Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.009 Shortcut Modification |
MalwareRedLeaves | RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. |
| T1547.009 Shortcut Modification |
MalwareSslMM | To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1547.009 Shortcut Modification |
MalwareInvisiMole | InvisiMole can use a .lnk shortcut for the Control Panel to establish persistence. |
| T1547.009 Shortcut Modification |
MalwareOkrum | Okrum can establish persistence by creating a .lnk shortcut to itself in the Startup folder. |
| T1547.009 Shortcut Modification |
MalwareMarkiRAT | MarkiRAT can modify the shortcut that launches Telegram by replacing its path with the malicious payload to launch with the legitimate executable. |
| T1547.009 Shortcut Modification |
MalwareKazuar | Kazuar adds a .lnk file to the Windows startup folder. |
| T1547.009 Shortcut Modification |
MalwareBlackEnergy | The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder. |
| T1547.009 Shortcut Modification |
MalwareReaver | Reaver creates a shortcut file and saves it in a Startup folder to establish persistence. |
| T1547.009 Shortcut Modification |
MalwareS-Type | S-Type may create the file |
| T1547.009 Shortcut Modification |
MalwareSeaDuke | SeaDuke is capable of persisting via a .lnk file stored in the Startup directory. |
| T1547.009 Shortcut Modification |
MalwareGazer | Gazer can establish persistence by creating a .lnk file in the Start menu or by modifying existing .lnk files to execute the malware through cmd.exe. |
| T1547.009 Shortcut Modification |
MalwareKONNI | A version of KONNI drops a Windows shortcut on the victim’s machine to establish persistence. |
| T1547.009 Shortcut Modification |
MalwareSPACESHIP | SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder. |
| T1547.009 Shortcut Modification |
MalwareMicropsia | Micropsia creates a shortcut to maintain persistence. |
| T1547.009 Shortcut Modification |
MalwareRogueRobin | RogueRobin establishes persistence by creating a shortcut (.LNK file) in the Windows startup folder to run a script each time the user logs in. |
| T1547.009 Shortcut Modification |
MalwareGrandoreiro | Grandoreiro can write or modify browser shortcuts to enable launching of malicious browser extensions. |
| T1547.009 Shortcut Modification |
MalwareBazar | Bazar can establish persistence by writing shortcuts to the Windows Startup folder. |
| T1547.009 Shortcut Modification |
MalwareSHIPSHAPE | SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder. |
| T1547.009 Shortcut Modification |
MalwareTinyZBot | TinyZBot can create a shortcut in the Windows startup folder for persistence. |
| T1547.009 Shortcut Modification |
MalwareFELIXROOT | FELIXROOT creates a .LNK file for persistence. |
| T1547.009 Shortcut Modification |
MalwareAstaroth | Astaroth's initial payload is a malicious .LNK file. |
| T1547.009 Shortcut Modification |
MalwareHelminth | Helminth establishes persistence by creating a shortcut. |
| T1547.009 Shortcut Modification |
MalwareComnie | Comnie establishes persistence via a .lnk file in the victim’s startup path. |
| T1547.009 Shortcut Modification |
MalwareBACKSPACE | BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory. |
| T1547.009 Shortcut Modification |
ToolEmpire | Empire can persist by modifying a .LNK file to include a backdoor. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.