EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium
A cybersecurity team is conducting a post-incident analysis on a compromised server. They suspect that an attacker used a remote access Trojan (RAT) to maintain long-term control. Which of the following locations is a common and stealthy place for a RAT to establish persistence on a Windows operating system?
- AThe 'Run' registry key (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run).
- BThe Recycle Bin folder.
- CThe 'Program Files' directory.
- DThe Windows \System32 folder directly.
Show answer & explanationAnswer & explanation
Correct answer: A. The 'Run' registry key (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run).
The 'Run' registry keys (both HKLM and HKCU) are frequently used by malware, including RATs, to achieve persistence. Entries in these keys automatically execute specified programs every time the user logs in or the system starts, making them a stealthy and effective method for maintaining access.
Why the other options are wrong
- B. The Recycle Bin is not a common persistence mechanism and is easily cleared.
- C. While malware might reside in Program Files, it needs a separate mechanism (like a Run key) to achieve persistence.
- D. The System32 folder is a common location for legitimate system files, but direct placement without a corresponding execution mechanism doesn't guarantee persistence.
Persistence Mechanisms (Windows)
Methods used by attackers to ensure their malicious code continues to run or can be reactivated on a Windows system after reboots or user logoffs.
- Registry Run keys are popular for auto-starting programs.
- Scheduled Tasks can execute payloads at specific times or events.
- Windows Services can run in the background with high privileges.
Memory trick: To 'stay on' Windows, you need to 'register' your presence or 'schedule' yourself.