Windows screensaver settings can be abused to achieve persistence by modifying per-user registry keys under HKCU\Control Panel\Desktop, causing a payload to launch after a period of user inactivity. The technique relies on changing values such as ScreenSaveActive, ScreenSaveTimeOut, and SCRNSAVE.EXE so the operating system starts an attacker-controlled executable when the screensaver is triggered, aligning with MITRE ATT&CK sub-technique T1546.002: Event Triggered Execution: Screensaver.
A public technical walkthrough demonstrated the method with C++ and registry-based configuration changes, while noting operational constraints: it depends on screensavers being enabled and may stop once the user resumes activity. Despite those limitations, the approach remains useful for execution during idle periods and has been associated with real-world malware activity, including reporting that Gazer and Turla have used screensaver-based persistence.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A technical walkthrough showed how to abuse Windows screensaver settings under HKCU\Control Panel\Desktop to launch a payload after user inactivity, including C++, reg.exe, and PowerShell examples. The demonstration configured ScreenSaveTimeOut to 10 seconds and SCRNSAVE.EXE to run a sample payload.
MITRE ATT&CK published the Enterprise sub-technique 'Event Triggered Execution: Screensaver' as T1546.002, documenting screensaver-based execution behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cocomelonc.github.io
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.