Real-world descriptions of how a group, tool or campaign used a technique.
29 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1112 Modify Registry |
GroupAPT38 | APT38 uses a tool called CLEANTOAD that has the capability to modify Registry keys. |
| T1112 Modify Registry |
GroupIndrik Spider | Indrik Spider has modified registry keys to prepare for ransomware execution and to disable common administrative utilities. |
| T1112 Modify Registry |
GroupBlackByte | BlackByte performed Registry modifications to escalate privileges and disable security tools. |
| T1112 Modify Registry |
GroupKimsuky | Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck. |
| T1112 Modify Registry |
GroupVolt Typhoon | Volt Typhoon has used `netsh` to create a PortProxy Registry modification on a compromised server running the Paessler Router Traffic Grapher (PRTG). |
| T1112 Modify Registry |
GroupPatchwork | A Patchwork payload deletes Resiliency Registry keys created by Microsoft Office applications in an apparent effort to trick users into thinking there were no issues during application runs. |
| T1112 Modify Registry |
GroupAPT41 | APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials. |
| T1112 Modify Registry |
GroupDragonfly | Dragonfly has modified the Registry to perform multiple techniques through the use of Reg. |
| T1112 Modify Registry |
GroupGorgon Group | Gorgon Group malware can deactivate security mechanisms in Microsoft Office by editing several keys and values under |
| T1112 Modify Registry |
GroupAPT32 | APT32's backdoor has modified the Windows Registry to store the backdoor's configuration. |
| T1112 Modify Registry |
GroupGamaredon Group | Gamaredon Group has removed security settings for VBA macro execution by changing registry values |
| T1112 Modify Registry |
GroupOilRig | OilRig has used reg.exe to modify system configuration. |
| T1112 Modify Registry |
GroupAquatic Panda | Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP. |
| T1112 Modify Registry |
GroupSaint Bear | Saint Bear will leverage malicious Windows batch scripts to modify registry values associated with Windows Defender functionality. |
| T1112 Modify Registry |
GroupBlue Mockingbird | Blue Mockingbird has used Windows Registry modifications to specify a DLL payload. |
| T1112 Modify Registry |
GroupTurla | Turla has modified Registry values to store payloads. |
| T1112 Modify Registry |
GroupTA505 | TA505 has used malware to disable Windows Defender through modification of the Registry. |
| T1112 Modify Registry |
GroupLotus Blossom | Lotus Blossom has installed tools such as Sagerunex by writing them to the Windows registry. |
| T1112 Modify Registry |
GroupMedusa Group | Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access. |
| T1112 Modify Registry |
GroupEmber Bear | Ember Bear modifies registry values for anti-forensics and defense evasion purposes. |
| T1112 Modify Registry |
GroupLuminousMoth | LuminousMoth has used malware that adds Registry keys for persistence. |
| T1112 Modify Registry |
GroupAPT42 | APT42 has modified Registry keys to maintain persistence. |
| T1112 Modify Registry |
GroupEarth Lusca | Earth Lusca modified the registry using the command |
| T1112 Modify Registry |
GroupSilence | Silence can create, delete, or modify a specified Registry key or value. |
| T1112 Modify Registry |
GroupWizard Spider | Wizard Spider has modified the Registry key |
| T1112 Modify Registry |
GroupMagic Hound | Magic Hound has modified Registry settings for security tools. |
| T1112 Modify Registry |
GroupThreat Group-3390 | A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`. |
| T1112 Modify Registry |
GroupFIN8 | FIN8 has deleted Registry keys during post compromise cleanup activities. |
| T1112 Modify Registry |
GroupAPT19 | APT19 uses a Port 22 malware variant to modify several Registry keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.