ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1564.003
Hidden Window
MalwareCANONSTAGER

CANONSTAGER has created a new window with a height and width of zero to remain hidden on the screen.

T1564.003
Hidden Window
MalwareSnip3

Snip3 can execute PowerShell scripts in a hidden window.

T1564.003
Hidden Window
MalwareInvisiMole

InvisiMole has executed legitimate tools in hidden windows.

T1564.003
Hidden Window
MalwarePowerShower

PowerShower has added a registry key so future powershell.exe instances are spawned with coordinates for a window position off-screen by default.

T1564.003
Hidden Window
MalwareKeyBoy

KeyBoy uses -w Hidden to conceal a PowerShell window that downloads a payload.

T1564.003
Hidden Window
MalwarePlugX

PlugX has the ability to execute a command on a hidden desktop.

T1564.003
Hidden Window
MalwareLumma Stealer

Lumma Stealer has utilized the .NET `ProcessStartInfo` class features to prevent the process from creating a visible window through setting the `CreateNoWindow` setting to “True,” which allows the executed command or script to run without displaying a command prompt window.

T1564.003
Hidden Window
MalwareCuba

Cuba has executed hidden PowerShell windows.

T1564.003
Hidden Window
MalwarePureCrypter

PureCrypter can set `ProcessWindowStyle.Hidden` to hide windows on victim machines.

T1564.003
Hidden Window
MalwareGlassWorm

GlassWorm has leveraged Hidden Virtual Network Computing (HVNC) to remain undetected and conduct execution of collection and communication actions.

T1564.003
Hidden Window
MalwareMetamorfo

Metamorfo has hidden its GUI using the ShowWindow() WINAPI call.

T1564.003
Hidden Window
MalwareQUIETCANARY

QUIETCANARY can execute processes in a hidden window.

T1564.003
Hidden Window
MalwareLockBit 2.0

LockBit 2.0 can execute command line arguments in a hidden window.

T1564.003
Hidden Window
MalwareHotCroissant

HotCroissant has the ability to hide the window for operations performed on a given file.

T1564.003
Hidden Window
MalwareOilBooster

OilBooster can hide its console window upon execution through the `ShowWindow` API.

T1564.003
Hidden Window
MalwareKivars

Kivars has the ability to conceal its activity through hiding active windows.

T1564.003
Hidden Window
MalwareBONDUPDATER

BONDUPDATER uses -windowstyle hidden to conceal a PowerShell window that downloads a payload.

T1564.003
Hidden Window
MalwareMeteor

Meteor can hide its console window upon execution to decrease its visibility to a victim.

T1564.003
Hidden Window
MalwareKOCTOPUS

KOCTOPUS has used -WindowsStyle Hidden to hide the command window.

T1564.003
Hidden Window
MalwareKevin

Kevin can hide the current window from the targeted user via the `ShowWindow` API function.

T1564.003
Hidden Window
MalwareAgent Tesla

Agent Tesla has used ProcessWindowStyle.Hidden to hide windows.

T1564.003
Hidden Window
MalwareAstaroth

Astaroth loads its module with the XSL script parameter vShow set to zero, which opens the application with a hidden window.

T1564.003
Hidden Window
MalwareWarzoneRAT

WarzoneRAT has the ability of performing remote desktop access via a hVNC window for decreased visibility.

T1564.003
Hidden Window
ToolSILENTTRINITY

SILENTTRINITY has the ability to set its window state to hidden.

T1564.003
Hidden Window
ToolAsyncRAT

AsyncRAT can hide the execution of scheduled tasks using `ProcessWindowStyle.Hidden`.

T1564.003
Hidden Window
ToolRemcos

Remcos can set `ProcessWindowStyle.Hidden` to hide windows.

T1564.003
Hidden Window
ToolMCMD

MCMD can modify processes to prevent them from being visible on the desktop.

T1564.003
Hidden Window
ToolKoadic

Koadic has used the command Powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden to hide its window.

T1564.003
Hidden Window
ToolQuasarRAT

QuasarRAT can hide process windows and make web requests invisible to the compromised user. Requests marked as invisible have been sent with user-agent string `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A` though QuasarRAT can only be run on Windows systems.

T1564.004
NTFS File Attributes
MalwarePowerDuke

PowerDuke hides many of its backdoor payloads in an alternate data stream (ADS).

T1564.004
NTFS File Attributes
MalwarePOWERSOURCE

If the victim is using PowerShell 3.0 or later, POWERSOURCE writes its decoded payload to an alternate data stream (ADS) named kernel32.dll that is saved in %PROGRAMDATA%\Windows\.

T1564.004
NTFS File Attributes
MalwareWastedLocker

WastedLocker has the ability to save and execute files as an alternate data stream (ADS).

T1564.004
NTFS File Attributes
MalwareRegin

The Regin malware platform uses Extended Attributes to store encrypted executables.

T1564.004
NTFS File Attributes
MalwareZeroaccess

Some variants of the Zeroaccess Trojan have been known to store data in Extended Attributes.

T1564.004
NTFS File Attributes
MalwareAnchor

Anchor has used NTFS to hide files.

T1564.004
NTFS File Attributes
MalwareGazer

Gazer stores configuration items in alternate data streams (ADSs) if the Registry is not accessible.

T1564.004
NTFS File Attributes
MalwareLatrodectus

Latrodectus can delete itself while its process is still running through the use of an alternate data stream.

T1564.004
NTFS File Attributes
MalwareValak

Valak has the ability save and execute files as alternate data streams (ADS).

T1564.004
NTFS File Attributes
MalwareLoJax

LoJax has loaded an embedded NTFS DXE driver to be able to access and write to NTFS partitions.

T1564.004
NTFS File Attributes
MalwareDEADEYE

The DEADEYE.EMBED variant of DEADEYE can embed its payload in an alternate data stream of a local file.

T1564.004
NTFS File Attributes
MalwareAstaroth

Astaroth can abuse alternate data streams (ADS) to store content for malicious payloads.

T1564.004
NTFS File Attributes
MalwareBitPaymer

BitPaymer has copied itself to the :bin alternate data stream of a newly created file.

T1564.004
NTFS File Attributes
Toolesentutl

esentutl can be used to read and write alternate data streams.

T1564.004
NTFS File Attributes
ToolExpand

Expand can be used to download or copy a file into an alternate data stream.

T1564.005
Hidden File System
MalwareRegin

Regin has used a hidden file system to store some of its components.

T1564.005
Hidden File System
MalwareUroburos

Uroburos can use concealed storage mechanisms including an NTFS or FAT-16 filesystem encrypted with CAST-128 in CBC mode.

T1564.005
Hidden File System
MalwareBOOTRASH

BOOTRASH has used unallocated disk space between partitions for a hidden file system that stores components of the Nemesis bootkit.

T1564.005
Hidden File System
MalwareComRAT

ComRAT has used a portable FAT16 partition image placed in %TEMP% as a hidden file system.

T1564.006
Run Virtual Instance
MalwareRagnar Locker

Ragnar Locker has used VirtualBox and a stripped Windows XP virtual machine to run itself. The use of a shared folder specified in the configuration enables Ragnar Locker to encrypt files on the host operating system, including files on any mapped drives.

T1564.006
Run Virtual Instance
MalwareMaze

Maze operators have used VirtualBox and a Windows 7 virtual machine to run the ransomware; the virtual machine's configuration file mapped the shared network drives of the target company, presumably so Maze can encrypt files on the shared drives as well as the local machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.