ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1564.001
Hidden Files and Directories
MalwareOkrum

Before exfiltration, Okrum's backdoor has used hidden files to store logs and outputs from backdoor commands.

T1564.001
Hidden Files and Directories
MalwareREPTILE

REPTILE has the ability to communicate with the kernel-mode component to hide files.

T1564.001
Hidden Files and Directories
MalwareRising Sun

Rising Sun can modify file attributes to hide files.

T1564.001
Hidden Files and Directories
MalwarePlugX

PlugX can modify the characteristics of folders to hide them from the compromised user. PlugX has also modified file attributes to hidden and system.

T1564.001
Hidden Files and Directories
MalwareExplosive

Explosive has commonly set file and path attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareClambling

Clambling has the ability to set its file attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareDarkGate

DarkGate initial installation involves dropping several files to a hidden directory named after the victim machine name. Additionally, DarkGate uses attrib to hide a directory in the following command: ` C:\Windows\system32\attrib.exe” +h C:/rjtu/`.

T1564.001
Hidden Files and Directories
MalwareThiefQuest

ThiefQuest hides a copy of itself in the user's ~/Library directory by using a . at the beginning of the file name followed by 9 random characters.

T1564.001
Hidden Files and Directories
MalwareWannaCry

WannaCry uses attrib +h to make some of its files hidden.

T1564.001
Hidden Files and Directories
MalwareIxeshe

Ixeshe sets its own executable file's attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareMicropsia

Micropsia creates a new hidden directory to store all components' outputs in a dedicated sub-folder for each.

T1564.001
Hidden Files and Directories
MalwareAttor

Attor can set attributes of log files and directories to HIDDEN, SYSTEM, ARCHIVE, or a combination of those.

T1564.001
Hidden Files and Directories
Malwareccf32

ccf32 has created a hidden directory on targeted systems, naming it after the current local time (year, month, and day).

T1564.001
Hidden Files and Directories
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D sets the main loader file’s attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareCalisto

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

T1564.001
Hidden Files and Directories
MalwareCarberp

Carberp has created a hidden file in the Startup folder of the current user.

T1564.001
Hidden Files and Directories
MalwareSysUpdate

SysUpdate has the ability to set file attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareBackConfig

BackConfig has the ability to set folders or files to be hidden from the Windows Explorer default view.

T1564.001
Hidden Files and Directories
MalwareLokibot

Lokibot has the ability to copy itself to a hidden file and directory.

T1564.001
Hidden Files and Directories
MalwarePoetRAT

PoetRAT has the ability to hide and unhide files.

T1564.001
Hidden Files and Directories
MalwareCoinTicker

CoinTicker downloads the following hidden files to evade detection and maintain persistence: /private/tmp/.info.enc, /private/tmp/.info.py, /private/tmp/.server.sh, ~/Library/LaunchAgents/.espl.plist, ~/Library/Containers/.[random string]/[random string].

T1564.001
Hidden Files and Directories
MalwareHIUPAN

HIUPAN has modified registry keys to ensure hidden files and extensions are not visible through the modification of `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced`.

T1564.001
Hidden Files and Directories
MalwareXCSSET

XCSSET uses a hidden folder named .xcassets and .git to embed itself in Xcode.

T1564.001
Hidden Files and Directories
MalwareAppleJeus

AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings.

T1564.001
Hidden Files and Directories
MalwareAgent Tesla

Agent Tesla has created hidden folders.

T1564.001
Hidden Files and Directories
MalwareQakBot

QakBot has placed its payload in hidden subdirectories.

T1564.001
Hidden Files and Directories
MalwareKomplex

The Komplex payload is stored in a hidden directory at /Users/Shared/.local/kextd.

T1564.001
Hidden Files and Directories
MalwareOSX/Shlayer

OSX/Shlayer has executed a .command script from a hidden directory in a mounted DMG.

T1564.001
Hidden Files and Directories
MalwareMacSpy

MacSpy stores itself in ~/Library/.DS_Stores/

T1564.001
Hidden Files and Directories
MalwareLoudMiner

LoudMiner has set the attributes of the VirtualBox directory and VBoxVmService parent directory to "hidden".

T1564.001
Hidden Files and Directories
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has been created with a hidden attribute to insure it's not visible to the victim.

T1564.001
Hidden Files and Directories
Toolattrib

attrib can be used to make files or directories hidden.

T1564.001
Hidden Files and Directories
ToolImminent Monitor

Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden.

T1564.001
Hidden Files and Directories
ToolQuasarRAT

QuasarRAT has the ability to set file attributes to "hidden" to hide files from the compromised user's view in Windows File Explorer.

T1564.001
Hidden Files and Directories
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a hidden directory in the user's home folder on Linux hosts to write a python backdoor.

T1564.002
Hidden Users
MalwareSMOKEDHAM

SMOKEDHAM has modified the Registry to hide created user accounts from the Windows logon screen.

T1564.003
Hidden Window
MalwareTrickBot

TrickBot has used a hidden VNC (hVNC) window to monitor the victim and collect information stealthily.

T1564.003
Hidden Window
MalwareQuietSieve

QuietSieve has the ability to execute payloads in a hidden window.

T1564.003
Hidden Window
MalwareAvosLocker

AvosLocker has hidden its console window by using the `ShowWindow` API function.

T1564.003
Hidden Window
MalwareWindTail

WindTail can instruct the OS to execute an application without a dock icon or menu.

T1564.003
Hidden Window
MalwareUrsnif

Ursnif droppers have used COM properties to execute malware in hidden windows.

T1564.003
Hidden Window
MalwareTsundere Botnet

Tsundere Botnet’s MSI installer has used `-WindowStyle Hidden` to hide Tsundere Botnet’s execution from the user.

T1564.003
Hidden Window
MalwareInvisibleFerret

InvisibleFerret has executed Python instances of the browser module “.n2/bow” utilizing the `CREATE_NO_WINDOW` process creation flag.

T1564.003
Hidden Window
MalwareSharpDisco

SharpDisco can hide windows using `ProcessWindowStyle.Hidden`.

T1564.003
Hidden Window
MalwareStrongPity

StrongPity has the ability to hide the console window for its document search module from the user.

T1564.003
Hidden Window
MalwareMedusa Ransomware

Medusa Ransomware has utilized the `ShowWindow` function to hide current window.

T1564.003
Hidden Window
MalwareBOOKWORM

BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module.

T1564.003
Hidden Window
MalwareHAMMERTOSS

HAMMERTOSS has used -WindowStyle hidden to conceal PowerShell windows.

T1564.003
Hidden Window
MalwareIMAPLoader

IMAPLoader hides the Windows Console window created by its execution by directly importing the `kernel32.dll` and `user32.dll` libraries `GetConsoleWindow` and `ShowWindow` APIs.

T1564.003
Hidden Window
MalwareSystemBC

SystemBC has utilized the `-WindowStyle Hidden -ep bypass -file `to conceal PowerShell windows.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.