Technique.View on attack.mitre.org
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility Reg may be used for local or remote Registry modification. Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API.
The Registry may be modified in order to hide configuration information or malicious payloads via Obfuscated Files or Information. The Registry may also be modified to impair defenses, such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory.
The Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system. Often Valid Accounts are required, along with access to the remote system's SMB/Windows Admin Shares for RPC communication.
Finally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via Reg or other utilities using the Win32 API. Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.
Rules on DetectionCode tagged with T1112.
| Used by | Procedure example |
|---|---|
| GroupAPT19 | APT19 uses a Port 22 malware variant to modify several Registry keys. |
| GroupAPT32 | APT32's backdoor has modified the Windows Registry to store the backdoor's configuration. |
| GroupAPT38 | APT38 uses a tool called CLEANTOAD that has the capability to modify Registry keys. |
| GroupAPT41 | APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials. |
| GroupAPT42 | APT42 has modified Registry keys to maintain persistence. |
| GroupAquatic Panda | Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP. |
| GroupBlackByte | BlackByte performed Registry modifications to escalate privileges and disable security tools. |
| GroupBlue Mockingbird | Blue Mockingbird has used Windows Registry modifications to specify a DLL payload. |
| Used by | Procedure example |
|---|---|
| ToolAADInternals | AADInternals can modify registry keys as part of setting a new pass-through authentication agent. |
| MalwareADVSTORESHELL | ADVSTORESHELL is capable of setting and deleting Registry values. |
| MalwareAgent Tesla | Agent Tesla can achieve persistence by modifying Registry key entries. |
| MalwareAmadey | Amadey has overwritten registry keys for persistence. |
| MalwareAttor | Attor's dispatcher can modify the Run registry key. |
| MalwareAvaddon | Avaddon modifies several registry keys for persistence and UAC bypass. |
| MalwareBACKSPACE | BACKSPACE is capable of deleting Registry keys, sub-keys, and values on a victim system. |
| MalwareBADCALL | BADCALL modifies the firewall Registry key |
View all 139 software examples
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching `rundll32.exe`, which in-turn launches the malware and communicates with C2 servers over the Internet. . |
| CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry. |
| CampaignOperation Honeybee | During Operation Honeybee, the threat actors used batch files that modified registry keys. |
| CampaignOperation Wocao | During Operation Wocao, the threat actors enabled Wdigest by changing the `HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest` registry value from 0 (disabled) to 1 (enabled). |
| CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, disabled security services via Registry modifications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.