Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
GroupAPT28 | APT28 has intentionally deleted computer files to cover their tracks, including with use of the program CCleaner. |
| T1070.004 File Deletion |
GroupMetador | Metador has quickly deleted `cbd.exe` from a compromised host following the successful deployment of their malware. |
| T1070.004 File Deletion |
GroupAPT5 | APT5 has deleted scripts and web shells to evade detection. |
| T1070.004 File Deletion |
GroupLazarus Group | Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim. Lazarus Group also uses secure file deletion to delete files from the victim. |
| T1070.004 File Deletion |
GroupINC Ransom | INC Ransom has uninstalled tools from compromised endpoints after use. |
| T1070.004 File Deletion |
GroupSilence | Silence has deleted artifacts, including scheduled tasks, communicates files from the C2 and other logs. |
| T1070.004 File Deletion |
GroupCobalt Group | Cobalt Group deleted the DLL dropper from the victim’s machine to cover their tracks. |
| T1070.004 File Deletion |
GroupWizard Spider | Wizard Spider has used file deletion to remove some modules and configurations from an infected host after use. |
| T1070.004 File Deletion |
GroupPlay | Play has used tools including Wevtutil to remove malicious files from compromised hosts. |
| T1070.004 File Deletion |
GroupMagic Hound | Magic Hound has deleted and overwrote files to cover tracks. |
| T1070.004 File Deletion |
GroupThreat Group-3390 | Threat Group-3390 has deleted existing logs and exfiltrated file archives from a victim. |
| T1070.004 File Deletion |
GroupFIN10 | FIN10 has used batch scripts and scheduled tasks to delete critical system files. |
| T1070.004 File Deletion |
GroupFIN8 | FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines. |
| T1070.004 File Deletion |
MalwarePowerDuke | PowerDuke has a command to write random data across a file and delete it. |
| T1070.004 File Deletion |
MalwareBLINDINGCAN | BLINDINGCAN has deleted itself and associated artifacts from victim machines. |
| T1070.004 File Deletion |
MalwareRCSession | RCSession can remove files from a targeted system. |
| T1070.004 File Deletion |
MalwareBumblebee | Bumblebee can uninstall its loader through the use of a `Sdl` command. |
| T1070.004 File Deletion |
MalwareBRICKSTORM | BRICKSTORM has the ability to delete files and directories. BRICKSTORM also has deleted installer files after execution to reduce detection. |
| T1070.004 File Deletion |
MalwareMURKYTOP | MURKYTOP has the capability to delete local files. |
| T1070.004 File Deletion |
MalwareRDFSNIFFER | RDFSNIFFER has the capability of deleting local files. |
| T1070.004 File Deletion |
MalwareNICECURL | NICECURL has a function to remove artifacts. |
| T1070.004 File Deletion |
MalwareProxysvc | Proxysvc can delete files indicated by the attacker and remove itself from disk using a batch file. |
| T1070.004 File Deletion |
MalwareNOKKI | NOKKI can delete files to cover tracks. |
| T1070.004 File Deletion |
MalwareBackdoor.Oldrea | Backdoor.Oldrea contains a cleanup module that removes traces of itself from the victim. |
| T1070.004 File Deletion |
MalwareStuxnet | Stuxnet uses an RPC server that contains a routine for file deletion and also removes itself from the system through a DLL export by deleting specific files. |
| T1070.004 File Deletion |
MalwareVersaMem | VersaMem deleted files related to initial installation such as temporary files related to the PID of the main web process. |
| T1070.004 File Deletion |
MalwareTDTESS | TDTESS creates then deletes log files during installation of itself as a service. |
| T1070.004 File Deletion |
MalwareCOATHANGER | COATHANGER removes files from victim environments following use in multiple instances. |
| T1070.004 File Deletion |
MalwareHALFBAKED | HALFBAKED can delete a specified file. |
| T1070.004 File Deletion |
MalwareWindTail | WindTail has the ability to receive and execute a self-delete command. |
| T1070.004 File Deletion |
MalwareMisdat | Misdat is capable of deleting the backdoor file. |
| T1070.004 File Deletion |
MalwareExaramel for Linux | Exaramel for Linux can uninstall its persistence mechanism and delete its configuration file. |
| T1070.004 File Deletion |
MalwareKEYMARBLE | KEYMARBLE has the capability to delete files off the victim’s machine. |
| T1070.004 File Deletion |
MalwareHAWKBALL | HAWKBALL has the ability to delete files. |
| T1070.004 File Deletion |
MalwareUrsnif | Ursnif has deleted data staged in tmp files after exfiltration. |
| T1070.004 File Deletion |
MalwareRansomHub | RansomHub has the ability to self-delete. |
| T1070.004 File Deletion |
MalwareRedLeaves | RedLeaves can delete specified files. |
| T1070.004 File Deletion |
MalwareZeus Panda | Zeus Panda has a command to delete a file. It also can uninstall scripts and delete files to cover its track. |
| T1070.004 File Deletion |
MalwareCARROTBAT | CARROTBAT has the ability to delete downloaded files from a compromised host. |
| T1070.004 File Deletion |
MalwareBankshot | Bankshot marks files to be deleted upon the next system reboot and uninstalls and removes itself from the system. |
| T1070.004 File Deletion |
MalwareStrongPity | StrongPity can delete previously exfiltrated files from the compromised host. |
| T1070.004 File Deletion |
MalwarePony | Pony has used scripts to delete itself after execution. |
| T1070.004 File Deletion |
MalwareNebulae | Nebulae has the ability to delete files and directories. |
| T1070.004 File Deletion |
MalwareAuditCred | AuditCred can delete files from the system. |
| T1070.004 File Deletion |
MalwareTONESHELL | TONESHELL has deleted payload files received from the C2 server. |
| T1070.004 File Deletion |
MalwareUPSTYLE | UPSTYLE removes `bootstrap.min.css` after parsing command and control instructions, restoring the file to its original state. |
| T1070.004 File Deletion |
MalwareOceanSalt | OceanSalt can delete files from the system. |
| T1070.004 File Deletion |
MalwareMedusa Ransomware | Medusa Ransomware has the ability to delete itself after execution. Medusa Ransomware also has the ability to delete itself after execution through the command `cmd /c ping localhost -n 3 > nul & del`. |
| T1070.004 File Deletion |
MalwareRainyDay | RainyDay has the ability to uninstall itself by deleting its service and files. |
| T1070.004 File Deletion |
MalwareAppleSeed | AppleSeed can delete files from a compromised host after they are exfiltrated. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.