ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
GroupAPT28

APT28 has intentionally deleted computer files to cover their tracks, including with use of the program CCleaner.

T1070.004
File Deletion
GroupMetador

Metador has quickly deleted `cbd.exe` from a compromised host following the successful deployment of their malware.

T1070.004
File Deletion
GroupAPT5

APT5 has deleted scripts and web shells to evade detection.

T1070.004
File Deletion
GroupLazarus Group

Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim. Lazarus Group also uses secure file deletion to delete files from the victim.

T1070.004
File Deletion
GroupINC Ransom

INC Ransom has uninstalled tools from compromised endpoints after use.

T1070.004
File Deletion
GroupSilence

Silence has deleted artifacts, including scheduled tasks, communicates files from the C2 and other logs.

T1070.004
File Deletion
GroupCobalt Group

Cobalt Group deleted the DLL dropper from the victim’s machine to cover their tracks.

T1070.004
File Deletion
GroupWizard Spider

Wizard Spider has used file deletion to remove some modules and configurations from an infected host after use.

T1070.004
File Deletion
GroupPlay

Play has used tools including Wevtutil to remove malicious files from compromised hosts.

T1070.004
File Deletion
GroupMagic Hound

Magic Hound has deleted and overwrote files to cover tracks.

T1070.004
File Deletion
GroupThreat Group-3390

Threat Group-3390 has deleted existing logs and exfiltrated file archives from a victim.

T1070.004
File Deletion
GroupFIN10

FIN10 has used batch scripts and scheduled tasks to delete critical system files.

T1070.004
File Deletion
GroupFIN8

FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines.

T1070.004
File Deletion
MalwarePowerDuke

PowerDuke has a command to write random data across a file and delete it.

T1070.004
File Deletion
MalwareBLINDINGCAN

BLINDINGCAN has deleted itself and associated artifacts from victim machines.

T1070.004
File Deletion
MalwareRCSession

RCSession can remove files from a targeted system.

T1070.004
File Deletion
MalwareBumblebee

Bumblebee can uninstall its loader through the use of a `Sdl` command.

T1070.004
File Deletion
MalwareBRICKSTORM

BRICKSTORM has the ability to delete files and directories. BRICKSTORM also has deleted installer files after execution to reduce detection.

T1070.004
File Deletion
MalwareMURKYTOP

MURKYTOP has the capability to delete local files.

T1070.004
File Deletion
MalwareRDFSNIFFER

RDFSNIFFER has the capability of deleting local files.

T1070.004
File Deletion
MalwareNICECURL

NICECURL has a function to remove artifacts.

T1070.004
File Deletion
MalwareProxysvc

Proxysvc can delete files indicated by the attacker and remove itself from disk using a batch file.

T1070.004
File Deletion
MalwareNOKKI

NOKKI can delete files to cover tracks.

T1070.004
File Deletion
MalwareBackdoor.Oldrea

Backdoor.Oldrea contains a cleanup module that removes traces of itself from the victim.

T1070.004
File Deletion
MalwareStuxnet

Stuxnet uses an RPC server that contains a routine for file deletion and also removes itself from the system through a DLL export by deleting specific files.

T1070.004
File Deletion
MalwareVersaMem

VersaMem deleted files related to initial installation such as temporary files related to the PID of the main web process.

T1070.004
File Deletion
MalwareTDTESS

TDTESS creates then deletes log files during installation of itself as a service.

T1070.004
File Deletion
MalwareCOATHANGER

COATHANGER removes files from victim environments following use in multiple instances.

T1070.004
File Deletion
MalwareHALFBAKED

HALFBAKED can delete a specified file.

T1070.004
File Deletion
MalwareWindTail

WindTail has the ability to receive and execute a self-delete command.

T1070.004
File Deletion
MalwareMisdat

Misdat is capable of deleting the backdoor file.

T1070.004
File Deletion
MalwareExaramel for Linux

Exaramel for Linux can uninstall its persistence mechanism and delete its configuration file.

T1070.004
File Deletion
MalwareKEYMARBLE

KEYMARBLE has the capability to delete files off the victim’s machine.

T1070.004
File Deletion
MalwareHAWKBALL

HAWKBALL has the ability to delete files.

T1070.004
File Deletion
MalwareUrsnif

Ursnif has deleted data staged in tmp files after exfiltration.

T1070.004
File Deletion
MalwareRansomHub

RansomHub has the ability to self-delete.

T1070.004
File Deletion
MalwareRedLeaves

RedLeaves can delete specified files.

T1070.004
File Deletion
MalwareZeus Panda

Zeus Panda has a command to delete a file. It also can uninstall scripts and delete files to cover its track.

T1070.004
File Deletion
MalwareCARROTBAT

CARROTBAT has the ability to delete downloaded files from a compromised host.

T1070.004
File Deletion
MalwareBankshot

Bankshot marks files to be deleted upon the next system reboot and uninstalls and removes itself from the system.

T1070.004
File Deletion
MalwareStrongPity

StrongPity can delete previously exfiltrated files from the compromised host.

T1070.004
File Deletion
MalwarePony

Pony has used scripts to delete itself after execution.

T1070.004
File Deletion
MalwareNebulae

Nebulae has the ability to delete files and directories.

T1070.004
File Deletion
MalwareAuditCred

AuditCred can delete files from the system.

T1070.004
File Deletion
MalwareTONESHELL

TONESHELL has deleted payload files received from the C2 server.

T1070.004
File Deletion
MalwareUPSTYLE

UPSTYLE removes `bootstrap.min.css` after parsing command and control instructions, restoring the file to its original state.

T1070.004
File Deletion
MalwareOceanSalt

OceanSalt can delete files from the system.

T1070.004
File Deletion
MalwareMedusa Ransomware

Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`.

T1070.004
File Deletion
MalwareRainyDay

RainyDay has the ability to uninstall itself by deleting its service and files.

T1070.004
File Deletion
MalwareAppleSeed

AppleSeed can delete files from a compromised host after they are exfiltrated.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.