51 results found (page 1 of 4)
https://attack.mitre.org/versions/v17/techniques/T1547/001

…oader installed Rising Sun to %Startup%\mssync.exe on a compromised host. [203] G0040 Patchwork Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key. [204] […