At

T1053.002

Sub-technique of T1053 Scheduled Task/Job.View on attack.mitre.org

About this technique

Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at utility exists as an executable within Windows, Linux, and macOS for scheduling tasks at a specified time and date. Although deprecated in favor of Scheduled Task's schtasks in Windows environments, using at requires that the Task Scheduler service be running, and the user to be logged on as a member of the local Administrators group. In addition to explicitly running the `at` command, adversaries may also schedule a task with at by directly leveraging the Windows Management Instrumentation `Win32_ScheduledJob` WMI class.

On Linux and macOS, at may be invoked by the superuser as well as any users added to the at.allow file. If the at.allow file does not exist, the at.deny file is checked. Every username not listed in at.deny is allowed to invoke at. If the at.deny exists and is empty, global use of at is permitted. If neither file exists (which is often the baseline) only the superuser is allowed to use at.

Adversaries may use at to execute programs at system startup or on a scheduled basis for Persistence. at can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM).

In Linux environments, adversaries may also abuse at to break out of restricted environments by using a task to spawn an interactive system shell or to run system commands. Similarly, at may also be used for Privilege Escalation if the binary is allowed to run as superuser via sudo.

Detection rules12

Rules on DetectionCode tagged with T1053.002.

Sigma8

RuleLevelLog source
Interactive AT Jobhighwindows / process_creation
Remote Schedule Task Lateral Movement via ATSvchighrpc_firewall / application
Remote Schedule Task Lateral Movement via ITaskSchedulerServicehighrpc_firewall / application
Remote Schedule Task Lateral Movement via SASechighrpc_firewall / application
MITRE BZAR Indicators for Executionmediumzeek / NULL
Remote Task Creation via ATSVC Named Pipemediumwindows / NULL
Remote Task Creation via ATSVC Named Pipe - Zeekmediumzeek / NULL
Scheduled Task/Job Atlowlinux / process_creation

Splunk4

RuleTypeRiskData source
Linux At Application ExecutionAnomalyNULLSysmon for Linux EventID 1
Linux Auditd At Application ExecutionAnomalyNULLLinux Auditd Syscall
Linux Possible Append Command To At Allow Config FileAnomalyNULLSysmon for Linux EventID 1
Scheduled Task Creation on Remote Endpoint using AtTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups3

Software3

Campaigns0

None recorded.

Procedure examples6

Groups3

Used byProcedure example
GroupAPT18

APT18 actors used the native at Windows task scheduler tool to use scheduled tasks for execution on a victim network.

GroupBRONZE BUTLER

BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement.

GroupThreat Group-3390

Threat Group-3390 actors use at to schedule tasks to run self-extracting RAR archives, which install HTTPBrowser or PlugX on other victims on a network.

Software3

Used byProcedure example
Toolat

at can be used to schedule a task on a system to be executed at a specific date or time.

ToolCrackMapExec

CrackMapExec can set a scheduled task on the target system to execute commands remotely using at.

MalwareMURKYTOP

MURKYTOP has the capability to schedule remote AT jobs.

References3

  1. GTFObins at Open source
    Emilio Pinna, Andrea Cardaci. (n.d.). gtfobins at. Retrieved September 28, 2021.
  2. Linux at Open source
    IEEE/The Open Group. (2017). at(1p) — Linux manual page. Retrieved February 25, 2022.
  3. Malicious Life by Cybereason Open source
    Philip Tsukerman. (n.d.). No Win32 Process Needed | Expanding the WMI Lateral Movement Arsenal. Retrieved June 19, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.