TACTIC: PERSISTENCE
Registry Run Keys / Startup Folder (T1547.001): real cases
MITRE Definition ↗ Adversaries add program references to Windows registry run keys to execute malware on user logon.
Key Facts
Technique ID
T1547.001
Persistence
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1547.001.
- Tactical Phase: Persistence.
- Substantiated in 1 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)
fugitive 2019-11-14
Primary Source Evidence Excerpt: Indictment ¶ 26, Page 15
"The malware wrote autorun entries into HKCU\Software\Microsoft\Windows\CurrentVersion\Run to maintain persistence across reboots."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →