Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group removed all previously delivered files from a compromised computer. |
| T1070.004 File Deletion |
CampaignKV Botnet Activity | KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device. |
| T1070.004 File Deletion |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capaple of removing scripts after execution. |
| T1070.004 File Deletion |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used batch files that reduced their fingerprint on a compromised system by deleting malware-related files. |
| T1070.004 File Deletion |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, vba_macro.exe deletes itself after `FONTCACHE.DAT`, `rundll32.exe`, and the associated .lnk file is delivered. |
| T1070.004 File Deletion |
CampaignCutting Edge | During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files. |
| T1070.004 File Deletion |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe. |
| T1070.004 File Deletion |
CampaignC0032 | During the C0032 campaign, TEMP.Veles routinely deleted tools, logs, and other files after they were finished with them. |
| T1070.004 File Deletion |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 routinely removed their tools, including custom backdoors, once remote access was achieved. |
| T1070.004 File Deletion |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace deleted delivered tools and files from compromised hosts. |
| T1070.004 File Deletion |
CampaignArcaneDoor | ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions. |
| T1070.004 File Deletion |
CampaignAPT41 DUST | APT41 DUST deleted various artifacts from victim systems following use. |
| T1070.004 File Deletion |
CampaignOperation Wocao | During Operation Wocao, the threat actors consistently removed traces of their activity by first overwriting a file using `/c cd /d c:\windows\temp\ & copy \\<IP ADDRESS>\c$\windows\system32\devmgr.dll \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1 /y` and then deleting the overwritten file using `/c cd /d c:\windows\temp\ & del \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.