ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
MalwareRunningRAT

RunningRAT contains code to delete files from the victim’s machine.

T1070.004
File Deletion
MalwareExbyte

Exbyte will self-delete if a hard-coded configuration file is not found.

T1070.004
File Deletion
MalwareDarkWatchman

DarkWatchman has been observed deleting its original launcher after installation.

T1070.004
File Deletion
MalwareBBSRAT

BBSRAT can delete files and directories.

T1070.004
File Deletion
MalwarePlugX

PlugX has the remove itself and other artifacts.

T1070.004
File Deletion
MalwareReaver

Reaver deletes the original dropped file from the victim.

T1070.004
File Deletion
MalwareBisonal

Bisonal will delete its dropper and VBS scripts from the victim’s machine.

T1070.004
File Deletion
MalwareMultiLayer Wiper

MultiLayer Wiper uses a batch file, remover.bat to delete malware artifacts and the batch file itself during execution.

T1070.004
File Deletion
MalwareNOOPLDR

NOOPLDR can delete a file containing configuration instructions after use.

T1070.004
File Deletion
MalwareS-Type

S-Type has deleted files it has created on a compromised host.

T1070.004
File Deletion
MalwareSeaDuke

SeaDuke can securely delete files, including deleting itself from the victim.

T1070.004
File Deletion
MalwareDustySky

DustySky can delete files it creates from the infected system.

T1070.004
File Deletion
MalwareRemsec

Remsec is capable of deleting files on the victim. It also securely removes itself after collecting and exfiltrating data.

T1070.004
File Deletion
MalwareEpic

Epic has a command to delete a file from the machine.

T1070.004
File Deletion
MalwareLightNeuron

LightNeuron has a function to delete files.

T1070.004
File Deletion
MalwareCuba

Cuba can use the command cmd.exe /c del to delete its artifacts from the system.

T1070.004
File Deletion
MalwarePureCrypter

PureCrypter can execute a PowerShell command to self-delete.

T1070.004
File Deletion
MalwareDarkGate

DarkGate has deleted its staging directories.

T1070.004
File Deletion
MalwareNanHaiShu

NanHaiShu launches a script to delete their original decoy file to cover tracks.

T1070.004
File Deletion
MalwareLockBit 3.0

LockBit 3.0 can delete itself from disk.

T1070.004
File Deletion
MalwareCarbanak

Carbanak has a command to delete files.

T1070.004
File Deletion
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can delete files.

T1070.004
File Deletion
MalwareFerocious

Ferocious can delete files from a compromised host.

T1070.004
File Deletion
MalwareElise

Elise is capable of launching a remote shell on the host to delete itself.

T1070.004
File Deletion
MalwareGazer

Gazer has commands to delete files and persistence mechanisms from the victim.

T1070.004
File Deletion
MalwareLatrodectus

Latrodectus has the ability to delete itself.

T1070.004
File Deletion
MalwareSaint Bot

Saint Bot can run a batch script named `del.bat` to remove any Saint Bot payload-linked files from a compromise system if anti-analysis or locale checks fail.

T1070.004
File Deletion
MalwarePay2Key

Pay2Key can remove its log file from disk.

T1070.004
File Deletion
MalwareLODEINFO

LODEINFO can delete files to remove traces of activity from victim systems.

T1070.004
File Deletion
MalwareCharmPower

CharmPower can delete created files from a compromised system.

T1070.004
File Deletion
MalwareTYPEFRAME

TYPEFRAME can delete files off the system.

T1070.004
File Deletion
MalwareMori

Mori can delete its DLL file and related files by Registry value.

T1070.004
File Deletion
MalwareQUADAGENT

QUADAGENT has a command to delete its Registry key and scheduled task.

T1070.004
File Deletion
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can delete files from a compromised host.

T1070.004
File Deletion
Malwarepngdowner

pngdowner deletes content from C2 communications that was saved to the user's temporary directory.

T1070.004
File Deletion
MalwareUroburos

Uroburos can run a `Clear Agents Track` command on an infected machine to delete Uroburos-related logs.

T1070.004
File Deletion
MalwareMetamorfo

Metamorfo has deleted itself from the system after execution.

T1070.004
File Deletion
MalwareEmbargo

Embargo has leveraged MDeployer to terminate the MS4Killer process, delete the decrypted payload files and a driver file dropped by MS4killer, and reboot the system.

T1070.004
File Deletion
MalwareTrojan.Karagany

Trojan.Karagany has used plugins with a self-delete capability.

T1070.004
File Deletion
MalwareBandook

Bandook has a command to delete a file.

T1070.004
File Deletion
MalwareMagicRAT

MagicRAT can delete files on victim systems, including itself.

T1070.004
File Deletion
MalwareKONNI

KONNI can delete files.

T1070.004
File Deletion
Malwaregh0st RAT

gh0st RAT has the capability to to delete files.

T1070.004
File Deletion
MalwareJHUHUGIT

The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files.

T1070.004
File Deletion
MalwareBLUELIGHT

BLUELIGHT can uninstall itself.

T1070.004
File Deletion
MalwareIxeshe

Ixeshe has a command to delete a file from the machine.

T1070.004
File Deletion
MalwareVBShower

VBShower has attempted to complicate forensic analysis by deleting all the files contained in %APPDATA%\..\Local\Temporary Internet Files\Content.Word and %APPDATA%\..\Local Settings\Temporary Internet Files\Content.Word\.

T1070.004
File Deletion
MalwareBPFDoor

After initial setup, BPFDoor's original execution process deletes the dropped binary and exits.

T1070.004
File Deletion
MalwareStoneDrill

StoneDrill has been observed deleting the temporary files once they fulfill their task.

T1070.004
File Deletion
MalwareOopsIE

OopsIE has the capability to delete files and scripts from the victim's machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.