Logon Script (Windows)

T1037.001

Sub-technique of T1037 Boot or Logon Initialization Scripts.View on attack.mitre.org

About this technique

Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence. Windows allows logon scripts to be run whenever a specific user or group of users log into a system. This is done via adding a path to a script to the HKCU\Environment\UserInitMprLogonScript Registry key.

Adversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary.

Detection rules4

Rules on DetectionCode tagged with T1037.001.

Sigma3

RuleLevelLog source
Potential Persistence Via Logon Scripts - CommandLinehighwindows / process_creation
Uncommon Userinit Child Processhighwindows / process_creation
Potential Persistence Via Logon Scripts - Registrymediumwindows / registry_set

Splunk1

RuleTypeRiskData source
Logon Script Event Trigger ExecutionTTPNULLSysmon EventID 13

Groups2

Software4

Campaigns0

None recorded.

Procedure examples6

Groups2

Used byProcedure example
GroupAPT28

An APT28 loader Trojan adds the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

GroupCobalt Group

Cobalt Group has added persistence by registering the file name for the next stage malware under HKCU\Environment\UserInitMprLogonScript.

Software4

Used byProcedure example
MalwareAttor

Attor's dispatcher can establish persistence via adding a Registry key with a logon script HKEY_CURRENT_USER\Environment "UserInitMprLogonScript" .

MalwareJHUHUGIT

JHUHUGIT has registered a Windows shell script under the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

MalwareKGH_SPY

KGH_SPY has the ability to set the HKCU\Environment\UserInitMprLogonScript Registry key to execute logon scripts.

MalwareZebrocy

Zebrocy performs persistence with a logon script via adding to the Registry key HKCU\Environment\UserInitMprLogonScript.

References2

  1. Hexacorn Logon Scripts Open source
    Hexacorn. (2014, November 14). Beyond good ol’ Run key, Part 18. Retrieved November 15, 2019.
  2. TechNet Logon Scripts Open source
    Microsoft. (2005, January 21). Creating logon scripts. Retrieved April 27, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.