ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1070.004×

13 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group removed all previously delivered files from a compromised computer.

T1070.004
File Deletion
CampaignKV Botnet Activity

KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device.

T1070.004
File Deletion
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capaple of removing scripts after execution.

T1070.004
File Deletion
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used batch files that reduced their fingerprint on a compromised system by deleting malware-related files.

T1070.004
File Deletion
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, vba_macro.exe deletes itself after `FONTCACHE.DAT`, `rundll32.exe`, and the associated .lnk file is delivered.

T1070.004
File Deletion
CampaignCutting Edge

During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files.

T1070.004
File Deletion
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe.

T1070.004
File Deletion
CampaignC0032

During the C0032 campaign, TEMP.Veles routinely deleted tools, logs, and other files after they were finished with them.

T1070.004
File Deletion
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 routinely removed their tools, including custom backdoors, once remote access was achieved.

T1070.004
File Deletion
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace deleted delivered tools and files from compromised hosts.

T1070.004
File Deletion
CampaignArcaneDoor

ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions.

T1070.004
File Deletion
CampaignAPT41 DUST

APT41 DUST deleted various artifacts from victim systems following use.

T1070.004
File Deletion
CampaignOperation Wocao

During Operation Wocao, the threat actors consistently removed traces of their activity by first overwriting a file using `/c cd /d c:\windows\temp\ & copy \\<IP ADDRESS>\c$\windows\system32\devmgr.dll \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1 /y` and then deleting the overwritten file using `/c cd /d c:\windows\temp\ & del \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.