Power Settings

T1653

Technique.View on attack.mitre.org

About this technique

Adversaries may impair a system's ability to hibernate, reboot, or shut down in order to extend access to infected machines. When a computer enters a dormant state, some or all software and hardware may cease to operate which can disrupt malicious activity.

Adversaries may abuse system utilities and configuration settings to maintain access by preventing machines from entering a state, such as standby, that can terminate malicious activity.

For example, `powercfg` controls all configurable power system settings on a Windows system and can be abused to prevent an infected host from locking or shutting down. Adversaries may also extend system lock screen timeout settings. Other relevant settings, such as disk and hibernate timeout, can be similarly abused to keep the infected machine running even if no user is active.

Aware that some malware cannot survive system reboots, adversaries may entirely delete files used to invoke system shut down or reboot.

Detection rules1

Rules on DetectionCode tagged with T1653.

Sigma1

RuleLevelLog source
Mask System Power Settings Via Systemctlhighlinux / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software2

Campaigns1

Procedure examples3

Software2

Used byProcedure example
MalwareLine Dancer

Line Dancer can modify the crash dump process on infected machines to skip crash dump generation and proceed directly to device reboot for both persistence and forensic evasion purposes.

MalwareLine Runner

Line Runner used CVE-2024-20353 to trigger victim devices to reboot, in the process unzipping and installing the Line Dancer payload.

Campaigns1

Used byProcedure example
CampaignArcaneDoor

ArcaneDoor involved exploitation of CVE-2024-20353 to force a victim Cisco ASA to reboot, triggering the automated unzipping and execution of the Line Runner implant.

References7

  1. BATLOADER: The Evasive Downloader Malware Open source
    Bethany Hardin, Lavine Oluoch, Tatiana Vollbrecht. (2022, November 14). BATLOADER: The Evasive Downloader Malware. Retrieved June 5, 2023.
  2. CoinLoader: A Sophisticated Malware Loader Campaign Open source
    Avira. (2019, November 28). CoinLoader: A Sophisticated Malware Loader Campaign. Retrieved June 5, 2023.
  3. Condi-Botnet-binaries Open source
    Joie Salvio and Roy Tay. (2023, June 20). Condi DDoS Botnet Spreads via TP-Link's CVE-2023-1389. Retrieved September 5, 2023.
  4. Microsoft: Powercfg command-line options Open source
    Microsoft. (2021, December 15). Powercfg command-line options. Retrieved June 5, 2023.
  5. Sleep, shut down, hibernate Open source
    AVG. (n.d.). Should You Shut Down, Sleep or Hibernate Your PC or Mac Laptop?. Retrieved June 8, 2023.
  6. Two New Monero Malware Attacks Target Windows and Android Users Open source
    Douglas Bonderud. (2018, September 17). Two New Monero Malware Attacks Target Windows and Android Users. Retrieved June 5, 2023.
  7. systemdsleep Linux Open source
    Man7. (n.d.). systemd-sleep.conf(5) — Linux manual page. Retrieved June 7, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.