Windows Registry Change to Desktop Wallpaper Policy or Settings

Detects Windows registry updates that enforce or change the desktop wallpaper and restrict user control.

FreeUnreviewedSigmamediumv1
title: Windows Registry Change to Desktop Wallpaper Policy or Settings
id: 742de765-bfff-40a2-829d-a601b1952e7c
related:
  - id: 8cbc9475-8d05-4e27-9c32-df960716c701
    type: similar
  - id: 85b88e05-dadc-430b-8a9e-53ff1cd30aae
    type: derived
status: test
description: This rule flags registry value modifications under desktop-related policy paths that would replace the current desktop background, including settings tied to wallpaper enforcement and disabling user changes. Such changes can be used to persistently present ransom notes or other malicious imagery and to impair user defenses by preventing normal wallpaper restoration. It relies on telemetry showing registry value sets to specific target objects and values, while filtering out changes attributed to typical system components and a known EC2 launch utility.
references:
  - https://www.attackiq.com/2023/09/20/emulating-rhysida/
  - https://research.checkpoint.com/2023/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society/
  - https://www.trendmicro.com/en_us/research/23/h/an-overview-of-the-new-rhysida-ransomware.html
  - https://www.virustotal.com/gui/file/a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6/behavior
  - https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.WindowsDesktop::Wallpaper
  - https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.ControlPanelDisplay::CPL_Personalization_NoDesktopBackgroundUI
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_desktop_background_change.yml
author: Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ), Huntrule Team
date: 2023-12-21
modified: 2025-10-17
tags:
  - attack.persistence
  - attack.impact
  - attack.defense-impairment
  - attack.t1112
  - attack.t1491.001
logsource:
  product: windows
  category: registry_set
detection:
  selection_keys:
    TargetObject|contains:
      - Control Panel\Desktop
      - CurrentVersion\Policies\ActiveDesktop
      - CurrentVersion\Policies\System
  selection_values_1:
    TargetObject|endswith: NoChangingWallpaper
    Details: DWORD (0x00000001)
  selection_values_2:
    TargetObject|endswith: \Wallpaper
  selection_values_3:
    TargetObject|endswith: \WallpaperStyle
    Details: "2"
  filter_main_svchost:
    Image|endswith: \svchost.exe
  filter_main_empty:
    TargetObject|endswith: \Control Panel\Desktop\Wallpaper
    Details: (Empty)
  filter_main_explorer:
    Image|endswith: C:\Windows\Explorer.EXE
  filter_optional_ec2launch:
    Image:
      - C:\Program Files\Amazon\EC2Launch\EC2Launch.exe
      - C:\Program Files (x86)\Amazon\EC2Launch\EC2Launch.exe
    TargetObject|endswith: \Control Panel\Desktop\Wallpaper
  condition: selection_keys and 1 of selection_values_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Administrative scripts that change the desktop background to a company logo or other image.
level: medium
license: DRL-1.1

What it detects

This rule flags registry value modifications under desktop-related policy paths that would replace the current desktop background, including settings tied to wallpaper enforcement and disabling user changes. Such changes can be used to persistently present ransom notes or other malicious imagery and to impair user defenses by preventing normal wallpaper restoration. It relies on telemetry showing registry value sets to specific target objects and values, while filtering out changes attributed to typical system components and a known EC2 launch utility.

Known false positives

  • Administrative scripts that change the desktop background to a company logo or other image.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.