalwareBONDUPDATER | BONDUPDATER persists using a scheduled task that executes every minute. |
| T1053.005 Scheduled Task |
MalwareMeteor | Meteor execution begins from a scheduled task named `Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeAll` and it creates a separate scheduled task called `mstask` to run the wiper only once at 23:55:00. |
| T1053.005 Scheduled Task |
MalwareMaze | Maze has created scheduled tasks using name variants such as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update", to launch Maze at a specific time. |
| T1053.005 Scheduled Task |
MalwareComRAT | ComRAT has used a scheduled task to launch its PowerShell loader. |
| T1053.005 Scheduled Task |
MalwareDisco | Disco can create a scheduled task to run every minute for persistence. |
| T1053.005 Scheduled Task |
MalwareQilin | Qilin has pushed scheduled tasks via Group Policy Objects (GPOs) for execution. Qilin has also created a scheduled task named TVInstallRestore, configured to run at logon using the `/SC ONLOGON` argument. |
| T1053.005 Scheduled Task |
MalwareAppleJeus | AppleJeus has created a scheduled SYSTEM task that runs when a user logs in. |
| T1053.005 Scheduled Task |
MalwareSoreFang | SoreFang can gain persistence through use of scheduled tasks. |
| T1053.005 Scheduled Task |
MalwareCozyCar | One persistence mechanism used by CozyCar is to register itself as a scheduled task. |
| T1053.005 Scheduled Task |
MalwareAgent Tesla | Agent Tesla has achieved persistence via scheduled tasks. |
| T1053.005 Scheduled Task |
MalwarePOWERSTATS | POWERSTATS has established persistence through a scheduled task using the command |
| T1053.005 Scheduled Task |
MalwareBADNEWS | BADNEWS creates a scheduled task to establish by executing a malicious payload every subsequent minute. |
| T1053.005 Scheduled Task |
MalwareGoopy | Goopy has the ability to maintain persistence by creating scheduled tasks set to run every hour. |
| T1053.005 Scheduled Task |
MalwareRemexi | Remexi utilizes scheduled tasks as a persistence mechanism. |
| T1053.005 Scheduled Task |
MalwareQakBot | QakBot has the ability to create scheduled tasks for persistence. |
| T1053.005 Scheduled Task |
MalwareHelminth | Helminth has used a scheduled task for persistence. |
| T1053.005 Scheduled Task |
MalwareDridex | Dridex can maintain persistence via the creation of scheduled tasks within system directories such as `windows\system32\`, `windows\syswow64,` `winnt\system32`, and `winnt\syswow64`. |
| T1053.005 Scheduled Task |
MalwareJSS Loader | JSS Loader has the ability to launch scheduled tasks to establish persistence. |
| T1053.005 Scheduled Task |
MalwareStrifeWater | StrifeWater has create a scheduled task named `Mozilla\Firefox Default Browser Agent 409046Z0FF4A39CB` for persistence. |
| T1053.005 Scheduled Task |
ToolPowerSploit | PowerSploit's |
| T1053.005 Scheduled Task |
ToolEmpire | Empire has modules to interact with the Windows task scheduler. |
| T1053.005 Scheduled Task |
ToolCSPY Downloader | CSPY Downloader can use the schtasks utility to bypass UAC. |
| T1053.005 Scheduled Task |
ToolAsyncRAT | AsyncRAT can create a scheduled task to maintain persistence on system start-up. |
| T1053.005 Scheduled Task |
ToolMCMD | MCMD can use scheduled tasks for persistence. |
| T1053.005 Scheduled Task |
ToolIronNetInjector | IronNetInjector has used a task XML file named |
| T1053.005 Scheduled Task |
ToolKoadic | Koadic has used scheduled tasks to add persistence. |
| T1053.005 Scheduled Task |
Toolschtasks | schtasks is used to schedule tasks on a Windows system to run at a specific date and time. |
| T1053.005 Scheduled Task |
ToolQuasarRAT | QuasarRAT contains a .NET wrapper DLL for creating and managing scheduled tasks for maintaining persistence upon reboot. |
| T1053.005 Scheduled Task |
MalwareDuqu | Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware. |
| T1053.006 Systemd Timers |
MalwareMini Shai-Hulud | Mini Shai-Hulud has obtained persistence on Linux devices by writing the `gh-token-monitor` daemon within `~/.config/systemd/user/gh-token-monitor.service` that polls GitHub every 60 seconds. Mini Shai-Hulud has also leveraged a daemon called “kitty-monitor.service” to maintain persistence within Linux hosts. |
| T1053.006 Systemd Timers |
MalwareCanisterWorm | CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes. |
| T1055 Process Injection |
CampaignRedPenguin | During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes. |
| T1055 Process Injection |
CampaignOperation Sharpshooter | During Operation Sharpshooter, threat actors leveraged embedded shellcode to inject a downloader into the memory of Word. |
| T1055 Process Injection |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team loaded BlackEnergy into svchost.exe, which then launched iexplore.exe for their C2. |
| T1055 Process Injection |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL uses process injection to inject the C2 communication module code in the first found process instance of Chrome, Firefox, or Edge web browsers. It also monitors the established named pipe and re-injects the C2 communication module if necessary. |
| T1055 Process Injection |
CampaignCutting Edge | During Cutting Edge, threat actors used malicious SparkGateway plugins to inject shared objects into web process memory on compromised Ivanti Secure Connect VPNs to enable deployment of backdoors. |
| T1055 Process Injection |
CampaignArcaneDoor | ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices. |
| T1055 Process Injection |
CampaignOperation Wocao | During Operation Wocao, threat actors injected code into a selected process, which in turn launches a command as a child process of the original. |
| T1055 Process Injection |
GroupAPT38 | APT38 has injected malicious payloads into the `explorer.exe` process. |
| T1055 Process Injection |
GroupBlackByte | BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption. |
| T1055 Process Injection |
GroupKimsuky | Kimsuky has used Win7Elevate to inject malicious code into explorer.exe. |
| T1055 Process Injection |
GroupAPT41 | APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process. |
| T1055 Process Injection |
GroupAPT32 | APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe. |
| T1055 Process Injection |
GroupGamaredon Group | Gamaredon Group has injected Remcos into explorer.exe. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.