ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1564.001
Hidden Files and Directories
GroupHAFNIUM

HAFNIUM has hidden files on a compromised host.

T1564.001
Hidden Files and Directories
GroupFIN7

FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden.

T1564.001
Hidden Files and Directories
GroupMustang Panda

Mustang Panda's PlugX variant has created a hidden folder on USB drives named RECYCLE.BIN to store malicious executables and collected data. Mustang Panda has also modified file attributes to `hidden` and `system`.

T1564.001
Hidden Files and Directories
GroupRocke

Rocke downloaded a file "libprocesshider", which could hide files on the target system.

T1564.001
Hidden Files and Directories
GroupTropic Trooper

Tropic Trooper has created a hidden directory under C:\ProgramData\Apple\Updates\ and C:\Users\Public\Documents\Flash\.

T1564.001
Hidden Files and Directories
GroupRedCurl

RedCurl added the “hidden” file attribute to original files, manipulating victims to click on malicious LNK files.

T1564.001
Hidden Files and Directories
GroupLuminousMoth

LuminousMoth has used malware to store malicious binaries in hidden directories on victim's USB drives.

T1564.001
Hidden Files and Directories
GroupAPT28

APT28 has saved files with hidden file attributes.

T1564.001
Hidden Files and Directories
GroupLazarus Group

Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application.

T1564.001
Hidden Files and Directories
GroupTransparent Tribe

Transparent Tribe can hide legitimate directories and replace them with malicious copies of the same name.

T1564.001
Hidden Files and Directories
GroupFIN13

FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information.

T1564.001
Hidden Files and Directories
MalwareCOATHANGER

COATHANGER creates and installs itself to a hidden installation directory.

T1564.001
Hidden Files and Directories
MalwareNETWIRE

NETWIRE can copy itself to and launch itself from hidden folders.

T1564.001
Hidden Files and Directories
MalwareiKitten

iKitten saves itself with a leading "." so that it's hidden from users by default.

T1564.001
Hidden Files and Directories
MalwareEnvyScout

EnvyScout can use hidden directories and files to hide malicious executables.

T1564.001
Hidden Files and Directories
MalwareMachete

Machete has the capability to exfiltrate stolen data to a hidden folder on a removable drive.

T1564.001
Hidden Files and Directories
MalwareDacls

Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application.

T1564.001
Hidden Files and Directories
MalwareCuckoo Stealer

Cuckoo Stealer has copied its binary and the victim's scraped password into a hidden folder in the `/Users` directory.

T1564.001
Hidden Files and Directories
MalwareWastedLocker

WastedLocker has copied a random file from the Windows System32 folder to the %APPDATA% location under a different hidden filename.

T1564.001
Hidden Files and Directories
MalwareInvisiMole

InvisiMole can create hidden system directories.

T1564.001
Hidden Files and Directories
MalwareCLAIMLOADER

CLAIMLOADER has modified file attributes to remain hidden to a standard user.

T1564.001
Hidden Files and Directories
MalwareFruitFly

FruitFly saves itself with a leading "." to make it a hidden file.

T1564.001
Hidden Files and Directories
MalwareOkrum

Before exfiltration, Okrum's backdoor has used hidden files to store logs and outputs from backdoor commands.

T1564.001
Hidden Files and Directories
MalwareREPTILE

REPTILE has the ability to communicate with the kernel-mode component to hide files.

T1564.001
Hidden Files and Directories
MalwareRising Sun

Rising Sun can modify file attributes to hide files.

T1564.001
Hidden Files and Directories
MalwarePlugX

PlugX can modify the characteristics of folders to hide them from the compromised user. PlugX has also modified file attributes to hidden and system.

T1564.001
Hidden Files and Directories
MalwareExplosive

Explosive has commonly set file and path attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareClambling

Clambling has the ability to set its file attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareDarkGate

DarkGate initial installation involves dropping several files to a hidden directory named after the victim machine name. Additionally, DarkGate uses attrib to hide a directory in the following command: ` C:\Windows\system32\attrib.exe” +h C:/rjtu/`.

T1564.001
Hidden Files and Directories
MalwareThiefQuest

ThiefQuest hides a copy of itself in the user's ~/Library directory by using a . at the beginning of the file name followed by 9 random characters.

T1564.001
Hidden Files and Directories
MalwareWannaCry

WannaCry uses attrib +h to make some of its files hidden.

T1564.001
Hidden Files and Directories
MalwareIxeshe

Ixeshe sets its own executable file's attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareMicropsia

Micropsia creates a new hidden directory to store all components' outputs in a dedicated sub-folder for each.

T1564.001
Hidden Files and Directories
MalwareAttor

Attor can set attributes of log files and directories to HIDDEN, SYSTEM, ARCHIVE, or a combination of those.

T1564.001
Hidden Files and Directories
Malwareccf32

ccf32 has created a hidden directory on targeted systems, naming it after the current local time (year, month, and day).

T1564.001
Hidden Files and Directories
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D sets the main loader file’s attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareCalisto

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

T1564.001
Hidden Files and Directories
MalwareCarberp

Carberp has created a hidden file in the Startup folder of the current user.

T1564.001
Hidden Files and Directories
MalwareSysUpdate

SysUpdate has the ability to set file attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareBackConfig

BackConfig has the ability to set folders or files to be hidden from the Windows Explorer default view.

T1564.001
Hidden Files and Directories
MalwareLokibot

Lokibot has the ability to copy itself to a hidden file and directory.

T1564.001
Hidden Files and Directories
MalwarePoetRAT

PoetRAT has the ability to hide and unhide files.

T1564.001
Hidden Files and Directories
MalwareCoinTicker

CoinTicker downloads the following hidden files to evade detection and maintain persistence: /private/tmp/.info.enc, /private/tmp/.info.py, /private/tmp/.server.sh, ~/Library/LaunchAgents/.espl.plist, ~/Library/Containers/.[random string]/[random string].

T1564.001
Hidden Files and Directories
MalwareHIUPAN

HIUPAN has modified registry keys to ensure hidden files and extensions are not visible through the modification of `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced`.

T1564.001
Hidden Files and Directories
MalwareXCSSET

XCSSET uses a hidden folder named .xcassets and .git to embed itself in Xcode.

T1564.001
Hidden Files and Directories
MalwareAppleJeus

AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings.

T1564.001
Hidden Files and Directories
MalwareAgent Tesla

Agent Tesla has created hidden folders.

T1564.001
Hidden Files and Directories
MalwareQakBot

QakBot has placed its payload in hidden subdirectories.

T1564.001
Hidden Files and Directories
MalwareKomplex

The Komplex payload is stored in a hidden directory at /Users/Shared/.local/kextd.

T1564.001
Hidden Files and Directories
MalwareOSX/Shlayer

OSX/Shlayer has executed a .command script from a hidden directory in a mounted DMG.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.