Sub-technique of T1547 Boot or Logon Autostart Execution.View on attack.mitre.org
Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in. Winlogon.exe is a Windows component responsible for actions at logon/logoff as well as the secure attention sequence (SAS) triggered by Ctrl-Alt-Delete. Registry entries in HKLM\Software[\\Wow6432Node\\]\Microsoft\Windows NT\CurrentVersion\Winlogon\ and HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ are used to manage additional helper programs and functionalities that support Winlogon.
Malicious modifications to these Registry keys may cause Winlogon to load and execute malicious DLLs and/or executables. Specifically, the following subkeys have been known to be possibly vulnerable to abuse:
* Winlogon\Notify - points to notification package DLLs that handle Winlogon events
* Winlogon\Userinit - points to userinit.exe, the user initialization program executed when a user logs on
* Winlogon\Shell - points to explorer.exe, the system shell executed when a user logs on
Adversaries may take advantage of these features to repeatedly execute malicious code and establish persistence.
Rules on DetectionCode tagged with T1547.004.
| Rule | Level | Log source |
|---|---|---|
| Winlogon Notify Key Logon Persistence | high | windows / registry_set |
| MITRE BZAR Indicators for Persistence | medium | zeek / NULL |
| Winlogon Helper DLL | medium | windows / ps_script |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupTropic Trooper | Tropic Trooper has created the Registry key |
| GroupTurla | Turla established persistence by adding a Shell value under the Registry key |
| GroupWizard Spider | Wizard Spider has established persistence using Userinit by adding the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. |
| Used by | Procedure example |
|---|---|
| MalwareBazar | Bazar can use Winlogon Helper DLL to establish persistence. |
| MalwareCannon | Cannon adds the Registry key |
| MalwareDarkTortilla | DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Winlogon` registry key. |
| MalwareDipsind | A Dipsind variant registers as a Winlogon Event Notify DLL to establish persistence. |
| MalwareGazer | Gazer can establish persistence by setting the value “Shell” with “explorer.exe, %malware_pathfile%” under the Registry key |
| MalwareKeyBoy | KeyBoy issues the command |
| MalwareLockBit 3.0 | LockBit 3.0 can enable automatic logon through the `SOFTWARE\Microsoft\Windows |
| MalwareQilin | Qilin can configure a Winlogon registry entry. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.