ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1070.003
Clear Command History
MalwareJ-magic

J-magic can overwrite previously executed command line arguments.

T1070.003
Clear Command History
MalwareHildegard

Hildegard has used history -c to clear script shell logs.

T1070.003
Clear Command History
MalwareKobalos

Kobalos can remove all command history on compromised hosts.

T1070.004
File Deletion
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group removed all previously delivered files from a compromised computer.

T1070.004
File Deletion
CampaignKV Botnet Activity

KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device.

T1070.004
File Deletion
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capaple of removing scripts after execution.

T1070.004
File Deletion
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used batch files that reduced their fingerprint on a compromised system by deleting malware-related files.

T1070.004
File Deletion
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, vba_macro.exe deletes itself after `FONTCACHE.DAT`, `rundll32.exe`, and the associated .lnk file is delivered.

T1070.004
File Deletion
CampaignCutting Edge

During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files.

T1070.004
File Deletion
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe.

T1070.004
File Deletion
CampaignC0032

During the C0032 campaign, TEMP.Veles routinely deleted tools, logs, and other files after they were finished with them.

T1070.004
File Deletion
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 routinely removed their tools, including custom backdoors, once remote access was achieved.

T1070.004
File Deletion
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace deleted delivered tools and files from compromised hosts.

T1070.004
File Deletion
CampaignArcaneDoor

ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions.

T1070.004
File Deletion
CampaignAPT41 DUST

APT41 DUST deleted various artifacts from victim systems following use.

T1070.004
File Deletion
CampaignOperation Wocao

During Operation Wocao, the threat actors consistently removed traces of their activity by first overwriting a file using `/c cd /d c:\windows\temp\ & copy \\<IP ADDRESS>\c$\windows\system32\devmgr.dll \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1 /y` and then deleting the overwritten file using `/c cd /d c:\windows\temp\ & del \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1`.

T1070.004
File Deletion
GroupAPT38

APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process.

T1070.004
File Deletion
GroupBlackByte

BlackByte deleted ransomware executables post-encryption.

T1070.004
File Deletion
GroupAPT3

APT3 has a tool that can delete files.

T1070.004
File Deletion
GroupKimsuky

Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk. Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads. Kimsuky has also removed remnants of files used for delivery to include .log and .zip files.

T1070.004
File Deletion
GroupVolt Typhoon

Volt Typhoon has run `rd /S` to delete their working directories and deleted systeminfo.dat from `C:\Users\Public\Documentsfiles`.

T1070.004
File Deletion
GroupPatchwork

Patchwork removed certain files and replaced them so they could not be retrieved.

T1070.004
File Deletion
GroupAPT41

APT41 deleted files from the system.

T1070.004
File Deletion
GroupDragonfly

Dragonfly has deleted many of its files used during operations as part of cleanup, including removing applications and deleting screenshots.

T1070.004
File Deletion
GroupEvilnum

Evilnum has deleted files used during infection.

T1070.004
File Deletion
GroupmenuPass

A menuPass macro deletes files after it has decoded and decompressed them.

T1070.004
File Deletion
GroupAPT32

APT32's macOS backdoor can receive a “delete” command.

T1070.004
File Deletion
GroupFIN6

FIN6 has removed files from victim machines.

T1070.004
File Deletion
GroupGamaredon Group

Gamaredon Group tools can delete files used during an operation.

T1070.004
File Deletion
GroupTeamTNT

TeamTNT has used a payload that removes itself after running. TeamTNT also has deleted locally staged files for collecting credentials or scan results for local IP addresses after exfiltrating them.

T1070.004
File Deletion
GroupSandworm Team

Sandworm Team has used backdoors that can delete files used in an attack from an infected system.

T1070.004
File Deletion
GroupAPT18

APT18 actors deleted tools and batch files from victim systems.

T1070.004
File Deletion
GroupMustang Panda

Mustang Panda will delete their tools and files, and kill processes after their objectives are reached.

T1070.004
File Deletion
GroupRocke

Rocke has deleted files on infected machines.

T1070.004
File Deletion
GroupAPT39

APT39 has used malware to delete files after they are deployed on a compromised host.

T1070.004
File Deletion
GroupUNC3886

UNC3886 has used the the esxcli command line to remove files created by malicious vSphere Installation Bundles from disk.

T1070.004
File Deletion
GroupContagious Interview

Contagious Interview has configured malware to remove archives used in collection activities following successful exfiltration.

T1070.004
File Deletion
GroupOilRig

OilRig has deleted files associated with their payload after execution.

T1070.004
File Deletion
GroupTropic Trooper

Tropic Trooper has deleted dropper files on an infected system using command scripts.

T1070.004
File Deletion
GroupAquatic Panda

Aquatic Panda has deleted malicious executables from compromised machines.

T1070.004
File Deletion
GroupThe White Company

The White Company has the ability to delete its malware entirely from the target system.

T1070.004
File Deletion
GroupGroup5

Malware used by Group5 is capable of remotely deleting files from victims.

T1070.004
File Deletion
GroupRedCurl

RedCurl has deleted files after execution.

T1070.004
File Deletion
GroupFIN5

FIN5 uses SDelete to clean up the environment and attempt to prevent detection.

T1070.004
File Deletion
GroupAPT29

APT29 has used SDelete to remove artifacts from victim networks.

T1070.004
File Deletion
GroupChimera

Chimera has performed file deletion to evade detection.

T1070.004
File Deletion
GroupMirrorFace

MirrorFace has deleted directories containing malware and archives with files collected from the victim environment.

T1070.004
File Deletion
GroupMedusa Group

Medusa Group has deleted previously installed tools.

T1070.004
File Deletion
GroupBRONZE BUTLER

The BRONZE BUTLER uploader or malware the uploader uses command to delete the RAR archives after they have been exfiltrated.

T1070.004
File Deletion
GroupEmber Bear

Ember Bear deletes files related to lateral movement to avoid detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.