54
Groups Using This
3
Tactics
1
Platforms
11
Prevalence Rank
Description

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path. An adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to System Binary Proxy Execution, adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes. Adversaries may also create "hidden" scheduled tasks (i.e. Hide Artifacts) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions). Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.

View MITRE record โ†—

Platforms
Windows
Groups Using T1053.005 (54)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0032
Lazarus Group
๐Ÿ‡ฐ๐Ÿ‡ต North Korea93 techniques26 software
G0129
Mustang Panda
๐Ÿ‡ท๐Ÿ‡บ Russia85 techniques23 software
G0096
APT41
๐Ÿ‡จ๐Ÿ‡ณ China82 techniques32 software
G0034
Sandworm Team
๐Ÿ‡ท๐Ÿ‡บ Russia79 techniques27 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0047
Gamaredon Group
๐Ÿ‡ท๐Ÿ‡บ Russia70 techniques6 software
G0069
MuddyWater
๐Ÿ‡ฎ๐Ÿ‡ท Iran68 techniques21 software
G0046
FIN7
67 techniques19 software
G0016
APT29
๐Ÿ‡ท๐Ÿ‡บ Russia66 techniques49 software
G0102
Wizard Spider
๐Ÿ‡ท๐Ÿ‡บ Russia64 techniques22 software
G0114
Chimera
๐Ÿ‡จ๐Ÿ‡ณ China59 techniques6 software
G0082
APT38
๐Ÿ‡ฐ๐Ÿ‡ต North Korea56 techniques6 software
G0035
Dragonfly
๐Ÿ‡ท๐Ÿ‡บ Russia56 techniques10 software
G0087
APT39
๐Ÿ‡ฎ๐Ÿ‡ท Iran53 techniques11 software
G1016
FIN13
53 techniques4 software
G1043
BlackByte
48 techniques8 software
G1003
Ember Bear
๐Ÿ‡ท๐Ÿ‡บ Russia47 techniques11 software
G0045
menuPass
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques25 software
G1006
Earth Lusca
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques9 software
G0022
APT3
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G1053
Storm-0501
42 techniques8 software
G0117
Fox Kitten
๐Ÿ‡ฎ๐Ÿ‡ท Iran41 techniques5 software
G0040
Patchwork
๐Ÿ‡จ๐Ÿ‡ณ China41 techniques8 software
G1039
RedCurl
๐Ÿ‡ท๐Ÿ‡บ Russia41 techniques0 software
G0060
BRONZE BUTLER
๐Ÿ‡จ๐Ÿ‡ณ China40 techniques14 software
G0037
FIN6
40 techniques12 software
G0099
APT-C-36
38 techniques9 software
G0061
FIN8
36 techniques11 software
G1001
HEXANE
36 techniques12 software
G0080
Cobalt Group
34 techniques6 software
G1044
APT42
๐Ÿ‡ฎ๐Ÿ‡ท Iran32 techniques2 software
G0064
APT33
๐Ÿ‡ฎ๐Ÿ‡ท Iran31 techniques16 software
G0093
GALLIUM
๐Ÿ‡ท๐Ÿ‡บ Russia31 techniques16 software
G1036
Moonstone Sleet
๐Ÿ‡ฐ๐Ÿ‡ต North Korea30 techniques1 software
G0067
APT37
๐Ÿ‡ท๐Ÿ‡บ Russia29 techniques13 software
G0091
Silence
๐Ÿ‡ท๐Ÿ‡บ Russia28 techniques3 software
G1014
LuminousMoth
๐Ÿ‡จ๐Ÿ‡ณ China28 techniques2 software
G0126
Higaisa
๐Ÿ‡ท๐Ÿ‡บ Russia28 techniques3 software
G1018
TA2541
28 techniques9 software
G1035
Winter Vivern
๐Ÿ‡ท๐Ÿ‡บ Russia27 techniques0 software
G1022
ToddyCat
25 techniques9 software
G0108
Blue Mockingbird
22 techniques2 software
G0142
Confucius
19 techniques1 software
G1034
Daggerfly
๐Ÿ‡จ๐Ÿ‡ณ China17 techniques6 software
G1002
BITTER
๐Ÿ‡จ๐Ÿ‡ณ China16 techniques1 software
G0038
Stealth Falcon
16 techniques0 software
G0021
Molerats
16 techniques6 software
G0019
Naikon
๐Ÿ‡จ๐Ÿ‡ณ China14 techniques15 software
G0051
FIN10
11 techniques1 software
G0095
Machete
๐Ÿ‡ท๐Ÿ‡บ Russia11 techniques1 software
G0075
Rancor
9 techniques4 software
โ†‘