Description
The Registry Access and Manager feature in malware allows attackers to interact with the Windows Registry, the hierarchical database that stores low-level settings for the operating system and installed applications. With capabilities to view, create, edit, or delete registry keys and data, this feature gives attackers a powerful tool to manipulate system configurations and behavior. Additionally, it can be used to steal sensitive information such as passwords and software licenses stored in registry entries. For instance, by modifying or creating registry entries, malware can ensure its own persistence, deactivate security measures, or even alter user permissions. The ability to steal passwords and licenses from the registry can also facilitate privilege escalation, making the compromised system even more vulnerable to further exploitation. This kind of access is particularly valuable for advanced attacks, where fine-grained control over the target system is required. By manipulating the registry, attackers can not only deepen their level of system compromise but also tailor the environment to suit their malicious objectives, making this feature a key asset in a sophisticated malware toolkit.
| Categories | Exfiltration, Alteration, Credentials, System Management, Disruption |
| Dangerousness | High |
Existing Techniques
| Name | Associated Feature(s) | Has Snippet | Matching Sample |
|---|---|---|---|
Windows Registry Actions
|
Registry Manager, Destructive Operations | 0 | |
Windows Registry Enumeration
|
Registry Manager | 0 | |
Windows Registry Search
|
Registry Manager | 0 |
Windows Registry Actions
Windows Registry Enumeration
Windows Registry Search
Turkojan 3.0
Bifrost 1.2.1
Bandook 1.35
Poison Ivy 2.3.0
sharK 2.4.0 Fwb+
Nuclear RAT 2.1.0
Poison Ivy 2.3.2
Turkojan 4
Turkojan 4.0
sharK 3.1 fwb++
SynRAT 4.0.1
Cerberus 1.0 Beta
Cerberus 1.01 Beta
Cerberus 1.02 Beta
SynRAT 4.3.1-A-1
Apocalypse RAT 1.4
Cerberus 1.03.4
Spy-Net 2.6
DarkComet RAT 1.3
Cerberus 1.03.5 Beta
DarkComet RAT 2.0 RC4
CyberGate 1.04.8
Lost Door 4.3.1
DarkComet RAT 2.0 RC7
Schwarze Sonne 1.0
Lost Door 5.1
Coolvibes 1 Update 8
Xtreme RAT 2.9
DarkComet RAT 5.3
DarkComet RAT 5.3.1
NjRat 0.7d