{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/autostart/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["persistence","autostart","windows","detection"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis brief details a common persistence technique where adversaries create or modify files within the Windows Startup folder (\u003ccode\u003e%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\\u003c/code\u003e) to ensure their malicious code or shortcuts execute automatically. This mechanism allows attackers to maintain unauthorized access to a system after an initial compromise, ensuring their tools or backdoors restart with the operating system or user session. The technique is frequently observed in various malware campaigns, including ransomware families like Chaos Ransomware and multiple stealer and RAT variants such as NjRAT, RedLine Stealer, and Quasar RAT, which use it to re-establish control. Detecting such activity is crucial for preventing long-term compromise, as sustained access can lead to data exfiltration, further system entanglement, and impact on sensitive information.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Compromise:\u003c/strong\u003e An attacker gains initial access to a target system through various means (e.g., spearphishing, exploiting a vulnerable service, or drive-by download).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMalware Delivery:\u003c/strong\u003e The attacker delivers a payload, which could be an executable, script, or shortcut file.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFile Creation in Startup Folder:\u003c/strong\u003e The delivered payload or a component of it creates a file (e.g., \u003ccode\u003emalicious.exe\u003c/code\u003e, \u003ccode\u003escript.vbs\u003c/code\u003e, \u003ccode\u003eshortcut.lnk\u003c/code\u003e) in the \u003ccode\u003e%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\\u003c/code\u003e directory.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSystem Reboot/User Logon:\u003c/strong\u003e The victim system is rebooted, or the user logs on to their account.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAutomatic Execution:\u003c/strong\u003e The operating system automatically executes the malicious file placed in the Startup folder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePersistence Established:\u003c/strong\u003e The malicious code runs, re-establishing the attacker's presence on the system. This could involve re-launching a command and control (C2) agent, re-infecting the system, or performing other malicious activities.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpact Continuation:\u003c/strong\u003e The attacker maintains unauthorized access, potentially leading to continued data exfiltration, further system compromise, or the deployment of additional malicious functionalities (e.g., ransomware encryption).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this persistence mechanism can lead to severe consequences for an organization. Adversaries can maintain long-term unauthorized access to compromised systems, bypassing security measures and re-establishing control even after system restarts. This sustained presence enables attackers to exfiltrate sensitive data, deploy additional malware such as ransomware (e.g., Chaos Ransomware), or use the compromised host as a staging ground for lateral movement within the network. This technique has been observed in various malware campaigns, affecting multiple sectors by facilitating prolonged espionage, data theft, and destructive attacks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detect File Creation in Windows Startup Folder\u0026quot; to your SIEM to monitor for suspicious file creations.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon EventID 11 (FileCreate) logging on all Windows endpoints to ensure the necessary telemetry is collected for detection.\u003c/li\u003e\n\u003cli\u003eInvestigate any alerts from the \u0026quot;Detect File Creation in Windows Startup Folder\u0026quot; rule to determine if the activity is legitimate.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T09:05:01Z","date_published":"2026-07-24T09:05:01Z","id":"https://feed.craftedsignal.io/briefs/2026-07-autostart-execution-startup-folder/","summary":"Adversaries leverage the Windows %startup% folder to establish persistence by creating malicious files that execute automatically upon system boot or user logon, potentially leading to system compromise and unauthorized access.","title":"Windows Autostart Execution in Startup Folder for Persistence","url":"https://feed.craftedsignal.io/briefs/2026-07-autostart-execution-startup-folder/"}],"language":"en","title":"CraftedSignal Threat Feed - Autostart","version":"https://jsonfeed.org/version/1.1"}