Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.011 Fileless Storage |
MalwarePikabot | Some versions of Pikabot build the final PE payload in memory to avoid writing contents to disk on the executing machine. |
| T1027.011 Fileless Storage |
MalwareRCSession | RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`. |
| T1027.011 Fileless Storage |
MalwareExaramel for Windows | Exaramel for Windows stores the backdoor's configuration in the Registry in XML format. |
| T1027.011 Fileless Storage |
MalwareThreatNeedle | ThreatNeedle can save its configuration data as a RC4-encrypted Registry key under `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`. |
| T1027.011 Fileless Storage |
MalwareNETWIRE | NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`. |
| T1027.011 Fileless Storage |
MalwareTinyTurla | TinyTurla can save its configuration parameters in the Registry. |
| T1027.011 Fileless Storage |
MalwarePolyglotDuke | PolyglotDuke can store encrypted JSON configuration files in the Registry. |
| T1027.011 Fileless Storage |
MalwareRegDuke | RegDuke can store its encryption key in the Registry. |
| T1027.011 Fileless Storage |
MalwareVolgmer | Volgmer stores an encoded configuration file in |
| T1027.011 Fileless Storage |
MalwareDarkWatchman | DarkWatchman can store configuration strings, keylogger, and output of components in the Registry. |
| T1027.011 Fileless Storage |
MalwareChaes | Some versions of Chaes stored its instructions (otherwise in a `instructions.ini` file) in the Registry. |
| T1027.011 Fileless Storage |
MalwareTYPEFRAME | TYPEFRAME can install and store encrypted configuration data under the Registry key |
| T1027.011 Fileless Storage |
MalwareQUADAGENT | QUADAGENT stores a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications within a Registry key (such as `HKCU\Office365DCOMCheck`) in the `HKCU` hive. |
| T1027.011 Fileless Storage |
MalwareUroburos | Uroburos can store configuration information for the kernel driver and kernel driver loader components in an encrypted blob typically found at `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds.` |
| T1027.011 Fileless Storage |
MalwarePipeMon | PipeMon has stored its encrypted payload in the Registry under `HKLM\SOFTWARE\Microsoft\Print\Components\`. |
| T1027.011 Fileless Storage |
MalwareMosquito | Mosquito stores configuration values under the Registry key |
| T1027.011 Fileless Storage |
MalwareGrandoreiro | Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including |
| T1027.011 Fileless Storage |
MalwareSibot | Sibot has installed a second-stage script in the |
| T1027.011 Fileless Storage |
MalwareREvil | REvil can save encryption parameters and system information in the Registry. |
| T1027.011 Fileless Storage |
MalwareValak | Valak has the ability to store information regarding the C2 server and downloads in the Registry key |
| T1027.011 Fileless Storage |
MalwarePillowmint | Pillowmint has stored a compressed payload in the Registry key |
| T1027.011 Fileless Storage |
MalwareSysUpdate | SysUpdate can store its encoded configuration file within |
| T1027.011 Fileless Storage |
MalwareCHOPSTICK | CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry. |
| T1027.011 Fileless Storage |
MalwareComRAT | ComRAT has stored encrypted orchestrator code and payloads in the Registry. |
| T1027.011 Fileless Storage |
MalwareShadowPad | ShadowPad maintains a configuration block and virtual file system in the Registry. |
| T1027.011 Fileless Storage |
MalwareQakBot | QakBot can store its configuration information in a randomly named subkey under |
| T1027.011 Fileless Storage |
MalwareGelsemium | Gelsemium can store its components in the Registry. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.