ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1112×

29 examples

TechniqueUsed byProcedure example
T1112
Modify Registry
GroupAPT38

APT38 uses a tool called CLEANTOAD that has the capability to modify Registry keys.

T1112
Modify Registry
GroupIndrik Spider

Indrik Spider has modified registry keys to prepare for ransomware execution and to disable common administrative utilities.

T1112
Modify Registry
GroupBlackByte

BlackByte performed Registry modifications to escalate privileges and disable security tools.

T1112
Modify Registry
GroupKimsuky

Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck.

T1112
Modify Registry
GroupVolt Typhoon

Volt Typhoon has used `netsh` to create a PortProxy Registry modification on a compromised server running the Paessler Router Traffic Grapher (PRTG).

T1112
Modify Registry
GroupPatchwork

A Patchwork payload deletes Resiliency Registry keys created by Microsoft Office applications in an apparent effort to trick users into thinking there were no issues during application runs.

T1112
Modify Registry
GroupAPT41

APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.

T1112
Modify Registry
GroupDragonfly

Dragonfly has modified the Registry to perform multiple techniques through the use of Reg.

T1112
Modify Registry
GroupGorgon Group

Gorgon Group malware can deactivate security mechanisms in Microsoft Office by editing several keys and values under HKCU\Software\Microsoft\Office\.

T1112
Modify Registry
GroupAPT32

APT32's backdoor has modified the Windows Registry to store the backdoor's configuration.

T1112
Modify Registry
GroupGamaredon Group

Gamaredon Group has removed security settings for VBA macro execution by changing registry values HKCU\Software\Microsoft\Office\<version>\<product>\Security\VBAWarnings and HKCU\Software\Microsoft\Office\<version>\<product>\Security\AccessVBOM. Gamaredon Group has also modified Registry keys to hide folders and system files and to add the C2 address under `HKEY_CURRENT_USER\Console\WindowsUpdate`.

T1112
Modify Registry
GroupOilRig

OilRig has used reg.exe to modify system configuration.

T1112
Modify Registry
GroupAquatic Panda

Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP.

T1112
Modify Registry
GroupSaint Bear

Saint Bear will leverage malicious Windows batch scripts to modify registry values associated with Windows Defender functionality.

T1112
Modify Registry
GroupBlue Mockingbird

Blue Mockingbird has used Windows Registry modifications to specify a DLL payload.

T1112
Modify Registry
GroupTurla

Turla has modified Registry values to store payloads.

T1112
Modify Registry
GroupTA505

TA505 has used malware to disable Windows Defender through modification of the Registry.

T1112
Modify Registry
GroupLotus Blossom

Lotus Blossom has installed tools such as Sagerunex by writing them to the Windows registry.

T1112
Modify Registry
GroupMedusa Group

Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access.

T1112
Modify Registry
GroupEmber Bear

Ember Bear modifies registry values for anti-forensics and defense evasion purposes.

T1112
Modify Registry
GroupLuminousMoth

LuminousMoth has used malware that adds Registry keys for persistence.

T1112
Modify Registry
GroupAPT42

APT42 has modified Registry keys to maintain persistence.

T1112
Modify Registry
GroupEarth Lusca

Earth Lusca modified the registry using the command reg add “HKEY_CURRENT_USER\Environment” /v UserInitMprLogonScript /t REG_SZ /d “[file path]” for persistence.

T1112
Modify Registry
GroupSilence

Silence can create, delete, or modify a specified Registry key or value.

T1112
Modify Registry
GroupWizard Spider

Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest by setting the UseLogonCredential registry value to 1 in order to force credentials to be stored in clear text in memory. Wizard Spider has also modified the WDigest registry key to allow plaintext credentials to be cached in memory.

T1112
Modify Registry
GroupMagic Hound

Magic Hound has modified Registry settings for security tools.

T1112
Modify Registry
GroupThreat Group-3390

A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`.

T1112
Modify Registry
GroupFIN8

FIN8 has deleted Registry keys during post compromise cleanup activities.

T1112
Modify Registry
GroupAPT19

APT19 uses a Port 22 malware variant to modify several Registry keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.