Potentially Suspicious Desktop Background Change Via Registry

 Original Source: [Sigma source]
Title: Potentially Suspicious Desktop Background Change Via Registry
Status: test
Description:Detects registry value settings that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.
References:
  -https://www.attackiq.com/2023/09/20/emulating-rhysida/
  -https://research.checkpoint.com/2023/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society/
  -https://www.trendmicro.com/en_us/research/23/h/an-overview-of-the-new-rhysida-ransomware.html
  -https://www.virustotal.com/gui/file/a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6/behavior
  -https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.WindowsDesktop::Wallpaper
  -https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.ControlPanelDisplay::CPL_Personalization_NoDesktopBackgroundUI
Author: Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ)
Date: 2023-12-21
modified:2025-10-17
Tags:
  • -'attack.persistence'
  • -'attack.impact'
  • -'attack.defense-impairment'
  • -'attack.t1112'
  • -'attack.t1491.001'
Logsource:
  • product: windows
  • category: registry_set
Detection:
  selection_keys:
    TargetObject|contains:
      -'Control Panel\Desktop'
      -'CurrentVersion\Policies\ActiveDesktop'
      -'CurrentVersion\Policies\System'

  selection_values_1:
    TargetObject|endswith: 'NoChangingWallpaper'
    Details: 'DWORD (0x00000001)'
  selection_values_2:
    TargetObject|endswith: '\Wallpaper'
  selection_values_3:
    TargetObject|endswith: '\WallpaperStyle'
    Details: '2'
  filter_main_svchost:
    Image|endswith: '\svchost.exe'
  filter_main_empty:
    TargetObject|endswith: '\Control Panel\Desktop\Wallpaper'
    Details: '(Empty)'
  filter_main_explorer:
    Image|endswith: 'C:\Windows\Explorer.EXE'
  filter_optional_ec2launch:
    Image:
      -'C:\Program Files\Amazon\EC2Launch\EC2Launch.exe'
      -'C:\Program Files (x86)\Amazon\EC2Launch\EC2Launch.exe'

    TargetObject|endswith: '\Control Panel\Desktop\Wallpaper'
  condition:selection_keys and 1 of selection_values_* and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Administrative scripts that change the desktop background to a company logo or other image.
Level: medium