Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.001 Hidden Files and Directories |
MalwareOkrum | Before exfiltration, Okrum's backdoor has used hidden files to store logs and outputs from backdoor commands. |
| T1564.001 Hidden Files and Directories |
MalwareREPTILE | REPTILE has the ability to communicate with the kernel-mode component to hide files. |
| T1564.001 Hidden Files and Directories |
MalwareRising Sun | Rising Sun can modify file attributes to hide files. |
| T1564.001 Hidden Files and Directories |
MalwarePlugX | PlugX can modify the characteristics of folders to hide them from the compromised user. PlugX has also modified file attributes to hidden and system. |
| T1564.001 Hidden Files and Directories |
MalwareExplosive | Explosive has commonly set file and path attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareClambling | Clambling has the ability to set its file attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareDarkGate | DarkGate initial installation involves dropping several files to a hidden directory named after the victim machine name. Additionally, DarkGate uses attrib to hide a directory in the following command: ` C:\Windows\system32\attrib.exe” +h C:/rjtu/`. |
| T1564.001 Hidden Files and Directories |
MalwareThiefQuest | ThiefQuest hides a copy of itself in the user's |
| T1564.001 Hidden Files and Directories |
MalwareWannaCry | |
| T1564.001 Hidden Files and Directories |
MalwareIxeshe | Ixeshe sets its own executable file's attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareMicropsia | Micropsia creates a new hidden directory to store all components' outputs in a dedicated sub-folder for each. |
| T1564.001 Hidden Files and Directories |
MalwareAttor | Attor can set attributes of log files and directories to HIDDEN, SYSTEM, ARCHIVE, or a combination of those. |
| T1564.001 Hidden Files and Directories |
Malwareccf32 | ccf32 has created a hidden directory on targeted systems, naming it after the current local time (year, month, and day). |
| T1564.001 Hidden Files and Directories |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D sets the main loader file’s attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareCalisto | Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
| T1564.001 Hidden Files and Directories |
MalwareCarberp | Carberp has created a hidden file in the Startup folder of the current user. |
| T1564.001 Hidden Files and Directories |
MalwareSysUpdate | SysUpdate has the ability to set file attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareBackConfig | BackConfig has the ability to set folders or files to be hidden from the Windows Explorer default view. |
| T1564.001 Hidden Files and Directories |
MalwareLokibot | Lokibot has the ability to copy itself to a hidden file and directory. |
| T1564.001 Hidden Files and Directories |
MalwarePoetRAT | PoetRAT has the ability to hide and unhide files. |
| T1564.001 Hidden Files and Directories |
MalwareCoinTicker | CoinTicker downloads the following hidden files to evade detection and maintain persistence: /private/tmp/.info.enc, /private/tmp/.info.py, /private/tmp/.server.sh, ~/Library/LaunchAgents/.espl.plist, ~/Library/Containers/.[random string]/[random string]. |
| T1564.001 Hidden Files and Directories |
MalwareHIUPAN | HIUPAN has modified registry keys to ensure hidden files and extensions are not visible through the modification of `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced`. |
| T1564.001 Hidden Files and Directories |
MalwareXCSSET | XCSSET uses a hidden folder named |
| T1564.001 Hidden Files and Directories |
MalwareAppleJeus | AppleJeus has added a leading |
| T1564.001 Hidden Files and Directories |
MalwareAgent Tesla | Agent Tesla has created hidden folders. |
| T1564.001 Hidden Files and Directories |
MalwareQakBot | QakBot has placed its payload in hidden subdirectories. |
| T1564.001 Hidden Files and Directories |
MalwareKomplex | The Komplex payload is stored in a hidden directory at |
| T1564.001 Hidden Files and Directories |
MalwareOSX/Shlayer | OSX/Shlayer has executed a .command script from a hidden directory in a mounted DMG. |
| T1564.001 Hidden Files and Directories |
MalwareMacSpy | MacSpy stores itself in |
| T1564.001 Hidden Files and Directories |
MalwareLoudMiner | LoudMiner has set the attributes of the VirtualBox directory and VBoxVmService parent directory to "hidden". |
| T1564.001 Hidden Files and Directories |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has been created with a hidden attribute to insure it's not visible to the victim. |
| T1564.001 Hidden Files and Directories |
Toolattrib | attrib can be used to make files or directories hidden. |
| T1564.001 Hidden Files and Directories |
ToolImminent Monitor | Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden. |
| T1564.001 Hidden Files and Directories |
ToolQuasarRAT | QuasarRAT has the ability to set file attributes to "hidden" to hide files from the compromised user's view in Windows File Explorer. |
| T1564.001 Hidden Files and Directories |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a hidden directory in the user's home folder on Linux hosts to write a python backdoor. |
| T1564.002 Hidden Users |
MalwareSMOKEDHAM | SMOKEDHAM has modified the Registry to hide created user accounts from the Windows logon screen. |
| T1564.003 Hidden Window |
MalwareTrickBot | TrickBot has used a hidden VNC (hVNC) window to monitor the victim and collect information stealthily. |
| T1564.003 Hidden Window |
MalwareQuietSieve | QuietSieve has the ability to execute payloads in a hidden window. |
| T1564.003 Hidden Window |
MalwareAvosLocker | AvosLocker has hidden its console window by using the `ShowWindow` API function. |
| T1564.003 Hidden Window |
MalwareWindTail | WindTail can instruct the OS to execute an application without a dock icon or menu. |
| T1564.003 Hidden Window |
MalwareUrsnif | Ursnif droppers have used COM properties to execute malware in hidden windows. |
| T1564.003 Hidden Window |
MalwareTsundere Botnet | Tsundere Botnet’s MSI installer has used `-WindowStyle Hidden` to hide Tsundere Botnet’s execution from the user. |
| T1564.003 Hidden Window |
MalwareInvisibleFerret | InvisibleFerret has executed Python instances of the browser module “.n2/bow” utilizing the `CREATE_NO_WINDOW` process creation flag. |
| T1564.003 Hidden Window |
MalwareSharpDisco | SharpDisco can hide windows using `ProcessWindowStyle.Hidden`. |
| T1564.003 Hidden Window |
MalwareStrongPity | StrongPity has the ability to hide the console window for its document search module from the user. |
| T1564.003 Hidden Window |
MalwareMedusa Ransomware | Medusa Ransomware has utilized the `ShowWindow` function to hide current window. |
| T1564.003 Hidden Window |
MalwareBOOKWORM | BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module. |
| T1564.003 Hidden Window |
MalwareHAMMERTOSS | HAMMERTOSS has used |
| T1564.003 Hidden Window |
MalwareIMAPLoader | IMAPLoader hides the Windows Console window created by its execution by directly importing the `kernel32.dll` and `user32.dll` libraries `GetConsoleWindow` and `ShowWindow` APIs. |
| T1564.003 Hidden Window |
MalwareSystemBC | SystemBC has utilized the `-WindowStyle Hidden -ep bypass -file `to conceal PowerShell windows. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.