Real-world descriptions of how a group, tool or campaign used a technique.
251 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
MalwareStealBit | StealBit can self-delete its executable file from the compromised system. |
| T1070.004 File Deletion |
MalwareFELIXROOT | FELIXROOT deletes the .LNK file from the startup directory as well as the dropper components. |
| T1070.004 File Deletion |
MalwareZxShell | ZxShell can delete files from the system. |
| T1070.004 File Deletion |
MalwarePenquin | Penquin can delete downloaded executables after running them. |
| T1070.004 File Deletion |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has deleted generated files and folders from victim devices. |
| T1070.004 File Deletion |
MalwareBabyShark | BabyShark has cleaned up all files associated with the secondary payload execution. |
| T1070.004 File Deletion |
MalwareWinnti for Windows | Winnti for Windows can delete the DLLs for its various components from a compromised host. |
| T1070.004 File Deletion |
MalwareTroll Stealer | Troll Stealer creates and can execute a BAT script that will delete the malware. |
| T1070.004 File Deletion |
MalwareBLACKCOFFEE | BLACKCOFFEE has the capability to delete files. |
| T1070.004 File Deletion |
MalwareMeteor | Meteor will delete the folder containing malicious scripts if it detects the hostname as `PIS-APP`, `PIS-MOB`, `WSUSPROXY`, or `PIS-DB`. |
| T1070.004 File Deletion |
MalwarenjRAT | njRAT is capable of deleting files. |
| T1070.004 File Deletion |
MalwareIceApple | IceApple can delete files and directories from targeted systems. |
| T1070.004 File Deletion |
MalwareJPIN | JPIN's installer/uninstaller component deletes itself if it encounters a version of Windows earlier than Windows XP or identifies security-related processes running. |
| T1070.004 File Deletion |
MalwaremetaMain | metaMain has deleted collected items after uploading the content to its C2 server. |
| T1070.004 File Deletion |
MalwareHeyoka Backdoor | Heyoka Backdoor has the ability to delete folders and files from a targeted system. |
| T1070.004 File Deletion |
MalwareHTTPBrowser | HTTPBrowser deletes its original installer file once installation is complete. |
| T1070.004 File Deletion |
MalwareLunarWeb | LunarWeb can self-delete from a compromised host if safety checks of C2 connectivity fail. |
| T1070.004 File Deletion |
MalwareKillDisk | KillDisk has the ability to quit and delete itself. |
| T1070.004 File Deletion |
MalwareQilin | Qilin can delete itself from infected hosts after execution. |
| T1070.004 File Deletion |
MalwareAppleJeus | AppleJeus has deleted the MSI file after installation. |
| T1070.004 File Deletion |
MalwareKevin | Kevin can delete files created on the victim's machine. |
| T1070.004 File Deletion |
MalwarePasam | Pasam creates a backdoor through which remote attackers can delete files. |
| T1070.004 File Deletion |
MalwarePOWERSTATS | POWERSTATS can delete all files on the C:\, D:\, E:\ and, F:\ drives using PowerShell Remove-Item commands. |
| T1070.004 File Deletion |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON can delete log files generated from the malware stored at |
| T1070.004 File Deletion |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can delete files. |
| T1070.004 File Deletion |
MalwareQakBot | QakBot can delete folders and files including overwriting its executable with legitimate programs. |
| T1070.004 File Deletion |
MalwareDOWNIISSA | DOWNIISSA can delete files after download. |
| T1070.004 File Deletion |
MalwareHancitor | Hancitor has deleted files using the VBA |
| T1070.004 File Deletion |
MalwareGelsemium | Gelsemium can delete its dropper component from the targeted system. |
| T1070.004 File Deletion |
MalwarejRAT | jRAT has a function to delete files from the victim’s machine. |
| T1070.004 File Deletion |
MalwareKomplex | The Komplex trojan supports file deletion. |
| T1070.004 File Deletion |
MalwareDenis | Denis has a command to delete files from the victim’s machine. |
| T1070.004 File Deletion |
MalwareMacSpy | MacSpy deletes any temporary files it creates |
| T1070.004 File Deletion |
MalwareDtrack | Dtrack can remove its persistence and delete itself. |
| T1070.004 File Deletion |
MalwareLoudMiner | LoudMiner deleted installation files after completion. |
| T1070.004 File Deletion |
MalwareAzorult | Azorult can delete files from victim machines. |
| T1070.004 File Deletion |
MalwareADVSTORESHELL | ADVSTORESHELL can delete files and directories. |
| T1070.004 File Deletion |
MalwareStrifeWater | StrifeWater can self delete to cover its tracks. |
| T1070.004 File Deletion |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has deleted itself and the 'index.dat' file on a compromised machine to remove recent Internet history from the system. |
| T1070.004 File Deletion |
MalwareFALLCHILL | FALLCHILL can delete malware and associated artifacts from the victim. |
| T1070.004 File Deletion |
ToolSILENTTRINITY | SILENTTRINITY can remove files from the compromised host. |
| T1070.004 File Deletion |
ToolPcShare | PcShare has deleted its files and components from a compromised host. |
| T1070.004 File Deletion |
ToolCSPY Downloader | CSPY Downloader has the ability to self delete. |
| T1070.004 File Deletion |
ToolRemcos | Remcos can delete files and folders from victim machines. |
| T1070.004 File Deletion |
ToolImminent Monitor | Imminent Monitor has deleted files related to its dynamic debugger feature. |
| T1070.004 File Deletion |
Toolcmd | cmd can be used to delete files from the file system. |
| T1070.004 File Deletion |
ToolSDelete | SDelete deletes data in a way that makes it unrecoverable. |
| T1070.004 File Deletion |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to remove all staged files after exfiltration. |
| T1070.004 File Deletion |
MalwareMini Shai-Hulud | Mini Shai-Hulud has deleted all artifacts to include gathered credential archives to reduce disk persistence and detection. |
| T1070.004 File Deletion |
MalwareCanisterWorm | CanisterWorm has deleted itself after execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.