Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.001 Hidden Files and Directories |
MalwareMacSpy | MacSpy stores itself in |
| T1564.001 Hidden Files and Directories |
MalwareLoudMiner | LoudMiner has set the attributes of the VirtualBox directory and VBoxVmService parent directory to "hidden". |
| T1564.001 Hidden Files and Directories |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has been created with a hidden attribute to insure it's not visible to the victim. |
| T1564.001 Hidden Files and Directories |
Toolattrib | attrib can be used to make files or directories hidden. |
| T1564.001 Hidden Files and Directories |
ToolImminent Monitor | Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden. |
| T1564.001 Hidden Files and Directories |
ToolQuasarRAT | QuasarRAT has the ability to set file attributes to "hidden" to hide files from the compromised user's view in Windows File Explorer. |
| T1564.001 Hidden Files and Directories |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a hidden directory in the user's home folder on Linux hosts to write a python backdoor. |
| T1564.001 Hidden Files and Directories |
GroupTeamPCP | TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware. |
| T1564.002 Hidden Users |
GroupKimsuky | Kimsuky has run |
| T1564.002 Hidden Users |
GroupDragonfly | Dragonfly has modified the Registry to hide created user accounts. |
| T1564.002 Hidden Users |
MalwareSMOKEDHAM | SMOKEDHAM has modified the Registry to hide created user accounts from the Windows logon screen. |
| T1564.003 Hidden Window |
GroupAPT3 | APT3 has been known to use |
| T1564.003 Hidden Window |
GroupKimsuky | Kimsuky has used an information gathering module that will hide an AV software window from the victim. Kimsuky has also been known to use `-WindowStyle Hidden` to conceal PowerShell windows. |
| T1564.003 Hidden Window |
GroupGorgon Group | Gorgon Group has used |
| T1564.003 Hidden Window |
GroupAPT32 | APT32 has used the WindowStyle parameter to conceal PowerShell windows. |
| T1564.003 Hidden Window |
GroupGamaredon Group | Gamaredon Group has used |
| T1564.003 Hidden Window |
GroupFIN7 | FIN7 has used .txt files to conceal PowerShell commands. |
| T1564.003 Hidden Window |
GroupHigaisa | Higaisa used a payload that creates a hidden window. |
| T1564.003 Hidden Window |
GroupDarkHydrus | DarkHydrus has used |
| T1564.003 Hidden Window |
GroupMedusa Group | Medusa Group has utilized the `ShowWindow` API function to hide the current window. |
| T1564.003 Hidden Window |
GroupDeep Panda | Deep Panda has used |
| T1564.003 Hidden Window |
GroupToddyCat | ToddyCat has hidden malicious scripts using `powershell.exe -windowstyle hidden`. |
| T1564.003 Hidden Window |
GroupAPT28 | APT28 has used the WindowStyle parameter to conceal PowerShell windows. |
| T1564.003 Hidden Window |
GroupAPT-C-36 | APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. |
| T1564.003 Hidden Window |
GroupCopyKittens | CopyKittens has used |
| T1564.003 Hidden Window |
GroupVOID MANTICORE | VOID MANTICORE has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`. |
| T1564.003 Hidden Window |
GroupMagic Hound | Magic Hound malware has a function to determine whether the C2 server wishes to execute the newly dropped file in a hidden window. |
| T1564.003 Hidden Window |
GroupAPT19 | APT19 used |
| T1564.003 Hidden Window |
GroupNomadic Octopus | Nomadic Octopus executed PowerShell in a hidden window. |
| T1564.003 Hidden Window |
MalwareTrickBot | TrickBot has used a hidden VNC (hVNC) window to monitor the victim and collect information stealthily. |
| T1564.003 Hidden Window |
MalwareQuietSieve | QuietSieve has the ability to execute payloads in a hidden window. |
| T1564.003 Hidden Window |
MalwareAvosLocker | AvosLocker has hidden its console window by using the `ShowWindow` API function. |
| T1564.003 Hidden Window |
MalwareWindTail | WindTail can instruct the OS to execute an application without a dock icon or menu. |
| T1564.003 Hidden Window |
MalwareUrsnif | Ursnif droppers have used COM properties to execute malware in hidden windows. |
| T1564.003 Hidden Window |
MalwareTsundere Botnet | Tsundere Botnet’s MSI installer has used `-WindowStyle Hidden` to hide Tsundere Botnet’s execution from the user. |
| T1564.003 Hidden Window |
MalwareInvisibleFerret | InvisibleFerret has executed Python instances of the browser module “.n2/bow” utilizing the `CREATE_NO_WINDOW` process creation flag. |
| T1564.003 Hidden Window |
MalwareSharpDisco | SharpDisco can hide windows using `ProcessWindowStyle.Hidden`. |
| T1564.003 Hidden Window |
MalwareStrongPity | StrongPity has the ability to hide the console window for its document search module from the user. |
| T1564.003 Hidden Window |
MalwareMedusa Ransomware | Medusa Ransomware has utilized the `ShowWindow` function to hide current window. |
| T1564.003 Hidden Window |
MalwareBOOKWORM | BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module. |
| T1564.003 Hidden Window |
MalwareHAMMERTOSS | HAMMERTOSS has used |
| T1564.003 Hidden Window |
MalwareIMAPLoader | IMAPLoader hides the Windows Console window created by its execution by directly importing the `kernel32.dll` and `user32.dll` libraries `GetConsoleWindow` and `ShowWindow` APIs. |
| T1564.003 Hidden Window |
MalwareSystemBC | SystemBC has utilized the `-WindowStyle Hidden -ep bypass -file `to conceal PowerShell windows. |
| T1564.003 Hidden Window |
MalwareCANONSTAGER | CANONSTAGER has created a new window with a height and width of zero to remain hidden on the screen. |
| T1564.003 Hidden Window |
MalwareSnip3 | Snip3 can execute PowerShell scripts in a hidden window. |
| T1564.003 Hidden Window |
MalwareInvisiMole | InvisiMole has executed legitimate tools in hidden windows. |
| T1564.003 Hidden Window |
MalwarePowerShower | PowerShower has added a registry key so future powershell.exe instances are spawned with coordinates for a window position off-screen by default. |
| T1564.003 Hidden Window |
MalwareKeyBoy | KeyBoy uses |
| T1564.003 Hidden Window |
MalwarePlugX | PlugX has the ability to execute a command on a hidden desktop. |
| T1564.003 Hidden Window |
MalwareLumma Stealer | Lumma Stealer has utilized the .NET `ProcessStartInfo` class features to prevent the process from creating a visible window through setting the `CreateNoWindow` setting to “True,” which allows the executed command or script to run without displaying a command prompt window. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.