ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.011×

27 examples

TechniqueUsed byProcedure example
T1027.011
Fileless Storage
MalwarePikabot

Some versions of Pikabot build the final PE payload in memory to avoid writing contents to disk on the executing machine.

T1027.011
Fileless Storage
MalwareRCSession

RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`.

T1027.011
Fileless Storage
MalwareExaramel for Windows

Exaramel for Windows stores the backdoor's configuration in the Registry in XML format.

T1027.011
Fileless Storage
MalwareThreatNeedle

ThreatNeedle can save its configuration data as a RC4-encrypted Registry key under `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`.

T1027.011
Fileless Storage
MalwareNETWIRE

NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`.

T1027.011
Fileless Storage
MalwareTinyTurla

TinyTurla can save its configuration parameters in the Registry.

T1027.011
Fileless Storage
MalwarePolyglotDuke

PolyglotDuke can store encrypted JSON configuration files in the Registry.

T1027.011
Fileless Storage
MalwareRegDuke

RegDuke can store its encryption key in the Registry.

T1027.011
Fileless Storage
MalwareVolgmer

Volgmer stores an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1027.011
Fileless Storage
MalwareDarkWatchman

DarkWatchman can store configuration strings, keylogger, and output of components in the Registry.

T1027.011
Fileless Storage
MalwareChaes

Some versions of Chaes stored its instructions (otherwise in a `instructions.ini` file) in the Registry.

T1027.011
Fileless Storage
MalwareTYPEFRAME

TYPEFRAME can install and store encrypted configuration data under the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\laxhost.dll and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PrintConfigs.

T1027.011
Fileless Storage
MalwareQUADAGENT

QUADAGENT stores a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications within a Registry key (such as `HKCU\Office365DCOMCheck`) in the `HKCU` hive.

T1027.011
Fileless Storage
MalwareUroburos

Uroburos can store configuration information for the kernel driver and kernel driver loader components in an encrypted blob typically found at `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds.`

T1027.011
Fileless Storage
MalwarePipeMon

PipeMon has stored its encrypted payload in the Registry under `HKLM\SOFTWARE\Microsoft\Print\Components\`.

T1027.011
Fileless Storage
MalwareMosquito

Mosquito stores configuration values under the Registry key HKCU\Software\Microsoft\[dllname].

T1027.011
Fileless Storage
MalwareGrandoreiro

Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including %USERNAME% and ToolTech-RM.

T1027.011
Fileless Storage
MalwareSibot

Sibot has installed a second-stage script in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot registry key.

T1027.011
Fileless Storage
MalwareREvil

REvil can save encryption parameters and system information in the Registry.

T1027.011
Fileless Storage
MalwareValak

Valak has the ability to store information regarding the C2 server and downloads in the Registry key HKCU\Software\ApplicationContainer\Appsw64.

T1027.011
Fileless Storage
MalwarePillowmint

Pillowmint has stored a compressed payload in the Registry key HKLM\SOFTWARE\Microsoft\DRM.

T1027.011
Fileless Storage
MalwareSysUpdate

SysUpdate can store its encoded configuration file within Software\Classes\scConfig in either HKEY_LOCAL_MACHINE or HKEY_CURRENT_USER.

T1027.011
Fileless Storage
MalwareCHOPSTICK

CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry.

T1027.011
Fileless Storage
MalwareComRAT

ComRAT has stored encrypted orchestrator code and payloads in the Registry.

T1027.011
Fileless Storage
MalwareShadowPad

ShadowPad maintains a configuration block and virtual file system in the Registry.

T1027.011
Fileless Storage
MalwareQakBot

QakBot can store its configuration information in a randomly named subkey under HKCU\Software\Microsoft.

T1027.011
Fileless Storage
MalwareGelsemium

Gelsemium can store its components in the Registry.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.