Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
MalwareRunningRAT | RunningRAT contains code to delete files from the victim’s machine. |
| T1070.004 File Deletion |
MalwareExbyte | Exbyte will self-delete if a hard-coded configuration file is not found. |
| T1070.004 File Deletion |
MalwareDarkWatchman | DarkWatchman has been observed deleting its original launcher after installation. |
| T1070.004 File Deletion |
MalwareBBSRAT | BBSRAT can delete files and directories. |
| T1070.004 File Deletion |
MalwarePlugX | PlugX has the remove itself and other artifacts. |
| T1070.004 File Deletion |
MalwareReaver | Reaver deletes the original dropped file from the victim. |
| T1070.004 File Deletion |
MalwareBisonal | Bisonal will delete its dropper and VBS scripts from the victim’s machine. |
| T1070.004 File Deletion |
MalwareMultiLayer Wiper | MultiLayer Wiper uses a batch file, |
| T1070.004 File Deletion |
MalwareNOOPLDR | NOOPLDR can delete a file containing configuration instructions after use. |
| T1070.004 File Deletion |
MalwareS-Type | S-Type has deleted files it has created on a compromised host. |
| T1070.004 File Deletion |
MalwareSeaDuke | SeaDuke can securely delete files, including deleting itself from the victim. |
| T1070.004 File Deletion |
MalwareDustySky | DustySky can delete files it creates from the infected system. |
| T1070.004 File Deletion |
MalwareRemsec | Remsec is capable of deleting files on the victim. It also securely removes itself after collecting and exfiltrating data. |
| T1070.004 File Deletion |
MalwareEpic | Epic has a command to delete a file from the machine. |
| T1070.004 File Deletion |
MalwareLightNeuron | LightNeuron has a function to delete files. |
| T1070.004 File Deletion |
MalwareCuba | Cuba can use the command |
| T1070.004 File Deletion |
MalwarePureCrypter | PureCrypter can execute a PowerShell command to self-delete. |
| T1070.004 File Deletion |
MalwareDarkGate | DarkGate has deleted its staging directories. |
| T1070.004 File Deletion |
MalwareNanHaiShu | NanHaiShu launches a script to delete their original decoy file to cover tracks. |
| T1070.004 File Deletion |
MalwareLockBit 3.0 | LockBit 3.0 can delete itself from disk. |
| T1070.004 File Deletion |
MalwareCarbanak | Carbanak has a command to delete files. |
| T1070.004 File Deletion |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can delete files. |
| T1070.004 File Deletion |
MalwareFerocious | Ferocious can delete files from a compromised host. |
| T1070.004 File Deletion |
MalwareElise | Elise is capable of launching a remote shell on the host to delete itself. |
| T1070.004 File Deletion |
MalwareGazer | Gazer has commands to delete files and persistence mechanisms from the victim. |
| T1070.004 File Deletion |
MalwareLatrodectus | Latrodectus has the ability to delete itself. |
| T1070.004 File Deletion |
MalwareSaint Bot | Saint Bot can run a batch script named `del.bat` to remove any Saint Bot payload-linked files from a compromise system if anti-analysis or locale checks fail. |
| T1070.004 File Deletion |
MalwarePay2Key | Pay2Key can remove its log file from disk. |
| T1070.004 File Deletion |
MalwareLODEINFO | LODEINFO can delete files to remove traces of activity from victim systems. |
| T1070.004 File Deletion |
MalwareCharmPower | CharmPower can delete created files from a compromised system. |
| T1070.004 File Deletion |
MalwareTYPEFRAME | TYPEFRAME can delete files off the system. |
| T1070.004 File Deletion |
MalwareMori | Mori can delete its DLL file and related files by Registry value. |
| T1070.004 File Deletion |
MalwareQUADAGENT | QUADAGENT has a command to delete its Registry key and scheduled task. |
| T1070.004 File Deletion |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can delete files from a compromised host. |
| T1070.004 File Deletion |
Malwarepngdowner | pngdowner deletes content from C2 communications that was saved to the user's temporary directory. |
| T1070.004 File Deletion |
MalwareUroburos | Uroburos can run a `Clear Agents Track` command on an infected machine to delete Uroburos-related logs. |
| T1070.004 File Deletion |
MalwareMetamorfo | Metamorfo has deleted itself from the system after execution. |
| T1070.004 File Deletion |
MalwareEmbargo | Embargo has leveraged MDeployer to terminate the MS4Killer process, delete the decrypted payload files and a driver file dropped by MS4killer, and reboot the system. |
| T1070.004 File Deletion |
MalwareTrojan.Karagany | Trojan.Karagany has used plugins with a self-delete capability. |
| T1070.004 File Deletion |
MalwareBandook | Bandook has a command to delete a file. |
| T1070.004 File Deletion |
MalwareMagicRAT | MagicRAT can delete files on victim systems, including itself. |
| T1070.004 File Deletion |
MalwareKONNI | KONNI can delete files. |
| T1070.004 File Deletion |
Malwaregh0st RAT | gh0st RAT has the capability to to delete files. |
| T1070.004 File Deletion |
MalwareJHUHUGIT | The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files. |
| T1070.004 File Deletion |
MalwareBLUELIGHT | BLUELIGHT can uninstall itself. |
| T1070.004 File Deletion |
MalwareIxeshe | Ixeshe has a command to delete a file from the machine. |
| T1070.004 File Deletion |
MalwareVBShower | VBShower has attempted to complicate forensic analysis by deleting all the files contained in |
| T1070.004 File Deletion |
MalwareBPFDoor | After initial setup, BPFDoor's original execution process deletes the dropped binary and exits. |
| T1070.004 File Deletion |
MalwareStoneDrill | StoneDrill has been observed deleting the temporary files once they fulfill their task. |
| T1070.004 File Deletion |
MalwareOopsIE | OopsIE has the capability to delete files and scripts from the victim's machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.