ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1112×

139 examples

TechniqueUsed byProcedure example
T1112
Modify Registry
MalwareTrickBot

TrickBot can modify registry entries.

T1112
Modify Registry
MalwareRCSession

RCSession can write its configuration file to the Registry.

T1112
Modify Registry
MalwareSynAck

SynAck can manipulate Registry keys.

T1112
Modify Registry
MalwareExaramel for Windows

Exaramel for Windows adds the configuration to the Registry in XML format.

T1112
Modify Registry
MalwareAmadey

Amadey has overwritten registry keys for persistence.

T1112
Modify Registry
MalwareOrz

Orz can perform Registry operations.

T1112
Modify Registry
MalwareStuxnet

Stuxnet can create registry keys to load driver files.

T1112
Modify Registry
MalwareKEYMARBLE

KEYMARBLE has a command to create Registry entries for storing data under HKEY_CURRENT_USER\SOFTWARE\Microsoft\WABE\DataPath.

T1112
Modify Registry
MalwareUrsnif

Ursnif has used Registry modifications as part of its installation routine.

T1112
Modify Registry
MalwareThreatNeedle

ThreatNeedle can modify the Registry to save its configuration data as the following RC4-encrypted Registry key: `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`.

T1112
Modify Registry
MalwareZeus Panda

Zeus Panda modifies several Registry keys under HKCU\Software\Microsoft\Internet Explorer\ PhishingFilter\ to disable phishing filters.

T1112
Modify Registry
MalwarePrestige

Prestige has the ability to register new registry keys for a new extension handler via `HKCR\.enc` and `HKCR\enc\shell\open\command`.

T1112
Modify Registry
MalwareBankshot

Bankshot writes data into the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Pniumj.

T1112
Modify Registry
MalwarePLAINTEE

PLAINTEE uses reg add to add a Registry Run key for persistence.

T1112
Modify Registry
MalwareNETWIRE

NETWIRE can modify the Registry to store its configuration information.

T1112
Modify Registry
MalwareTinyTurla

TinyTurla can set its configuration parameters in the Registry.

T1112
Modify Registry
MalwareBOOKWORM

BOOKWORM has modified Registry key values as part of its created service `DeviceSync`.

T1112
Modify Registry
MalwareHyperStack

HyperStack can add the name of its communication pipe to HKLM\SYSTEM\\CurrentControlSet\\Services\\lanmanserver\\parameters\NullSessionPipes.

T1112
Modify Registry
MalwareGreyEnergy

GreyEnergy modifies conditions in the Registry and adds keys.

T1112
Modify Registry
MalwareCrimson

Crimson can set a Registry key to determine how long it has been installed and possibly to indicate the version number.

T1112
Modify Registry
MalwareTEARDROP

TEARDROP modified the Registry to create a Windows service for itself on a compromised host.

T1112
Modify Registry
MalwareMafalda

Mafalda can manipulate the system registry on a compromised host.

T1112
Modify Registry
MalwarePolyglotDuke

PolyglotDuke can write encrypted JSON configuration files to the Registry.

T1112
Modify Registry
MalwareShrinkLocker

ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption.

T1112
Modify Registry
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware modifies the victim Registry to allow for elevated execution.

T1112
Modify Registry
MalwareHOPLIGHT

HOPLIGHT has modified Managed Object Format (MOF) files within the Registry to run specific commands and create persistence on the system.

T1112
Modify Registry
MalwareWastedLocker

WastedLocker can modify registry values within the Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap registry key.

T1112
Modify Registry
MalwareRegDuke

RegDuke can create seemingly legitimate Registry key to store its encryption key.

T1112
Modify Registry
MalwareInvisiMole

InvisiMole has a command to create, set, copy, or delete a specified Registry key or value.

T1112
Modify Registry
MalwareNaid

Naid creates Registry entries that store information about a created service and point to a malicious DLL dropped to disk.

T1112
Modify Registry
MalwareVolgmer

Volgmer modifies the Registry to store an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1112
Modify Registry
MalwareTRANSLATEXT

TRANSLATEXT has modified the following registry key to install itself as the value, granting permission to install specified extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist`.

T1112
Modify Registry
MalwareRegin

Regin appears to have functionality to modify remote Registry information.

T1112
Modify Registry
MalwareNeoichor

Neoichor has the ability to configure browser settings by modifying Registry entries under `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer`.

T1112
Modify Registry
MalwareBlackCat

BlackCat has the ability to add the following registry key on compromised networks to maintain persistence: `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services \LanmanServer\Paramenters`

T1112
Modify Registry
MalwarePowerShower

PowerShower has added a registry key so future powershell.exe instances are spawned off-screen by default, and has removed all registry entries that are left behind during the dropper process.

T1112
Modify Registry
MalwareDarkComet

DarkComet adds a Registry value for its installation routine to the Registry Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System Enable LUA=”0” and HKEY_CURRENT_USER\Software\DC3_FEXEC.

T1112
Modify Registry
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use the Windows Registry Environment key to change the `%windir%` variable to point to `c:\Windows` to enable payload execution.

T1112
Modify Registry
MalwarezwShell

zwShell can modify the Registry.

T1112
Modify Registry
MalwareDCSrv

DCSrv has created Registry keys for persistence.

T1112
Modify Registry
MalwareShimRat

ShimRat has registered two registry keys for shim databases.

T1112
Modify Registry
MalwareAvaddon

Avaddon modifies several registry keys for persistence and UAC bypass.

T1112
Modify Registry
MalwareConficker

Conficker adds keys to the Registry at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services and various other Registry locations.

T1112
Modify Registry
MalwareDarkTortilla

DarkTortilla has modified registry keys for persistence.

T1112
Modify Registry
MalwareROKRAT

ROKRAT can modify the `HKEY_CURRENT_USER\Software\Microsoft\Office\` registry key so it can bypass the VB object model (VBOM) on a compromised host.

T1112
Modify Registry
MalwareDarkWatchman

DarkWatchman can modify Registry values to store configuration strings, keylogger, and output of components.

T1112
Modify Registry
MalwarePlugX

PlugX has a module to create, delete, or modify Registry keys.

T1112
Modify Registry
MalwareBisonal

Bisonal has deleted Registry keys to clean up its prior activity.

T1112
Modify Registry
MalwareNOOPLDR

NOOPLDR can store its payload in the Registry using a random hex string in `HKCU\SOFTWARE\Microsoft\COM3`.

T1112
Modify Registry
MalwareExplosive

Explosive has a function to write itself to Registry values.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.