Windows Registry Change to Desktop Wallpaper Policy or Settings
Detects Windows registry updates that enforce or change the desktop wallpaper and restrict user control.
FreeUnreviewedSigmamediumv1
windows-registry-change-to-desktop-wallpaper-policy-or-settings-85b88e05
title: Windows Registry Change to Desktop Wallpaper Policy or Settings
id: 742de765-bfff-40a2-829d-a601b1952e7c
related:
- id: 8cbc9475-8d05-4e27-9c32-df960716c701
type: similar
- id: 85b88e05-dadc-430b-8a9e-53ff1cd30aae
type: derived
status: test
description: This rule flags registry value modifications under desktop-related policy paths that would replace the current desktop background, including settings tied to wallpaper enforcement and disabling user changes. Such changes can be used to persistently present ransom notes or other malicious imagery and to impair user defenses by preventing normal wallpaper restoration. It relies on telemetry showing registry value sets to specific target objects and values, while filtering out changes attributed to typical system components and a known EC2 launch utility.
references:
- https://www.attackiq.com/2023/09/20/emulating-rhysida/
- https://research.checkpoint.com/2023/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society/
- https://www.trendmicro.com/en_us/research/23/h/an-overview-of-the-new-rhysida-ransomware.html
- https://www.virustotal.com/gui/file/a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6/behavior
- https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.WindowsDesktop::Wallpaper
- https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.ControlPanelDisplay::CPL_Personalization_NoDesktopBackgroundUI
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_desktop_background_change.yml
author: Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ), Huntrule Team
date: 2023-12-21
modified: 2025-10-17
tags:
- attack.persistence
- attack.impact
- attack.defense-impairment
- attack.t1112
- attack.t1491.001
logsource:
product: windows
category: registry_set
detection:
selection_keys:
TargetObject|contains:
- Control Panel\Desktop
- CurrentVersion\Policies\ActiveDesktop
- CurrentVersion\Policies\System
selection_values_1:
TargetObject|endswith: NoChangingWallpaper
Details: DWORD (0x00000001)
selection_values_2:
TargetObject|endswith: \Wallpaper
selection_values_3:
TargetObject|endswith: \WallpaperStyle
Details: "2"
filter_main_svchost:
Image|endswith: \svchost.exe
filter_main_empty:
TargetObject|endswith: \Control Panel\Desktop\Wallpaper
Details: (Empty)
filter_main_explorer:
Image|endswith: C:\Windows\Explorer.EXE
filter_optional_ec2launch:
Image:
- C:\Program Files\Amazon\EC2Launch\EC2Launch.exe
- C:\Program Files (x86)\Amazon\EC2Launch\EC2Launch.exe
TargetObject|endswith: \Control Panel\Desktop\Wallpaper
condition: selection_keys and 1 of selection_values_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Administrative scripts that change the desktop background to a company logo or other image.
level: medium
license: DRL-1.1
What it detects
This rule flags registry value modifications under desktop-related policy paths that would replace the current desktop background, including settings tied to wallpaper enforcement and disabling user changes. Such changes can be used to persistently present ransom notes or other malicious imagery and to impair user defenses by preventing normal wallpaper restoration. It relies on telemetry showing registry value sets to specific target objects and values, while filtering out changes attributed to typical system components and a known EC2 launch utility.
Known false positives
- Administrative scripts that change the desktop background to a company logo or other image.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.