Attackers can maintain persistence on Windows by abusing Winlogon autostart mechanisms, including modification of registry values such as HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell and Userinit, as well as use of the Winlogon Helper DLL technique tracked by MITRE ATT&CK as T1547.004. By altering these settings, a malicious executable or DLL can be launched automatically during user logon, giving malware a reliable way to survive reboots and regain execution.
Public technical material showed a C++ proof of concept that rewrites Winlogon registry keys to start a test payload at logon and noted that older Windows versions may also expose persistence through the Winlogon\Notify key. The technique requires elevated privileges, but it has been associated with real-world malware activity, including Turla, Gazer, and Bazaar. Defenders are advised to restrict local administrator access and monitor Winlogon-related autorun entries for unauthorized changes, including with tools such as Sysinternals Autoruns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A technical article demonstrated Windows persistence by modifying Winlogon registry keys such as Shell and Userinit so a test payload would execute at user logon. The walkthrough included proof-of-concept C++ code, validation steps, cleanup guidance, and noted the technique's use by Turla, Gazer, and Bazaar.
MITRE ATT&CK published the Enterprise sub-technique 'Boot or Logon Autostart Execution: Winlogon Helper DLL' as T1547.004, documenting abuse of Winlogon-related mechanisms for persistence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cocomelonc.github.io
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.