ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1564.001
Hidden Files and Directories
MalwareMacSpy

MacSpy stores itself in ~/Library/.DS_Stores/

T1564.001
Hidden Files and Directories
MalwareLoudMiner

LoudMiner has set the attributes of the VirtualBox directory and VBoxVmService parent directory to "hidden".

T1564.001
Hidden Files and Directories
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has been created with a hidden attribute to insure it's not visible to the victim.

T1564.001
Hidden Files and Directories
Toolattrib

attrib can be used to make files or directories hidden.

T1564.001
Hidden Files and Directories
ToolImminent Monitor

Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden.

T1564.001
Hidden Files and Directories
ToolQuasarRAT

QuasarRAT has the ability to set file attributes to "hidden" to hide files from the compromised user's view in Windows File Explorer.

T1564.001
Hidden Files and Directories
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a hidden directory in the user's home folder on Linux hosts to write a python backdoor.

T1564.001
Hidden Files and Directories
GroupTeamPCP

TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware.

T1564.002
Hidden Users
GroupKimsuky

Kimsuky has run reg add ‘HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList’ /v to hide a newly created user.

T1564.002
Hidden Users
GroupDragonfly

Dragonfly has modified the Registry to hide created user accounts.

T1564.002
Hidden Users
MalwareSMOKEDHAM

SMOKEDHAM has modified the Registry to hide created user accounts from the Windows logon screen.

T1564.003
Hidden Window
GroupAPT3

APT3 has been known to use -WindowStyle Hidden to conceal PowerShell windows.

T1564.003
Hidden Window
GroupKimsuky

Kimsuky has used an information gathering module that will hide an AV software window from the victim. Kimsuky has also been known to use `-WindowStyle Hidden` to conceal PowerShell windows.

T1564.003
Hidden Window
GroupGorgon Group

Gorgon Group has used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1564.003
Hidden Window
GroupAPT32

APT32 has used the WindowStyle parameter to conceal PowerShell windows.

T1564.003
Hidden Window
GroupGamaredon Group

Gamaredon Group has used hidcon to run batch files in a hidden console window. Gamaredon Group has also executed PowerShell in a hidden window.

T1564.003
Hidden Window
GroupFIN7

FIN7 has used .txt files to conceal PowerShell commands.

T1564.003
Hidden Window
GroupHigaisa

Higaisa used a payload that creates a hidden window.

T1564.003
Hidden Window
GroupDarkHydrus

DarkHydrus has used -WindowStyle Hidden to conceal PowerShell windows.

T1564.003
Hidden Window
GroupMedusa Group

Medusa Group has utilized the `ShowWindow` API function to hide the current window.

T1564.003
Hidden Window
GroupDeep Panda

Deep Panda has used -w hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1564.003
Hidden Window
GroupToddyCat

ToddyCat has hidden malicious scripts using `powershell.exe -windowstyle hidden`.

T1564.003
Hidden Window
GroupAPT28

APT28 has used the WindowStyle parameter to conceal PowerShell windows.

T1564.003
Hidden Window
GroupAPT-C-36

APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution.

T1564.003
Hidden Window
GroupCopyKittens

CopyKittens has used -w hidden and -windowstyle hidden to conceal PowerShell windows.

T1564.003
Hidden Window
GroupVOID MANTICORE

VOID MANTICORE has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`.

T1564.003
Hidden Window
GroupMagic Hound

Magic Hound malware has a function to determine whether the C2 server wishes to execute the newly dropped file in a hidden window.

T1564.003
Hidden Window
GroupAPT19

APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1564.003
Hidden Window
GroupNomadic Octopus

Nomadic Octopus executed PowerShell in a hidden window.

T1564.003
Hidden Window
MalwareTrickBot

TrickBot has used a hidden VNC (hVNC) window to monitor the victim and collect information stealthily.

T1564.003
Hidden Window
MalwareQuietSieve

QuietSieve has the ability to execute payloads in a hidden window.

T1564.003
Hidden Window
MalwareAvosLocker

AvosLocker has hidden its console window by using the `ShowWindow` API function.

T1564.003
Hidden Window
MalwareWindTail

WindTail can instruct the OS to execute an application without a dock icon or menu.

T1564.003
Hidden Window
MalwareUrsnif

Ursnif droppers have used COM properties to execute malware in hidden windows.

T1564.003
Hidden Window
MalwareTsundere Botnet

Tsundere Botnet’s MSI installer has used `-WindowStyle Hidden` to hide Tsundere Botnet’s execution from the user.

T1564.003
Hidden Window
MalwareInvisibleFerret

InvisibleFerret has executed Python instances of the browser module “.n2/bow” utilizing the `CREATE_NO_WINDOW` process creation flag.

T1564.003
Hidden Window
MalwareSharpDisco

SharpDisco can hide windows using `ProcessWindowStyle.Hidden`.

T1564.003
Hidden Window
MalwareStrongPity

StrongPity has the ability to hide the console window for its document search module from the user.

T1564.003
Hidden Window
MalwareMedusa Ransomware

Medusa Ransomware has utilized the `ShowWindow` function to hide current window.

T1564.003
Hidden Window
MalwareBOOKWORM

BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module.

T1564.003
Hidden Window
MalwareHAMMERTOSS

HAMMERTOSS has used -WindowStyle hidden to conceal PowerShell windows.

T1564.003
Hidden Window
MalwareIMAPLoader

IMAPLoader hides the Windows Console window created by its execution by directly importing the `kernel32.dll` and `user32.dll` libraries `GetConsoleWindow` and `ShowWindow` APIs.

T1564.003
Hidden Window
MalwareSystemBC

SystemBC has utilized the `-WindowStyle Hidden -ep bypass -file `to conceal PowerShell windows.

T1564.003
Hidden Window
MalwareCANONSTAGER

CANONSTAGER has created a new window with a height and width of zero to remain hidden on the screen.

T1564.003
Hidden Window
MalwareSnip3

Snip3 can execute PowerShell scripts in a hidden window.

T1564.003
Hidden Window
MalwareInvisiMole

InvisiMole has executed legitimate tools in hidden windows.

T1564.003
Hidden Window
MalwarePowerShower

PowerShower has added a registry key so future powershell.exe instances are spawned with coordinates for a window position off-screen by default.

T1564.003
Hidden Window
MalwareKeyBoy

KeyBoy uses -w Hidden to conceal a PowerShell window that downloads a payload.

T1564.003
Hidden Window
MalwarePlugX

PlugX has the ability to execute a command on a hidden desktop.

T1564.003
Hidden Window
MalwareLumma Stealer

Lumma Stealer has utilized the .NET `ProcessStartInfo` class features to prevent the process from creating a visible window through setting the `CreateNoWindow` setting to “True,” which allows the executed command or script to run without displaying a command prompt window.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.