Print Processors

T1547.012

Sub-technique of T1547 Boot or Logon Autostart Execution.View on attack.mitre.org

About this technique

Adversaries may abuse print processors to run malicious DLLs during system boot for persistence and/or privilege escalation. Print processors are DLLs that are loaded by the print spooler service, `spoolsv.exe`, during boot.

Adversaries may abuse the print spooler service by adding print processors that load malicious DLLs at startup. A print processor can be installed through the AddPrintProcessor API call with an account that has SeLoadDriverPrivilege enabled. Alternatively, a print processor can be registered to the print spooler service by adding the HKLM\SYSTEM\\[CurrentControlSet or ControlSet001]\Control\Print\Environments\\[Windows architecture: e.g., Windows x64]\Print Processors\\[user defined]\Driver Registry key that points to the DLL.

For the malicious print processor to be correctly installed, the payload must be located in the dedicated system print-processor directory, that can be found with the GetPrintProcessorDirectory API call, or referenced via a relative path from this directory. After the print processors are installed, the print spooler service, which starts during boot, must be restarted in order for them to run.

The print spooler service runs under SYSTEM level permissions, therefore print processors installed by an adversary may run under elevated privileges.

Detection rules7

Rules on DetectionCode tagged with T1547.012.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk7

RuleTypeRiskData source
Print Processor Registry AutostartTTPNULLSysmon EventID 13
Print Spooler Adding A Printer DriverTTPNULLWindows Event Log Printservice 316
Print Spooler Failed to Load a Plug-inTTPNULLWindows Event Log Printservice 808, Windows Event Log Printservice 4909
Spoolsv Spawning Rundll32TTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Spoolsv Suspicious Loaded ModulesTTPNULLSysmon EventID 7
Spoolsv Writing a DLLTTPNULLSysmon EventID 1 AND Sysmon EventID 11, Windows Event Log Security 4688 AND Sysmon EventID 11
Spoolsv Writing a DLL - SysmonTTPNULLSysmon EventID 11

Groups1

Software2

Campaigns0

None recorded.

Procedure examples3

Groups1

Used byProcedure example
GroupEarth Lusca

Earth Lusca has added the Registry key `HKLM\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Print Processors\UDPrint” /v Driver /d “spool.dll /f` to load malware as a Print Processor.

Software2

Used byProcedure example
MalwareGelsemium

Gelsemium can drop itself in C:\Windows\System32\spool\prtprocs\x64\winprint.dll to be loaded automatically by the spoolsv Windows service.

MalwarePipeMon

The PipeMon installer has modified the Registry key HKLM\SYSTEM\CurrentControlSet\Control\Print\Environments\Windows x64\Print Processors to install PipeMon as a Print Processor.

References3

  1. ESET PipeMon May 2020 Open source
    Tartare, M. et al. (2020, May 21). No “Game over” for the Winnti Group. Retrieved August 24, 2020.
  2. Microsoft AddPrintProcessor May 2018 Open source
    Microsoft. (2018, May 31). AddPrintProcessor function. Retrieved October 5, 2020.
  3. Microsoft Intro Print Processors Open source
    Microsoft. (2023, June 26). Introduction to print processors. Retrieved September 27, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.