The Startup Folder (T1060) is a Windows persistence technique where programs placed in the Startup folder automatically run at user logon, enabling re-entry after reboots.
The Startup Folder (T1060) is a Windows persistence technique where programs placed in the Startup folder automatically run at user logon, enabling re-entry after reboots. It is commonly abused by threat actors to achieve lightweight, low-privilege persistence and to maintain access across sessions. In the context of the provided article, this technique underpins Windows-based malware campaigns by enabling ongoing presence, often coordinated with social-engineering delivery methods.
A ClickFix social engineering campaign is targeting the hospitality sector in Europe by using fake Windows Blue Screen of Death (BSOD) screens. This tactic tricks users into manually compiling and executing malware on…