Shortcut Modification

T1547.009

Sub-technique of T1547 Boot or Logon Autostart Execution.View on attack.mitre.org

About this technique

Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic links are used to reference other files or programs that will be opened or executed when the shortcut is clicked or executed by a system startup process.

Adversaries may abuse shortcuts in the startup folder to execute their tools and achieve persistence. Although often used as payloads in an infection chain (e.g. Spearphishing Attachment), adversaries may also create a new shortcut as a means of indirection, while also abusing Masquerading to make the malicious shortcut appear as a legitimate program. Adversaries can also edit the target path or entirely replace an existing shortcut so their malware will be executed instead of the intended legitimate program.

Shortcuts can also be abused to establish persistence by implementing other methods. For example, LNK browser extensions may be modified (e.g. Browser Extensions) to persistently launch malware.

Detection rules4

Rules on DetectionCode tagged with T1547.009.

Sigma4

RuleLevelLog source
Creation Exe for Service with Unquoted Pathhighwindows / file_event
Desktop.INI Created by Uncommon Processmediumwindows / file_event
New Custom Shim Database Createdmediumwindows / file_event
Windows Network Access Suspicious desktop.ini Actionmediumwindows / NULL

Splunk0

No Splunk rules are mapped to this technique yet.

Groups4

Software25

Show 1 more

Campaigns0

None recorded.

Procedure examples29

Groups4

Used byProcedure example
GroupAPT39

APT39 has modified LNK shortcuts.

GroupGorgon Group

Gorgon Group malware can create a .lnk file and add a Registry Run key to establish persistence.

GroupLazarus Group

Lazarus Group malware has maintained persistence on a system by creating a LNK shortcut in the user’s Startup folder.

GroupLeviathan

Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor.

Software25

Used byProcedure example
MalwareAstaroth

Astaroth's initial payload is a malicious .LNK file.

MalwareBACKSPACE

BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory.

MalwareBazar

Bazar can establish persistence by writing shortcuts to the Windows Startup folder.

MalwareBlackEnergy

The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder.

MalwareComnie

Comnie establishes persistence via a .lnk file in the victim’s startup path.

ToolEmpire

Empire can persist by modifying a .LNK file to include a backdoor.

MalwareFELIXROOT

FELIXROOT creates a .LNK file for persistence.

MalwareGazer

Gazer can establish persistence by creating a .lnk file in the Start menu or by modifying existing .lnk files to execute the malware through cmd.exe.

View all 25 software examples

References1

  1. Shortcut for Persistence Open source
    Elastic. (n.d.). Shortcut File Written or Modified for Persistence. Retrieved June 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.