Real-world descriptions of how a group, tool or campaign used a technique.
251 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
MalwareEpic | Epic has a command to delete a file from the machine. |
| T1070.004 File Deletion |
MalwareLightNeuron | LightNeuron has a function to delete files. |
| T1070.004 File Deletion |
MalwareCuba | Cuba can use the command |
| T1070.004 File Deletion |
MalwarePureCrypter | PureCrypter can execute a PowerShell command to self-delete. |
| T1070.004 File Deletion |
MalwareDarkGate | DarkGate has deleted its staging directories. |
| T1070.004 File Deletion |
MalwareNanHaiShu | NanHaiShu launches a script to delete their original decoy file to cover tracks. |
| T1070.004 File Deletion |
MalwareLockBit 3.0 | LockBit 3.0 can delete itself from disk. |
| T1070.004 File Deletion |
MalwareCarbanak | Carbanak has a command to delete files. |
| T1070.004 File Deletion |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can delete files. |
| T1070.004 File Deletion |
MalwareFerocious | Ferocious can delete files from a compromised host. |
| T1070.004 File Deletion |
MalwareElise | Elise is capable of launching a remote shell on the host to delete itself. |
| T1070.004 File Deletion |
MalwareGazer | Gazer has commands to delete files and persistence mechanisms from the victim. |
| T1070.004 File Deletion |
MalwareLatrodectus | Latrodectus has the ability to delete itself. |
| T1070.004 File Deletion |
MalwareSaint Bot | Saint Bot can run a batch script named `del.bat` to remove any Saint Bot payload-linked files from a compromise system if anti-analysis or locale checks fail. |
| T1070.004 File Deletion |
MalwarePay2Key | Pay2Key can remove its log file from disk. |
| T1070.004 File Deletion |
MalwareLODEINFO | LODEINFO can delete files to remove traces of activity from victim systems. |
| T1070.004 File Deletion |
MalwareCharmPower | CharmPower can delete created files from a compromised system. |
| T1070.004 File Deletion |
MalwareTYPEFRAME | TYPEFRAME can delete files off the system. |
| T1070.004 File Deletion |
MalwareMori | Mori can delete its DLL file and related files by Registry value. |
| T1070.004 File Deletion |
MalwareQUADAGENT | QUADAGENT has a command to delete its Registry key and scheduled task. |
| T1070.004 File Deletion |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can delete files from a compromised host. |
| T1070.004 File Deletion |
Malwarepngdowner | pngdowner deletes content from C2 communications that was saved to the user's temporary directory. |
| T1070.004 File Deletion |
MalwareUroburos | Uroburos can run a `Clear Agents Track` command on an infected machine to delete Uroburos-related logs. |
| T1070.004 File Deletion |
MalwareMetamorfo | Metamorfo has deleted itself from the system after execution. |
| T1070.004 File Deletion |
MalwareEmbargo | Embargo has leveraged MDeployer to terminate the MS4Killer process, delete the decrypted payload files and a driver file dropped by MS4killer, and reboot the system. |
| T1070.004 File Deletion |
MalwareTrojan.Karagany | Trojan.Karagany has used plugins with a self-delete capability. |
| T1070.004 File Deletion |
MalwareBandook | Bandook has a command to delete a file. |
| T1070.004 File Deletion |
MalwareMagicRAT | MagicRAT can delete files on victim systems, including itself. |
| T1070.004 File Deletion |
MalwareKONNI | KONNI can delete files. |
| T1070.004 File Deletion |
Malwaregh0st RAT | gh0st RAT has the capability to to delete files. |
| T1070.004 File Deletion |
MalwareJHUHUGIT | The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files. |
| T1070.004 File Deletion |
MalwareBLUELIGHT | BLUELIGHT can uninstall itself. |
| T1070.004 File Deletion |
MalwareIxeshe | Ixeshe has a command to delete a file from the machine. |
| T1070.004 File Deletion |
MalwareVBShower | VBShower has attempted to complicate forensic analysis by deleting all the files contained in |
| T1070.004 File Deletion |
MalwareBPFDoor | After initial setup, BPFDoor's original execution process deletes the dropped binary and exits. |
| T1070.004 File Deletion |
MalwareStoneDrill | StoneDrill has been observed deleting the temporary files once they fulfill their task. |
| T1070.004 File Deletion |
MalwareOopsIE | OopsIE has the capability to delete files and scripts from the victim's machine. |
| T1070.004 File Deletion |
MalwareAttor | Attor’s plugin deletes the collected files and log files after exfiltration. |
| T1070.004 File Deletion |
MalwareSQLRat | SQLRat has used been observed deleting scripts once used. |
| T1070.004 File Deletion |
MalwareSDBbot | SDBbot has the ability to delete files from a compromised host. |
| T1070.004 File Deletion |
MalwareMosquito | Mosquito deletes files using DeleteFileW API call. |
| T1070.004 File Deletion |
MalwareRTM | RTM can delete all files created during its execution. |
| T1070.004 File Deletion |
MalwareDerusbi | Derusbi is capable of deleting files. It has been observed loading a Linux Kernel Module (LKM) and then deleting it from the hard disk as well as overwriting the data with null bytes. |
| T1070.004 File Deletion |
MalwareGrandoreiro | Grandoreiro can delete .LNK files created in the Startup folder. |
| T1070.004 File Deletion |
MalwareLiteDuke | LiteDuke can securely delete files by first writing random data to the file. |
| T1070.004 File Deletion |
MalwareSakula | Some Sakula samples use cmd.exe to delete temporary files. |
| T1070.004 File Deletion |
MalwareSibot | Sibot will delete itself if a certain server response is received. |
| T1070.004 File Deletion |
MalwareWINDSHIELD | WINDSHIELD is capable of file deletion along with other file system interaction. |
| T1070.004 File Deletion |
MalwareDrovorub | Drovorub can delete specific files from a compromised host. |
| T1070.004 File Deletion |
MalwareShark | Shark can delete files downloaded to the compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.