Boot or Logon Initialization Scripts

T1037

Technique with 5 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence. Initialization scripts can be used to perform administrative functions, which may often execute other programs or send information to an internal logging server. These scripts can vary based on operating system and whether applied locally or remotely.

Adversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary.

An adversary may also be able to escalate their privileges since some boot or logon initialization scripts run with higher privileges.

Detection rules11

Rules on DetectionCode tagged with T1037 or one of its sub-techniques.

Sigma4

RuleLevelLog sourceTechnique
Potential Persistence Via Logon Scripts - CommandLinehighwindows / process_creationT1037.001
Uncommon Userinit Child Processhighwindows / process_creationT1037.001
Potential Persistence Via Logon Scripts - Registrymediumwindows / registry_setT1037.001
Startup Item File Created - MacOSlowmacos / file_eventT1037.005

Splunk7

RuleTypeRiskData sourceTechnique
Linux File Creation In Init Boot DirectoryAnomalyNULLSysmon for Linux EventID 11T1037.004
Linux File Creation In System Generator DirectoryAnomalyNULLSysmon for Linux EventID 11T1037.005
Linux MOTD Script AddedAnomalyNULLSysmon for Linux EventID 11T1037
Linux Suspicious XDG AutostartAnomalyNULLSysmon for Linux EventID 11T1037
Linux UDEV Rule CreatedAnomalyNULLSysmon for Linux EventID 11T1037
Logon Script Event Trigger ExecutionTTPNULLSysmon EventID 13T1037.001
MacOS LoginHook PersistenceTTPNULLOsquery ResultsT1037.002

Sub-techniques5

IDNameExamples
T1037.001Logon Script (Windows)6
T1037.002Login Hook0
T1037.003Network Logon Script0
T1037.004RC Scripts7
T1037.005Startup Items1

Groups4

Software3

Campaigns1

Procedure examples8

Groups4

Used byProcedure example
GroupAPT29

APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup.

GroupAPT41

APT41 used a hidden shell script in `/etc/rc.d/init.d` to leverage the `ADORE.XSEC`backdoor and `Adore-NG` rootkit.

GroupRocke

Rocke has installed an "init.d" startup script to maintain persistence.

GroupUNC3886

UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices.

Software3

Used byProcedure example
MalwareRotaJakiro

Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.conf` file in the `/etc/init/` folder.

MalwareSPAWNCHIMERA

SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence.

MalwareVIRTUALPITA

VIRTUALPITA can persist as an init.d startup service on Linux vCenter systems.

Campaigns1

Used byProcedure example
CampaignArcaneDoor

ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices.

References2

  1. Anomali Rocke March 2019 Open source
    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.
  2. Mandiant APT29 Eye Spy Email Nov 22 Open source
    Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.