Install WanaCry persistence via registry

/static/assets/windows-logo.svg
WannaCry uses the Windows registry Run key for persistence. This technique stages and writes a PneumaEX agent to disk and configures the Run key to start it.
locked
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.

Login

Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
APT38 WannaCry

2022-05-31

/static/assets/windows-logo.svg/static/assets/apple-logo.svg/static/assets/linux-logo.svg
Perform lateral movement using EternalBlue and DoublePulsar exploits.