ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1053.005×

12 examples

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script.

T1053.005
Scheduled Task
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used scheduled tasks to help establish persistence.

T1053.005
Scheduled Task
CampaignFrankenstein

During Frankenstein, the threat actors established persistence through a scheduled task using the command: `/Create /F /SC DAILY /ST 09:00 /TN WinUpdate /TR`, named "WinUpdate"

T1053.005
Scheduled Task
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles installed scheduled tasks defined in XML files.

T1053.005
Scheduled Task
CampaignJuicy Mix

During Juicy Mix, OilRig used VBS droppers to schedule tasks for persistence.

T1053.005
Scheduled Task
CampaignC0032

During the C0032 campaign, TEMP.Veles used scheduled task XML triggers.

T1053.005
Scheduled Task
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted.

T1053.005
Scheduled Task
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used scheduled tasks to execute batch scripts for lateral movement with the following command: `SCHTASKS /Create /S <IP Address> /U <Username> /p <Password> /SC ONCE /TN test /TR <Path to a Batch File> /ST <Time> /RU SYSTEM.`

T1053.005
Scheduled Task
CampaignOperation Wocao

During Operation Wocao, threat actors used scheduled tasks to execute malicious PowerShell code on remote systems.

T1053.005
Scheduled Task
CampaignC0017

During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

T1053.005
Scheduled Task
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1053.005
Scheduled Task
CampaignCostaRicto

During CostaRicto, the threat actors used scheduled tasks to download backdoor tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.