Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.003 Hidden Window |
MalwareCuba | Cuba has executed hidden PowerShell windows. |
| T1564.003 Hidden Window |
MalwarePureCrypter | PureCrypter can set `ProcessWindowStyle.Hidden` to hide windows on victim machines. |
| T1564.003 Hidden Window |
MalwareGlassWorm | GlassWorm has leveraged Hidden Virtual Network Computing (HVNC) to remain undetected and conduct execution of collection and communication actions. |
| T1564.003 Hidden Window |
MalwareMetamorfo | Metamorfo has hidden its GUI using the ShowWindow() WINAPI call. |
| T1564.003 Hidden Window |
MalwareQUIETCANARY | QUIETCANARY can execute processes in a hidden window. |
| T1564.003 Hidden Window |
MalwareLockBit 2.0 | LockBit 2.0 can execute command line arguments in a hidden window. |
| T1564.003 Hidden Window |
MalwareHotCroissant | HotCroissant has the ability to hide the window for operations performed on a given file. |
| T1564.003 Hidden Window |
MalwareOilBooster | OilBooster can hide its console window upon execution through the `ShowWindow` API. |
| T1564.003 Hidden Window |
MalwareKivars | Kivars has the ability to conceal its activity through hiding active windows. |
| T1564.003 Hidden Window |
MalwareBONDUPDATER | BONDUPDATER uses |
| T1564.003 Hidden Window |
MalwareMeteor | Meteor can hide its console window upon execution to decrease its visibility to a victim. |
| T1564.003 Hidden Window |
MalwareKOCTOPUS | KOCTOPUS has used |
| T1564.003 Hidden Window |
MalwareKevin | Kevin can hide the current window from the targeted user via the `ShowWindow` API function. |
| T1564.003 Hidden Window |
MalwareAgent Tesla | Agent Tesla has used |
| T1564.003 Hidden Window |
MalwareAstaroth | Astaroth loads its module with the XSL script parameter |
| T1564.003 Hidden Window |
MalwareWarzoneRAT | WarzoneRAT has the ability of performing remote desktop access via a hVNC window for decreased visibility. |
| T1564.003 Hidden Window |
ToolSILENTTRINITY | SILENTTRINITY has the ability to set its window state to hidden. |
| T1564.003 Hidden Window |
ToolAsyncRAT | AsyncRAT can hide the execution of scheduled tasks using `ProcessWindowStyle.Hidden`. |
| T1564.003 Hidden Window |
ToolRemcos | Remcos can set `ProcessWindowStyle.Hidden` to hide windows. |
| T1564.003 Hidden Window |
ToolMCMD | MCMD can modify processes to prevent them from being visible on the desktop. |
| T1564.003 Hidden Window |
ToolKoadic | Koadic has used the command |
| T1564.003 Hidden Window |
ToolQuasarRAT | QuasarRAT can hide process windows and make web requests invisible to the compromised user. Requests marked as invisible have been sent with user-agent string `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A` though QuasarRAT can only be run on Windows systems. |
| T1564.004 NTFS File Attributes |
GroupAPT32 | APT32 used NTFS alternate data streams to hide their payloads. |
| T1564.004 NTFS File Attributes |
MalwarePowerDuke | PowerDuke hides many of its backdoor payloads in an alternate data stream (ADS). |
| T1564.004 NTFS File Attributes |
MalwarePOWERSOURCE | If the victim is using PowerShell 3.0 or later, POWERSOURCE writes its decoded payload to an alternate data stream (ADS) named kernel32.dll that is saved in |
| T1564.004 NTFS File Attributes |
MalwareWastedLocker | WastedLocker has the ability to save and execute files as an alternate data stream (ADS). |
| T1564.004 NTFS File Attributes |
MalwareRegin | The Regin malware platform uses Extended Attributes to store encrypted executables. |
| T1564.004 NTFS File Attributes |
MalwareZeroaccess | Some variants of the Zeroaccess Trojan have been known to store data in Extended Attributes. |
| T1564.004 NTFS File Attributes |
MalwareAnchor | Anchor has used NTFS to hide files. |
| T1564.004 NTFS File Attributes |
MalwareGazer | Gazer stores configuration items in alternate data streams (ADSs) if the Registry is not accessible. |
| T1564.004 NTFS File Attributes |
MalwareLatrodectus | Latrodectus can delete itself while its process is still running through the use of an alternate data stream. |
| T1564.004 NTFS File Attributes |
MalwareValak | Valak has the ability save and execute files as alternate data streams (ADS). |
| T1564.004 NTFS File Attributes |
MalwareLoJax | LoJax has loaded an embedded NTFS DXE driver to be able to access and write to NTFS partitions. |
| T1564.004 NTFS File Attributes |
MalwareDEADEYE | The DEADEYE.EMBED variant of DEADEYE can embed its payload in an alternate data stream of a local file. |
| T1564.004 NTFS File Attributes |
MalwareAstaroth | Astaroth can abuse alternate data streams (ADS) to store content for malicious payloads. |
| T1564.004 NTFS File Attributes |
MalwareBitPaymer | BitPaymer has copied itself to the |
| T1564.004 NTFS File Attributes |
Toolesentutl | esentutl can be used to read and write alternate data streams. |
| T1564.004 NTFS File Attributes |
ToolExpand | Expand can be used to download or copy a file into an alternate data stream. |
| T1564.005 Hidden File System |
GroupStrider | Strider has used a hidden file system that is stored as a file on disk. |
| T1564.005 Hidden File System |
GroupEquation | Equation has used an encrypted virtual file system stored in the Windows Registry. |
| T1564.005 Hidden File System |
MalwareRegin | Regin has used a hidden file system to store some of its components. |
| T1564.005 Hidden File System |
MalwareUroburos | Uroburos can use concealed storage mechanisms including an NTFS or FAT-16 filesystem encrypted with CAST-128 in CBC mode. |
| T1564.005 Hidden File System |
MalwareBOOTRASH | BOOTRASH has used unallocated disk space between partitions for a hidden file system that stores components of the Nemesis bootkit. |
| T1564.005 Hidden File System |
MalwareComRAT | ComRAT has used a portable FAT16 partition image placed in %TEMP% as a hidden file system. |
| T1564.006 Run Virtual Instance |
MalwareRagnar Locker | Ragnar Locker has used VirtualBox and a stripped Windows XP virtual machine to run itself. The use of a shared folder specified in the configuration enables Ragnar Locker to encrypt files on the host operating system, including files on any mapped drives. |
| T1564.006 Run Virtual Instance |
MalwareMaze | Maze operators have used VirtualBox and a Windows 7 virtual machine to run the ransomware; the virtual machine's configuration file mapped the shared network drives of the target company, presumably so Maze can encrypt files on the shared drives as well as the local machine. |
| T1564.006 Run Virtual Instance |
MalwareLoudMiner | LoudMiner has used QEMU and VirtualBox to run a Tiny Core Linux virtual machine, which runs XMRig and makes connections to the C2 server for updates. |
| T1564.008 Email Hiding Rules |
GroupScattered Spider | Scattered Spider creates inbound rules on the compromised email accounts of security personnel to automatically delete emails from vendor security products. |
| T1564.008 Email Hiding Rules |
GroupFIN4 | FIN4 has created rules in victims' Microsoft Outlook accounts to automatically delete emails containing words such as “hacked," "phish," and “malware" in a likely attempt to prevent organizations from communicating about their activities. |
| T1564.008 Email Hiding Rules |
MalwareKali365 | Kali365 has the ability to modify email rules to delete email based notifications prior to the victim seeing them. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.