Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1543.003 Windows Service |
GroupTeamTNT | TeamTNT has used malware that adds cryptocurrency miners as a service. |
| T1543.003 Windows Service |
GroupFIN7 | FIN7 created new Windows services and added them to the startup directories for persistence. |
| T1543.003 Windows Service |
GroupOilRig | OilRig has used a compromised Domain Controller to create a service on a remote host. |
| T1543.003 Windows Service |
GroupCarbanak | Carbanak malware installs itself as a service to provide persistence and SYSTEM privileges. |
| T1543.003 Windows Service |
GroupTropic Trooper | Tropic Trooper has installed a service pointing to a malicious DLL dropped to disk. |
| T1543.003 Windows Service |
GroupAquatic Panda | Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change. |
| T1543.003 Windows Service |
GroupKe3chang | Ke3chang backdoor RoyalDNS established persistence through adding a service called |
| T1543.003 Windows Service |
GroupBlue Mockingbird | Blue Mockingbird has made their XMRIG payloads persistent as a Windows Service. |
| T1543.003 Windows Service |
GroupDarkVishnya | DarkVishnya created new services for shellcode loaders distribution. |
| T1543.003 Windows Service |
GroupLotus Blossom | Lotus Blossom has configured tools such as Sagerunex to run as Windows services. |
| T1543.003 Windows Service |
GroupCinnamon Tempest | Cinnamon Tempest has created system services to establish persistence for deployed tooling. |
| T1543.003 Windows Service |
GroupMedusa Group | Medusa Group has used vulnerable or signed drivers to modify security solutions on victim devices. |
| T1543.003 Windows Service |
GroupAgrius | Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence. |
| T1543.003 Windows Service |
GroupLazarus Group | Several Lazarus Group malware families install themselves as new services. |
| T1543.003 Windows Service |
GroupEarth Lusca | Earth Lusca created a service using the command |
| T1543.003 Windows Service |
GroupCobalt Group | Cobalt Group has created new services to establish persistence. |
| T1543.003 Windows Service |
GroupWizard Spider | Wizard Spider has installed TrickBot as a service named ControlServiceA in order to establish persistence. |
| T1543.003 Windows Service |
GroupPROMETHIUM | PROMETHIUM has created new services and modified existing services for persistence. |
| T1543.003 Windows Service |
GroupThreat Group-3390 | Threat Group-3390's malware can create a new service, sometimes naming it after the config information, to gain persistence. |
| T1543.003 Windows Service |
GroupAPT19 | An APT19 Port 22 malware variant registers itself as a service. |
| T1546.001 Change Default File Association |
GroupKimsuky | Kimsuky has a HWP document stealer module which changes the default program association in the registry to open HWP documents. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupMustang Panda | Mustang Panda's custom ORat tool uses a WMI event consumer to maintain persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupLeviathan | Leviathan has used WMI for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupBlue Mockingbird | Blue Mockingbird has used mofcomp.exe to establish WMI Event Subscription persistence mechanisms configured from a *.mof file. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupTurla | Turla has used WMI event filters and consumers to establish persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupAPT29 | APT29 has used WMI event subscriptions for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupMetador | Metador has established persistence through the use of a WMI event subscription combined with unusual living-off-the-land binaries such as `cdb.exe`. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupHEXANE | HEXANE has used WMI event subscriptions for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupRancor | Rancor has complied VBScript-generated MOF files into WMI event subscriptions for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupAPT33 | APT33 has attempted to use WMI event subscriptions to establish persistence on compromised hosts. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupFIN8 | FIN8 has used WMI event subscriptions for persistence. |
| T1546.004 Unix Shell Configuration Modification |
GroupContagious Interview | Contagious Interview has targeted macOS victim hosts using a bash downloader `coremedia.sh` and a bash script `cloud.sh`. |
| T1546.008 Accessibility Features |
GroupAPT3 | APT3 replaces the Sticky Keys binary |
| T1546.008 Accessibility Features |
GroupAPT41 | APT41 leveraged sticky keys to establish persistence. |
| T1546.008 Accessibility Features |
GroupAPT29 | APT29 used sticky-keys to obtain unauthenticated, privileged console access. |
| T1546.008 Accessibility Features |
GroupAxiom | Axiom actors have been known to use the Sticky Keys replacement within RDP sessions to obtain persistence. |
| T1546.008 Accessibility Features |
GroupDeep Panda | Deep Panda has used the sticky-keys technique to bypass the RDP login screen on remote systems during intrusions. |
| T1546.008 Accessibility Features |
GroupFox Kitten | Fox Kitten has used sticky keys to launch a command prompt. |
| T1546.010 AppInit DLLs |
GroupAPT39 | APT39 has used malware to set |
| T1546.011 Application Shimming |
GroupFIN7 | FIN7 has used application shim databases for persistence. |
| T1546.013 PowerShell Profile |
GroupTurla | Turla has used PowerShell profiles to maintain persistence on an infected machine. |
| T1546.015 Component Object Model Hijacking |
GroupAPT28 | APT28 has used COM hijacking for persistence by replacing the legitimate |
| T1546.016 Installer Packages |
GroupTeamPCP | TeamPCP has modified software packages with preinstall scripts to download and execute malicious payloads. |
| T1547 Boot or Logon Autostart Execution |
GroupAPT42 | APT42 has modified the Registry to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupBlackByte | BlackByte has used Registry Run keys for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT3 | APT3 places scripts in the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKimsuky | Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupPatchwork | Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT41 | APT41 created and modified startup files for persistence. APT41 added a registry key in |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDragonfly | Dragonfly has added the registry value ntdll to the Registry Run key to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.