ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1547.004×

10 examples

TechniqueUsed byProcedure example
T1547.004
Winlogon Helper DLL
MalwareKeyBoy

KeyBoy issues the command reg add “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon” to achieve persistence.

T1547.004
Winlogon Helper DLL
MalwareDarkTortilla

DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Winlogon` registry key.

T1547.004
Winlogon Helper DLL
MalwareLockBit 3.0

LockBit 3.0 can enable automatic logon through the `SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon` Registry key.

T1547.004
Winlogon Helper DLL
MalwareGazer

Gazer can establish persistence by setting the value “Shell” with “explorer.exe, %malware_pathfile%” under the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1547.004
Winlogon Helper DLL
MalwareBazar

Bazar can use Winlogon Helper DLL to establish persistence.

T1547.004
Winlogon Helper DLL
MalwareRevenge RAT

Revenge RAT creates a Registry key at HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell to survive a system reboot.

T1547.004
Winlogon Helper DLL
MalwareCannon

Cannon adds the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon to establish persistence.

T1547.004
Winlogon Helper DLL
MalwareDipsind

A Dipsind variant registers as a Winlogon Event Notify DLL to establish persistence.

T1547.004
Winlogon Helper DLL
MalwareQilin

Qilin can configure a Winlogon registry entry.

T1547.004
Winlogon Helper DLL
MalwareRemexi

Remexi achieves persistence using Userinit by adding the Registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.