A technical walkthrough demonstrated how Windows Scheduled Tasks can be abused to establish malware persistence, using a simple C proof of concept that creates a task named MeowTask to launch a payload at user logon with SYSTEM privileges and the highest run level. The author initially tested a payload that displayed a message box, then replaced it with one that writes a file after the message box failed to appear following reboot, illustrating how attackers can adapt payload behavior while keeping the persistence mechanism unchanged.
The write-up also noted operational quirks during testing, including the task only working in the author’s virtual machine when the laptop was connected to power rather than running on battery. The technique aligns with tradecraft previously associated with threat actors including APT17 and APT41, reinforcing that scheduled task creation remains a practical persistence method defenders should monitor for, particularly unusual or unauthorized tasks that may be detectable or blockable through EDR controls.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
A technical walkthrough demonstrated how to abuse Windows Scheduled Tasks for persistence by creating a task named "MeowTask" that runs a payload at user logon as SYSTEM with the highest privileges. The author showed testing with an initial message-box payload and a revised file-writing payload that successfully created meow.txt after logon.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.