Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.004 Winlogon Helper DLL |
MalwareKeyBoy | KeyBoy issues the command |
| T1547.004 Winlogon Helper DLL |
MalwareDarkTortilla | DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Winlogon` registry key. |
| T1547.004 Winlogon Helper DLL |
MalwareLockBit 3.0 | LockBit 3.0 can enable automatic logon through the `SOFTWARE\Microsoft\Windows |
| T1547.004 Winlogon Helper DLL |
MalwareGazer | Gazer can establish persistence by setting the value “Shell” with “explorer.exe, %malware_pathfile%” under the Registry key |
| T1547.004 Winlogon Helper DLL |
MalwareBazar | Bazar can use Winlogon Helper DLL to establish persistence. |
| T1547.004 Winlogon Helper DLL |
MalwareRevenge RAT | Revenge RAT creates a Registry key at |
| T1547.004 Winlogon Helper DLL |
MalwareCannon | Cannon adds the Registry key |
| T1547.004 Winlogon Helper DLL |
MalwareDipsind | A Dipsind variant registers as a Winlogon Event Notify DLL to establish persistence. |
| T1547.004 Winlogon Helper DLL |
MalwareQilin | Qilin can configure a Winlogon registry entry. |
| T1547.004 Winlogon Helper DLL |
MalwareRemexi | Remexi achieves persistence using Userinit by adding the Registry key |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.