Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560.003 Archive via Custom Method |
GroupFIN6 | FIN6 has encoded data gathered from the victim with a simple substitution cipher and single-byte XOR using the 0xAA key, and Base64 with character permutation. |
| T1560.003 Archive via Custom Method |
GroupMustang Panda | Mustang Panda has encrypted documents with RC4 prior to exfiltration. |
| T1560.003 Archive via Custom Method |
GroupUNC3886 | UNC3886 has XOR encrypted and Gzip compressed captured credentials. |
| T1560.003 Archive via Custom Method |
GroupLotus Blossom | Lotus Blossom has used custom tools to compress and archive data on victim systems. |
| T1560.003 Archive via Custom Method |
GroupLazarus Group | A Lazarus Group malware sample encrypts data using a simple byte based XOR operation prior to exfiltration. |
| T1560.003 Archive via Custom Method |
GroupCopyKittens | CopyKittens encrypts data with a substitute cipher prior to exfiltration. |
| T1561.001 Disk Content Wipe |
GroupGamaredon Group | Gamaredon Group has used tools to delete files and folders from victims' desktops and profiles. |
| T1561.001 Disk Content Wipe |
GroupLazarus Group | Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive with a mix of static and random buffers. A similar process is then used to wipe content in logical drives and, finally, attempt to wipe every byte of every sector on every drive. WhiskeyBravo can be used to overwrite the first 4.9MB of physical drives. WhiskeyDelta can overwrite the first 132MB or 1.5MB of each drive with random data from heap memory. |
| T1561.001 Disk Content Wipe |
GroupVOID MANTICORE | VOID MANTICORE has utilized a disk wiping utility to facilitate destructive actions on victim servers. VOID MANTICORE has also utilized legitimate remote disk wiping commands. |
| T1561.002 Disk Structure Wipe |
GroupAPT38 | APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. |
| T1561.002 Disk Structure Wipe |
GroupSandworm Team | Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record. |
| T1561.002 Disk Structure Wipe |
GroupAPT37 | APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). |
| T1561.002 Disk Structure Wipe |
GroupEmber Bear | Ember Bear conducted destructive operations against victims, including disk structure wiping, via the WhisperGate malware in Ukraine. |
| T1561.002 Disk Structure Wipe |
GroupLazarus Group | Lazarus Group malware SHARPKNOT overwrites and deletes the Master Boot Record (MBR) on the victim's machine and has possessed MBR wiper malware since at least 2009. |
| T1561.002 Disk Structure Wipe |
GroupVOID MANTICORE | VOID MANTICORE has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files. |
| T1563.002 RDP Hijacking |
GroupAxiom | Axiom has targeted victims with remote administration tools including RDP. |
| T1564.001 Hidden Files and Directories |
GroupAPT32 | APT32's macOS backdoor hides the clientID file via a chflags function. |
| T1564.001 Hidden Files and Directories |
GroupHAFNIUM | HAFNIUM has hidden files on a compromised host. |
| T1564.001 Hidden Files and Directories |
GroupFIN7 | FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden. |
| T1564.001 Hidden Files and Directories |
GroupMustang Panda | Mustang Panda's PlugX variant has created a hidden folder on USB drives named |
| T1564.001 Hidden Files and Directories |
GroupRocke | Rocke downloaded a file "libprocesshider", which could hide files on the target system. |
| T1564.001 Hidden Files and Directories |
GroupTropic Trooper | Tropic Trooper has created a hidden directory under |
| T1564.001 Hidden Files and Directories |
GroupRedCurl | RedCurl added the “hidden” file attribute to original files, manipulating victims to click on malicious LNK files. |
| T1564.001 Hidden Files and Directories |
GroupLuminousMoth | LuminousMoth has used malware to store malicious binaries in hidden directories on victim's USB drives. |
| T1564.001 Hidden Files and Directories |
GroupAPT28 | APT28 has saved files with hidden file attributes. |
| T1564.001 Hidden Files and Directories |
GroupLazarus Group | Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application. |
| T1564.001 Hidden Files and Directories |
GroupTransparent Tribe | Transparent Tribe can hide legitimate directories and replace them with malicious copies of the same name. |
| T1564.001 Hidden Files and Directories |
GroupFIN13 | FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information. |
| T1564.001 Hidden Files and Directories |
GroupTeamPCP | TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware. |
| T1564.002 Hidden Users |
GroupKimsuky | Kimsuky has run |
| T1564.002 Hidden Users |
GroupDragonfly | Dragonfly has modified the Registry to hide created user accounts. |
| T1564.003 Hidden Window |
GroupAPT3 | APT3 has been known to use |
| T1564.003 Hidden Window |
GroupKimsuky | Kimsuky has used an information gathering module that will hide an AV software window from the victim. Kimsuky has also been known to use `-WindowStyle Hidden` to conceal PowerShell windows. |
| T1564.003 Hidden Window |
GroupGorgon Group | Gorgon Group has used |
| T1564.003 Hidden Window |
GroupAPT32 | APT32 has used the WindowStyle parameter to conceal PowerShell windows. |
| T1564.003 Hidden Window |
GroupGamaredon Group | Gamaredon Group has used |
| T1564.003 Hidden Window |
GroupFIN7 | FIN7 has used .txt files to conceal PowerShell commands. |
| T1564.003 Hidden Window |
GroupHigaisa | Higaisa used a payload that creates a hidden window. |
| T1564.003 Hidden Window |
GroupDarkHydrus | DarkHydrus has used |
| T1564.003 Hidden Window |
GroupMedusa Group | Medusa Group has utilized the `ShowWindow` API function to hide the current window. |
| T1564.003 Hidden Window |
GroupDeep Panda | Deep Panda has used |
| T1564.003 Hidden Window |
GroupToddyCat | ToddyCat has hidden malicious scripts using `powershell.exe -windowstyle hidden`. |
| T1564.003 Hidden Window |
GroupAPT28 | APT28 has used the WindowStyle parameter to conceal PowerShell windows. |
| T1564.003 Hidden Window |
GroupAPT-C-36 | APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. |
| T1564.003 Hidden Window |
GroupCopyKittens | CopyKittens has used |
| T1564.003 Hidden Window |
GroupVOID MANTICORE | VOID MANTICORE has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`. |
| T1564.003 Hidden Window |
GroupMagic Hound | Magic Hound malware has a function to determine whether the C2 server wishes to execute the newly dropped file in a hidden window. |
| T1564.003 Hidden Window |
GroupAPT19 | APT19 used |
| T1564.003 Hidden Window |
GroupNomadic Octopus | Nomadic Octopus executed PowerShell in a hidden window. |
| T1564.004 NTFS File Attributes |
GroupAPT32 | APT32 used NTFS alternate data streams to hide their payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.