Real-world descriptions of how a group, tool or campaign used a technique.
57 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
GroupBlackByte | BlackByte has used Registry Run keys for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT3 | APT3 places scripts in the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKimsuky | Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupPatchwork | Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT41 | APT41 created and modified startup files for persistence. APT41 added a registry key in |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDragonfly | Dragonfly has added the registry value ntdll to the Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupGorgon Group | Gorgon Group malware can create a .lnk file and add a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT32 | APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMuddyWater | MuddyWater has added Registry Run key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupNaikon | Naikon has modified a victim's Windows Run registry to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN6 | FIN6 has used Registry Run keys to establish persistence for its downloader tools known as HARDTACK and SHIPBREAD. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupGamaredon Group | Gamaredon Group tools have registered Run keys in the registry to give malicious VBS files persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupStorm-1811 | Storm-1811 has created Windows Registry Run keys that execute various batch scripts to establish persistence on victim devices. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTeamTNT | TeamTNT has added batch scripts to the startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN7 | FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT18 | APT18 establishes persistence via the |
| T1547.001 Registry Run Keys / Startup Folder |
GroupSidewinder | Sidewinder has added paths to executables in the Registry to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMustang Panda | Mustang Panda has created the registry key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupZIRCONIUM | ZIRCONIUM has created a Registry Run key named |
| T1547.001 Registry Run Keys / Startup Folder |
GroupRocke | Rocke's miner has created UPX-packed files in the Windows Start Menu Folder. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT39 | APT39 has maintained persistence using the startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupContagious Interview | Contagious Interview has established persistence using InvisibleFerret malware to place a .bat file in the Startup Folder. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTA2541 | TA2541 has placed VBS files in the Startup folder and used Registry run keys to establish persistence for malicious payloads. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT37 | APT37's has added persistence via the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupHigaisa | Higaisa added a spoofed binary to the start-up folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTropic Trooper | Tropic Trooper has created shortcuts in the Startup folder to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupPutter Panda | A dropper used by Putter Panda installs itself into the ASEP Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKe3chang | Several Ke3chang backdoors achieved persistence by adding a Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupConfucius | Confucius has dropped malicious files into the startup folder `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` on a compromised host in order to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLeviathan | Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTurla | A Turla Javascript backdoor added a local_update_check value under the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupRedCurl | RedCurl has established persistence by creating entries in `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT29 | APT29 added Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDark Caracal | Dark Caracal's version of Bandook adds a registry key to |
| T1547.001 Registry Run Keys / Startup Folder |
GroupBRONZE BUTLER | BRONZE BUTLER has used a batch script that adds a Registry Run key to establish malware persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDarkhotel | Darkhotel has been known to establish persistence by adding programs to the Run Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLazyScripter | LazyScripter has achieved persistence via writing a PowerShell script to the autorun registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupWindshift | Windshift has created LNK files in the Startup folder to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLuminousMoth | LuminousMoth has used malicious DLLs that setup persistence in the Registry Key `HKCU\Software\Microsoft\Windows\Current Version\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT28 | APT28 has deployed malware that has copied itself to the startup directory for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupRTM | RTM has used Registry run keys to establish persistence for the RTM Trojan and other tools, such as a modified version of TeamViewer remote desktop software. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLazarus Group | Lazarus Group has maintained persistence by loading malicious code into a startup folder or by adding a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupSilence | Silence has used |
| T1547.001 Registry Run Keys / Startup Folder |
GroupCobalt Group | Cobalt Group has used Registry Run keys for persistence. The group has also set a Startup path to launch the PowerShell shell command and download Cobalt Strike. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupWizard Spider | Wizard Spider has established persistence via the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMolerats | Molerats saved malicious files within the AppData and Startup folders to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMoonstone Sleet | Moonstone Sleet used registry run keys for process execution during initial victim infection. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupInception | Inception has maintained persistence by modifying Registry run key value |
| T1547.001 Registry Run Keys / Startup Folder |
GroupVOID MANTICORE | VOID MANTICORE has created Windows Registry entries to autorun stage two malware payloads to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupPROMETHIUM | PROMETHIUM has used Registry run keys to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.