Skip to content
Bulwark Black Bulwark Black LLC
Threat Intel
  • Latest reporting
  • Russian CTI
  • Chinese CTI
  • North Korean CTI
  • Iranian CTI
  • Global / Anomalous
  • Malware
  • IOC / YARA downloads
Software
  • Contractor Codex ↗
  • SAMscout AI ↗
  • VA Disability Calc & Track
  • What we build
  • All software
Services
  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • Small-Business IT & Cybersecurity
Company
  • About
  • Community
  • Contact
IOC Extractor Indicators Feeds The Brief Blog
Threat Intel → Work with us →
All Threat Intel → Latest reporting Russian CTI Chinese CTI North Korean CTI Iranian CTI Global / Anomalous Malware IOC / YARA downloads
All Software → Contractor Codex ↗ SAMscout AI ↗ VA Disability Calc & Track What we build All software
All Services → Websites & Web Apps Custom iOS Apps AI & Automation Small-Business IT & Cybersecurity
All Company → About Community Contact
IOC Extractor Indicators Feeds The Brief Blog Work with us →
RSS
Latest
Dropcatch Domains Show Why Reputation Is Not TrustCaptiveCrunch Shows Why Travel Wi-Fi Is an Identity Attack SurfaceHoneyMyte’s CoolClient Rootkit Shows Why Kernel Visibility MattersJWR Phishing Framework Shows Why MFA Codes Are Now Live TargetsEvooo1Bot Shows Why Exposed Linux and Edge Devices Are Still High-Value TargetsMalware Crypting Services Show Why Behavioral Detection MattersPrivate Wireless Utility Networks Are Becoming OT Attack PathsKong Mesh Vulnerabilities Show Why Service Mesh Security Needs Control-Plane DisciplineGunra Ransomware Shows Why VPN Compromise Is an Incident, Not a Patch TicketCI Fortify Shows Why OT Isolation Must Be Engineered Before the IncidentLazarus Dream Job Campaign Turns Fake Recruiting Into a Windows Zero-Day IntrusionDeno Runtime Abuse Shows Why Developer Tooling Needs Security GovernanceAeternum Shows Why Blockchain-Based C2 Is a Practical Defense ProblemDeadLock Ransomware Shows Why Recovery Infrastructure Is Part of the Attack SurfaceDropcatch Domains Show Why Reputation Is Not TrustCaptiveCrunch Shows Why Travel Wi-Fi Is an Identity Attack SurfaceHoneyMyte’s CoolClient Rootkit Shows Why Kernel Visibility MattersJWR Phishing Framework Shows Why MFA Codes Are Now Live TargetsEvooo1Bot Shows Why Exposed Linux and Edge Devices Are Still High-Value TargetsMalware Crypting Services Show Why Behavioral Detection MattersPrivate Wireless Utility Networks Are Becoming OT Attack PathsKong Mesh Vulnerabilities Show Why Service Mesh Security Needs Control-Plane DisciplineGunra Ransomware Shows Why VPN Compromise Is an Incident, Not a Patch TicketCI Fortify Shows Why OT Isolation Must Be Engineered Before the IncidentLazarus Dream Job Campaign Turns Fake Recruiting Into a Windows Zero-Day IntrusionDeno Runtime Abuse Shows Why Developer Tooling Needs Security GovernanceAeternum Shows Why Blockchain-Based C2 Is a Practical Defense ProblemDeadLock Ransomware Shows Why Recovery Infrastructure Is Part of the Attack Surface

Threat Intel·Chinese Cyber Threat Intelligence·Jan 5, 2024·By Albert LaScola

Hackers Modifying Registry Keys to Establish Persistence via Scheduled Tasks

Hackers Modifying Registry Keys to Establish Persistence via Scheduled Tasks
Hackers Modifying Registry Keys to Establish Persistence via Scheduled Tasks
Scheduled Task Tampering
Hackers-Modifying-Registry-Keys-to-Establish-Persistence-via-Scheduled-TasksDownload

#Hafnium

← Older report

Tackling Anti-Analysis Techniques of GuLoader and RedLine Stealer

Newer report →

Prior to Cyber Attack, Russian Attackers Spent Months Inside the Ukraine Telecoms Giant

Next step

Want this turned into detection for your environment?

We build the defenses we write about: detection rules, hardening, and incident response for small businesses and government contractors. Or take the indicators above and run them yourself, every report ships with machine-readable downloads.

Work With Us →Get the IOC Feeds →

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

readers get The Brief

Double opt-in. One-click unsubscribe on every issue. We never share your address.

Bulwark Black

Veteran-Owned · SDVOSB

Bulwark Black LLC
Cyber threat intelligence, custom software, and remote tech help.
Remote across the United States.

Registered agent address (mailing only):
522 W Riverside Ave, Ste N
Spokane, WA 99201

Two front doors

  • Cyber Threat Intelligence
  • Indicator Database
  • Threat Feeds
  • Shared Infrastructure
  • Threat Alerts
  • The Brief
  • Tech Services & Apps

Services

  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • IT + Cybersecurity

Company

  • About
  • Software
  • VA Disability Calc & Track
  • Community
  • Blog
  • How I Work
  • Contact
  • Privacy
  • Terms
  • VA Calc Privacy Policy

For agencies & primes

  • Capability statement
  • CAGE: 17UL6
  • UEI: DVNTWBJ2HMP8
  • SDVOSB · SAM Registered

support@bulwarkblack.com

Connect

  • LinkedIn
  • GitHub

© 2026 Bulwark Black LLC. All rights reserved.

Privacy · Terms · Cookie choices

We use Google Analytics to measure site traffic, which sets cookies. No ads and no cross-site tracking. See our privacy policy.