SHIPSHAPE is a Windows malware family identified in ATT&CK as S0028. It has been associated with persistence through Windows autostart mechanisms, including Registry Run keys and Startup-folder shortcut modification. Reported behavior includes creating a shortcut in the Startup folder so the malware executes at user logon, and using Registry-based boot or logon autostart execution to survive reboots. SHIPSHAPE has also been documented as replicating through removable media, indicating propagation via USB or similar devices. Based on the available facts, SHIPSHAPE is best characterized by its persistence and removable-media replication behavior on Windows systems; additional functionality, operator attribution, and sector targeting are not established with high confidence from the available information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that establishes persistence by creating a shortcut in the Startup folder.
Backdoor malware that persists by creating a Startup-folder shortcut.
Malware that establishes persistence through registry run keys and shortcut modification and can replicate via removable media.
Achieves persistence by creating a shortcut in the Startup folder.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.