Real-world descriptions of how a group, tool or campaign used a technique.
251 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
MalwareODAgent | ODAgent can delete payloads and files used to pass C2 commands from remotely hosted cloud accounts. |
| T1070.004 File Deletion |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware deletes itself following device encryption. |
| T1070.004 File Deletion |
MalwareFlawedAmmyy | FlawedAmmyy can execute batch scripts to delete files. |
| T1070.004 File Deletion |
MalwareGuLoader | GuLoader can delete its executable from the |
| T1070.004 File Deletion |
MalwareProLock | ProLock can remove files containing its payload after they are executed. |
| T1070.004 File Deletion |
MalwareInvisiMole | InvisiMole has deleted files and directories including XML and files successfully uploaded to C2 servers. |
| T1070.004 File Deletion |
MalwareP.A.S. Webshell | P.A.S. Webshell can delete scripts from a subdirectory of /tmp after they are run. |
| T1070.004 File Deletion |
MalwareApostle | Apostle writes batch scripts to disk, such as |
| T1070.004 File Deletion |
MalwareVolgmer | Volgmer can delete files and itself after infection to avoid analysis. |
| T1070.004 File Deletion |
MalwareWhisperGate | WhisperGate can delete tools from a compromised host after execution. |
| T1070.004 File Deletion |
MalwareFruitFly | FruitFly will delete files on the system. |
| T1070.004 File Deletion |
MalwareAcidPour | AcidPour includes a self-delete function where the malware deletes itself from disk after execution and program load into memory. |
| T1070.004 File Deletion |
MalwareRDAT | RDAT can issue SOAP requests to delete already processed C2 emails. RDAT can also delete itself from the infected system. |
| T1070.004 File Deletion |
MalwareOkrum | Okrum's backdoor deletes files after they have been successfully uploaded to C2 servers. |
| T1070.004 File Deletion |
MalwareSamSam | SamSam has been seen deleting its own files and payloads to make analysis of the attack more difficult. |
| T1070.004 File Deletion |
MalwareRaspberry Robin | Raspberry Robin can delete its initial delivery script from disk during execution. |
| T1070.004 File Deletion |
MalwareFysbis | Fysbis has the ability to delete files. |
| T1070.004 File Deletion |
MalwareVERMIN | VERMIN can delete files on the victim’s machine. |
| T1070.004 File Deletion |
MalwareNightdoor | Nightdoor can self-delete. |
| T1070.004 File Deletion |
MalwareHTTPTroy | HTTPTroy can terminate its running process and then remove traces of itself through the `die <COMMAND>` command. |
| T1070.004 File Deletion |
MalwarePowerShower | PowerShower has the ability to remove all files created during the dropper process. |
| T1070.004 File Deletion |
MalwareKazuar | Kazuar can delete files. |
| T1070.004 File Deletion |
MalwareFatDuke | FatDuke can secure delete its DLL. |
| T1070.004 File Deletion |
MalwarezwShell | zwShell has deleted itself after creating a service as well as deleted a temporary file when the system reboots. |
| T1070.004 File Deletion |
MalwareRising Sun | Rising Sun can delete files and artifacts it creates. |
| T1070.004 File Deletion |
MalwareShimRat | ShimRat can uninstall itself from compromised hosts, as well create and modify directories, delete, move, copy, and rename files. |
| T1070.004 File Deletion |
MalwareHi-Zor | Hi-Zor deletes its RAT installer file as it executes its DLL payload file. |
| T1070.004 File Deletion |
MalwareXAgentOSX | XAgentOSX contains the deletFileFromPath function to delete a specified file using the NSFileManager:removeFileAtPath method. |
| T1070.004 File Deletion |
MalwareGreen Lambert | Green Lambert can delete the original executable after initial installation in addition to unused functions. |
| T1070.004 File Deletion |
MalwareLockerGoga | LockerGoga has been observed deleting its original launcher after execution. |
| T1070.004 File Deletion |
MalwarePUNCHBUGGY | PUNCHBUGGY can delete files written to disk. |
| T1070.004 File Deletion |
MalwareHyperBro | HyperBro has the ability to delete a specified file. |
| T1070.004 File Deletion |
MalwareAnchor | Anchor can self delete its dropper after the malware is successfully deployed. |
| T1070.004 File Deletion |
MalwareLine Runner | Line Runner removes its initial ZIP delivery archive after processing the enclosed LUA script. |
| T1070.004 File Deletion |
MalwarePteranodon | Pteranodon can delete files that may interfere with it executing. It also can delete temporary files and itself after the initial script executes. |
| T1070.004 File Deletion |
MalwareBeaverTail | BeaverTail has deleted files from a compromised host after they were exfiltrated. |
| T1070.004 File Deletion |
MalwareROKRAT | ROKRAT can request to delete files. |
| T1070.004 File Deletion |
MalwareRunningRAT | RunningRAT contains code to delete files from the victim’s machine. |
| T1070.004 File Deletion |
MalwareExbyte | Exbyte will self-delete if a hard-coded configuration file is not found. |
| T1070.004 File Deletion |
MalwareDarkWatchman | DarkWatchman has been observed deleting its original launcher after installation. |
| T1070.004 File Deletion |
MalwareBBSRAT | BBSRAT can delete files and directories. |
| T1070.004 File Deletion |
MalwarePlugX | PlugX has the remove itself and other artifacts. |
| T1070.004 File Deletion |
MalwareReaver | Reaver deletes the original dropped file from the victim. |
| T1070.004 File Deletion |
MalwareBisonal | Bisonal will delete its dropper and VBS scripts from the victim’s machine. |
| T1070.004 File Deletion |
MalwareMultiLayer Wiper | MultiLayer Wiper uses a batch file, |
| T1070.004 File Deletion |
MalwareNOOPLDR | NOOPLDR can delete a file containing configuration instructions after use. |
| T1070.004 File Deletion |
MalwareS-Type | S-Type has deleted files it has created on a compromised host. |
| T1070.004 File Deletion |
MalwareSeaDuke | SeaDuke can securely delete files, including deleting itself from the victim. |
| T1070.004 File Deletion |
MalwareDustySky | DustySky can delete files it creates from the infected system. |
| T1070.004 File Deletion |
MalwareRemsec | Remsec is capable of deleting files on the victim. It also securely removes itself after collecting and exfiltrating data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.