29
Groups Using This
2
Tactics
1
Platforms
38
Prevalence Rank
Description

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution. Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility Reg may be used for local or remote Registry modification. Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API. The Registry may be modified in order to hide configuration information or malicious payloads via Obfuscated Files or Information. The Registry may also be modified to impair defenses, such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory. The Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system. Often Valid Accounts are required, along with access to the remote system's SMB/Windows Admin Shares for RPC communication. Finally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via Reg or other utilities using the Win32 API. Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.

View MITRE record โ†—

Platforms
Windows
Groups Using T1112 (29)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0096
APT41
๐Ÿ‡จ๐Ÿ‡ณ China82 techniques32 software
G1017
Volt Typhoon
๐Ÿ‡จ๐Ÿ‡ณ China81 techniques17 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0047
Gamaredon Group
๐Ÿ‡ท๐Ÿ‡บ Russia70 techniques6 software
G0010
Turla
๐Ÿ‡ท๐Ÿ‡บ Russia68 techniques30 software
G0102
Wizard Spider
๐Ÿ‡ท๐Ÿ‡บ Russia64 techniques22 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G1051
Medusa Group
57 techniques5 software
G0082
APT38
๐Ÿ‡ฐ๐Ÿ‡ต North Korea56 techniques6 software
G0035
Dragonfly
๐Ÿ‡ท๐Ÿ‡บ Russia56 techniques10 software
G1043
BlackByte
48 techniques8 software
G1003
Ember Bear
๐Ÿ‡ท๐Ÿ‡บ Russia47 techniques11 software
G1006
Earth Lusca
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques9 software
G0040
Patchwork
๐Ÿ‡จ๐Ÿ‡ณ China41 techniques8 software
G0061
FIN8
36 techniques11 software
G0143
Aquatic Panda
๐Ÿ‡จ๐Ÿ‡ณ China35 techniques6 software
G0092
TA505
34 techniques16 software
G0119
Indrik Spider
๐Ÿ‡ท๐Ÿ‡บ Russia33 techniques8 software
G1044
APT42
๐Ÿ‡ฎ๐Ÿ‡ท Iran32 techniques2 software
G0091
Silence
๐Ÿ‡ท๐Ÿ‡บ Russia28 techniques3 software
G1014
LuminousMoth
๐Ÿ‡จ๐Ÿ‡ณ China28 techniques2 software
G0108
Blue Mockingbird
22 techniques2 software
G0030
Lotus Blossom
21 techniques9 software
G0073
APT19
๐Ÿ‡จ๐Ÿ‡ณ China21 techniques2 software
G1031
Saint Bear
๐Ÿ‡ท๐Ÿ‡บ Russia18 techniques2 software
G0078
Gorgon Group
๐Ÿ‡ท๐Ÿ‡บ Russia16 techniques4 software
โ†‘