FORENSIA

ATT&CK · T1112

Modify Registry

Tactics: defense-impairment, persistence

About

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution. Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility Reg may be used for local or remote Registry modification. Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API. The Registry may be modified in order to hide configuration information or malicious payloads via Obfuscated Files or Information. The Registry may also be modified to impair defenses, such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory. The Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system. Often Valid Accounts are required, along with access to the remote system's SMB/Windows Admin Shares for RPC communication. Finally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via Reg or other utilities using the Win32 API. Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.

Platforms: WindowsMITRE ATT&CK ↗

Used by actors

29 known groups

Software

139 malware/tools implement this

TaidoorPoisonIvyPlugXReginUroburosCHOPSTICKBACKSPACEgh0st RATADVSTORESHELLRegRoverCrimsonComRATShamoonStreamExRTMCobalt StrikeSOUNDBITEPHOREALVolgmerNETWIREHydraqNaidNerexOrzBankshotROKRATSynAckBADCALLPLAINTEEMosquitoInvisiMoleCatchamasQuasarRATTYPEFRAMETrickBotFELIXROOTBisonalQUADAGENTKEYMARBLEZeus PandaAgent TeslaRemcosDarkCometNanoCoreGreyEnergyExaramel for WindowsCardinal RATzwShellKONNIHOPLIGHTnjRATUrsnifLoJaxZxShellPoetRATAttorPowerShowerShimRatLokibotMetamorfoNetwalkerTajMahalValakCrackMapExecREvilPipeMonRegDukePillowmintPolyglotDukeCSPY DownloaderGrandoreiroSLOTHFULMEDIAHyperStackSUNBURSTTEARDROPEVILNUMExplosiveBitPaymerCaterpillar WebShellMegaCortexWaterbearPysaSibotShadowPadStuxnetConfickerClopWastedLockerChaesAvaddonSMOKEDHAMQakBotClamblingRCSessionSysUpdatePandoraThreatNeedleGelsemiumTinyTurlaKOCTOPUSWarzoneRATDarkWatchmanCharmPowerAADInternalsFerociousNeoichorSILENTTRINITYHermeticWiperTarraskAmadeyDCSrvMoriPcSharePrestigemetaMainMafaldaDarkTortillaBlackCatBlack BastaNightClubSamuraiNPPSPYIPsec HelperCHIMNEYSWEEPShrinkLockerBlackByte RansomwareBlackByte 2.0 RansomwareKapekaLockBit 2.0TRANSLATEXTLockBit 3.0BOOKWORMHIUPANQilinEmbargoHiddenFaceNOOPLDRMuddyViper

Corpus indicators tagged with this technique

5,837 indicators in the corpus carry T1112.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2025-61155cveransomware853
cve-2023-52271cveransomware853
cve-2026-3102cve853
cve-2025-1055cveransomware853
50ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdfsha256supply_chain801
93b3d3925ccc201ab0f16017153a79ef05b8f5c2hashcryptojacking802
462af0a3a9094d44c30cc65544ec1171a62365cff09e67f5e87e061a3d604bd0hashcryptojacking802
669002654c264191d4660fbf757860d930175649735f81370b9f1af3658a304csha256phishing802
7b7981c99d59595fe15377df84695bb72ce0b85560a3935f930657b2d162e5efsha256phishing801
7900c2772680523cadc9fe4e07300d45500191ba64ff5b91573531b133840b14sha256phishing802
c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2sha256supply_chain801
282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990sha256supply_chain801
248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51dbsha256phishing802
adcd15f3d6b87f84d106ea426fa824fd20c9d64f6d199ce92580884290785f30sha256phishing801
5115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35dsha256phishing802
5272917261d7091a59e00f9d09cd7eb1d3e111115a5b367f79a66d0d7c7b01f4sha256phishing802
7b297f18ece81e87608e158288cc9c06cb9f4a8f1b2d2256aecf7bba8d7be2absha256phishing802
bd46890121106b43f0c01ab82629400chashcryptojacking802
60972abf5425c191c81bae117f1dedaea13d39bc52f367d5dff9ad1aa4b9c5casha256phishing802
22de84e8f29cba932cf65cf4dc1d333cb8b2e468204f97030712bee32691ac3bsha256phishing802
62a879b0d1c1649cc72b2b6f61a8f6bd888625ce6e8a7aefe0a0461e4f27c525sha256phishing802
23b37d2ebe683cec3b145b6f2234ee728b99228cf3774399fcfad9502daab9a9sha256phishing802
771a47120b935e218322046e838347d722d265b91f1afdef91194a5bec86a97asha256phishing802
a37f6403fbf28fa0b48863287f4c5a5dhashcryptojacking802
164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3sha256supply_chain801
43d597783af656a35184021f5e20686896463a1712f9216e0217a2ca740e3935sha256phishing802
17832aa629524ef6e8d8d6e9b6b902a8d324b559e3c36dbd0e221ab1690be871sha256supply_chain801
44a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695fsha256phishing802
5ab41cf20315d2ea1385967d588159873a65ef5581a0b78de06c0d8617894194sha256phishing802

Showing the top 30 by severity of 5,837.