Sub-technique of T1053 Scheduled Task/Job.View on attack.mitre.org
Adversaries may abuse the cron utility to perform task scheduling for initial or recurring execution of malicious code. The cron utility is a time-based job scheduler for Unix-like operating systems. The crontab file contains the schedule of cron entries to be run and the specified times for execution. Any crontab files are stored in operating system-specific file paths.
An adversary may use cron in Linux or Unix environments to execute programs at system startup or on a scheduled basis for Persistence. In ESXi environments, cron jobs must be created directly via the crontab file (e.g., `/var/spool/cron/crontabs/root`).
Rules on DetectionCode tagged with T1053.003.
| Rule | Level | Log source |
|---|---|---|
| Triple Cross eBPF Rootkit Default Persistence | high | linux / file_event |
| Azure Kubernetes CronJob | medium | azure / NULL |
| Modifying Crontab | medium | linux / NULL |
| Scheduled Cron Task/Job - Linux | medium | linux / process_creation |
| Scheduled Cron Task/Job - MacOs | medium | macos / process_creation |
| New Cron File Created | low | linux / file_event |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco Isovalent - Cron Job Creation | Anomaly | NULL | Cisco Isovalent Process Exec |
| Cisco Secure Firewall - Wget or Curl Download | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Linux Add Files In Known Crontab Directories | Anomaly | NULL | Sysmon for Linux EventID 11 |
| Linux Adding Crontab Using List Parameter | Hunting | NULL | Sysmon for Linux EventID 1 |
| Linux At Allow Config File Creation | Anomaly | NULL | Sysmon for Linux EventID 11 |
| Linux Auditd Edit Cron Table Parameter | Anomaly | NULL | Linux Auditd Syscall |
| Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File | Hunting | NULL | Linux Auditd Path, Linux Auditd Cwd |
| Linux Crontab Enumeration | Hunting | NULL | Sysmon for Linux EventID 1, Cisco Isovalent Process Exec |
| Linux Edit Cron Table Parameter | Hunting | NULL | Sysmon for Linux EventID 1 |
| Linux Possible Append Cronjob Entry on Existing Cronjob File | Hunting | NULL | Sysmon for Linux EventID 1 |
| Linux Possible Cronjob Modification With Editor | Hunting | NULL | Sysmon for Linux EventID 1 |
| Used by | Procedure example |
|---|---|
| GroupAPT38 | APT38 has used cron to create pre-scheduled and periodic background jobs on a Linux system. |
| GroupAPT5 | APT5 has made modifications to the crontab file including in `/var/cron/tabs/`. |
| GroupRocke | Rocke installed a cron job that downloaded and executed files from the C2. |
| Used by | Procedure example |
|---|---|
| MalwareAnchor | Anchor can install itself as a cron job. |
| MalwareExaramel for Linux | Exaramel for Linux uses crontab for persistence if it does not have root privileges. |
| MalwareGoldMax | The GoldMax Linux variant has used a crontab entry with a |
| MalwareGomir | Gomir will configure a crontab for process execution to start the backdoor on reboot if it is not initially running under group 0 privileges. |
| MalwareJanicab | Janicab used a cron job for persistence on Mac devices. |
| MalwareKinsing | Kinsing has used crontab to download and run shell scripts every minute to ensure persistence. |
| MalwareNETWIRE | NETWIRE can use crontabs to establish persistence. |
| MalwareNKAbuse | NKAbuse uses a Cron job to establish persistence when infecting Linux hosts. |
| Used by | Procedure example |
|---|---|
| CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.