T1060 - Startup Folder - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 5, 2026
Last Seen
January 5, 2026

The Startup Folder (T1060) is a Windows persistence technique where programs placed in the Startup folder automatically run at user logon, enabling re-entry after reboots.

Overview

The Startup Folder (T1060) is a Windows persistence technique where programs placed in the Startup folder automatically run at user logon, enabling re-entry after reboots. It is commonly abused by threat actors to achieve lightweight, low-privilege persistence and to maintain access across sessions. In the context of the provided article, this technique underpins Windows-based malware campaigns by enabling ongoing presence, often coordinated with social-engineering delivery methods.

Related Threat Clusters

Recent Intelligence Reports

  • ClickFix attack uses fake Windows BSOD screens to push malware — Bleepingcomputer · January 5, 2026

CVSS v3.1 Breakdown