FORENSIA

ATT&CK · T1547.009 · sub-technique

Shortcut Modification

Tactics: persistence, privilege-escalation

About

Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic links are used to reference other files or programs that will be opened or executed when the shortcut is clicked or executed by a system startup process. Adversaries may abuse shortcuts in the startup folder to execute their tools and achieve persistence. Although often used as payloads in an infection chain (e.g. Spearphishing Attachment), adversaries may also create a new shortcut as a means of indirection, while also abusing Masquerading to make the malicious shortcut appear as a legitimate program. Adversaries can also edit the target path or entirely replace an existing shortcut so their malware will be executed instead of the intended legitimate program. Shortcuts can also be abused to establish persistence by implementing other methods. For example, LNK browser extensions may be modified (e.g. Browser Extensions) to persistently launch malware.

Used by actors

4 known groups

Software

25 malware/tools implement this

TinyZBotSHIPSHAPEBACKSPACESPACESHIPSeaDukeSslMMS-TypeBlackEnergyRedLeavesGazerHelminthReaverComnieInvisiMoleKazuarFELIXROOTRogueRobinMicropsiaKONNIEmpireAstarothOkrumGrandoreiroBazarMarkiRAT

Corpus indicators tagged with this technique

46 indicators in the corpus carry T1547.009.

IndicatorTypeFamilySevSrc
cve-2026-3102cve853
535f4337f261b6da20a3c614eb13270bed2d533ahash803
1794369214b7f62e70a0485e61335c61hash803
8e1624d110c090ff57d4b493a9107c66hash803
02819d200d1424882af81cb504b3e8614b32397ahash803
17f8f8f34dfa737f36182fed7ff9e9814a114058hash803
901cfa97b1baaf908fd4a02bb52d970f576c4193hash803
ae4601a19d28332a3ec6ac31b385cdf53be53450hash803
c2d9d48b3b10bd58cdf5df9463e3ffcd60533ff3hash803
d2cb0d7a9ad2b5d4ea7c2da8aec62beb37cf36d6hash803
e05f1767c2a337910ed75e90288838d6d0541164hash803
e815a9b418d09c2d4bcd074c2c0bc21406eeb22fhash803
1405a3c5e0aeb08012484134e16cdec4ab29b4a4hash803
2423a5bf0fa7cb9ec09211630a5488629499691bhash803
29f1d346a6e71774c7dad25b90f446b2974393dfhash803
42add9475e67a1ccc6a6af94b5475d3defc01b85hash803
5f1f3689bcf23de1b280b5f35712946da0f7978fhash803
69331cfdac792dc79240e6a6bb6e803eabd70bebhash803
76253fb55aed707440e808ea78e7101318436b1chash803
954722b0c9c678b1313d1f8b204e102842dc5889hash803
9803604ec45f31f9ef75bcca1e1310d8ac1fc3a6hash803
dad26f61da7b8bccc78364411812be74c025b475hash803
edce72f59e4c1d136cd1946af70d334c19df858dhash803
c27a1688fa5a4ec9497da0fc9bd88c8b362234c5sha1cryptojacking782
62d5e9ed6c1444469e4b89f3ca6c2047a5e8eb98sha1cryptojacking782
bbeaac7ef00268bd5cc583e26624e760085581dcsha1cryptojacking782
f9ea4f4b636614226579ac6cbfc8abe21539a8dasha1cryptojacking782
017830597704acd90fb171f3025bc6f28745da57sha1cryptojacking782
56b75638beabd690f38de434f7efd623md5cryptojacking762
512b49f441765698c679b5da5f0cc868md5cryptojacking762

Showing the top 30 by severity of 46.