BIOC
Informational
✕
Persistence via Registry screensaver key change
Attackers may install their malware persistently by modifying the value of the screensaver Registry key.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Event Triggered Execution: Screensaver (T1546.002)
Indicator:
Registry registry key name = *\Control Panel\Desktop AND registry value name = SCRNSAVE.EXE AND action type = set_registry_value Process initiator cmd != * shell32.dll,Control_RunDLL desk.cpl,ScreenSaver,* AND initiated by != rundll32.exe AND cgo name != explorer.exe Host host os = windows
Preventable: yes