Real-world descriptions of how a group, tool or campaign used a technique.
12 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.005 Scheduled Task |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script. |
| T1053.005 Scheduled Task |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used scheduled tasks to help establish persistence. |
| T1053.005 Scheduled Task |
CampaignFrankenstein | During Frankenstein, the threat actors established persistence through a scheduled task using the command: `/Create /F /SC DAILY /ST 09:00 /TN WinUpdate /TR`, named "WinUpdate" |
| T1053.005 Scheduled Task |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles installed scheduled tasks defined in XML files. |
| T1053.005 Scheduled Task |
CampaignJuicy Mix | During Juicy Mix, OilRig used VBS droppers to schedule tasks for persistence. |
| T1053.005 Scheduled Task |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used scheduled task XML triggers. |
| T1053.005 Scheduled Task |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted. |
| T1053.005 Scheduled Task |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used scheduled tasks to execute batch scripts for lateral movement with the following command: `SCHTASKS /Create /S <IP Address> /U <Username> /p <Password> /SC ONCE /TN test /TR <Path to a Batch File> /ST <Time> /RU SYSTEM.` |
| T1053.005 Scheduled Task |
CampaignOperation Wocao | During Operation Wocao, threat actors used scheduled tasks to execute malicious PowerShell code on remote systems. |
| T1053.005 Scheduled Task |
CampaignC0017 | During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`. |
| T1053.005 Scheduled Task |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time. |
| T1053.005 Scheduled Task |
CampaignCostaRicto | During CostaRicto, the threat actors used scheduled tasks to download backdoor tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.