Real-world descriptions of how a group, tool or campaign used a technique.
47 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
GroupAPT38 | APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process. |
| T1070.004 File Deletion |
GroupBlackByte | BlackByte deleted ransomware executables post-encryption. |
| T1070.004 File Deletion |
GroupAPT3 | APT3 has a tool that can delete files. |
| T1070.004 File Deletion |
GroupKimsuky | Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk. Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads. Kimsuky has also removed remnants of files used for delivery to include .log and .zip files. |
| T1070.004 File Deletion |
GroupVolt Typhoon | Volt Typhoon has run `rd /S` to delete their working directories and deleted systeminfo.dat from `C:\Users\Public\Documentsfiles`. |
| T1070.004 File Deletion |
GroupPatchwork | Patchwork removed certain files and replaced them so they could not be retrieved. |
| T1070.004 File Deletion |
GroupAPT41 | APT41 deleted files from the system. |
| T1070.004 File Deletion |
GroupDragonfly | Dragonfly has deleted many of its files used during operations as part of cleanup, including removing applications and deleting screenshots. |
| T1070.004 File Deletion |
GroupEvilnum | Evilnum has deleted files used during infection. |
| T1070.004 File Deletion |
GroupmenuPass | A menuPass macro deletes files after it has decoded and decompressed them. |
| T1070.004 File Deletion |
GroupAPT32 | APT32's macOS backdoor can receive a “delete” command. |
| T1070.004 File Deletion |
GroupFIN6 | FIN6 has removed files from victim machines. |
| T1070.004 File Deletion |
GroupGamaredon Group | Gamaredon Group tools can delete files used during an operation. |
| T1070.004 File Deletion |
GroupTeamTNT | TeamTNT has used a payload that removes itself after running. TeamTNT also has deleted locally staged files for collecting credentials or scan results for local IP addresses after exfiltrating them. |
| T1070.004 File Deletion |
GroupSandworm Team | Sandworm Team has used backdoors that can delete files used in an attack from an infected system. |
| T1070.004 File Deletion |
GroupAPT18 | APT18 actors deleted tools and batch files from victim systems. |
| T1070.004 File Deletion |
GroupMustang Panda | Mustang Panda will delete their tools and files, and kill processes after their objectives are reached. |
| T1070.004 File Deletion |
GroupRocke | Rocke has deleted files on infected machines. |
| T1070.004 File Deletion |
GroupAPT39 | APT39 has used malware to delete files after they are deployed on a compromised host. |
| T1070.004 File Deletion |
GroupUNC3886 | UNC3886 has used the the esxcli command line to remove files created by malicious vSphere Installation Bundles from disk. |
| T1070.004 File Deletion |
GroupContagious Interview | Contagious Interview has configured malware to remove archives used in collection activities following successful exfiltration. |
| T1070.004 File Deletion |
GroupOilRig | OilRig has deleted files associated with their payload after execution. |
| T1070.004 File Deletion |
GroupTropic Trooper | Tropic Trooper has deleted dropper files on an infected system using command scripts. |
| T1070.004 File Deletion |
GroupAquatic Panda | Aquatic Panda has deleted malicious executables from compromised machines. |
| T1070.004 File Deletion |
GroupThe White Company | The White Company has the ability to delete its malware entirely from the target system. |
| T1070.004 File Deletion |
GroupGroup5 | Malware used by Group5 is capable of remotely deleting files from victims. |
| T1070.004 File Deletion |
GroupRedCurl | RedCurl has deleted files after execution. |
| T1070.004 File Deletion |
GroupFIN5 | FIN5 uses SDelete to clean up the environment and attempt to prevent detection. |
| T1070.004 File Deletion |
GroupAPT29 | APT29 has used SDelete to remove artifacts from victim networks. |
| T1070.004 File Deletion |
GroupChimera | Chimera has performed file deletion to evade detection. |
| T1070.004 File Deletion |
GroupMirrorFace | MirrorFace has deleted directories containing malware and archives with files collected from the victim environment. |
| T1070.004 File Deletion |
GroupMedusa Group | Medusa Group has deleted previously installed tools. |
| T1070.004 File Deletion |
GroupBRONZE BUTLER | The BRONZE BUTLER uploader or malware the uploader uses |
| T1070.004 File Deletion |
GroupEmber Bear | Ember Bear deletes files related to lateral movement to avoid detection. |
| T1070.004 File Deletion |
GroupAPT28 | APT28 has intentionally deleted computer files to cover their tracks, including with use of the program CCleaner. |
| T1070.004 File Deletion |
GroupMetador | Metador has quickly deleted `cbd.exe` from a compromised host following the successful deployment of their malware. |
| T1070.004 File Deletion |
GroupAPT5 | APT5 has deleted scripts and web shells to evade detection. |
| T1070.004 File Deletion |
GroupLazarus Group | Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim. Lazarus Group also uses secure file deletion to delete files from the victim. |
| T1070.004 File Deletion |
GroupINC Ransom | INC Ransom has uninstalled tools from compromised endpoints after use. |
| T1070.004 File Deletion |
GroupSilence | Silence has deleted artifacts, including scheduled tasks, communicates files from the C2 and other logs. |
| T1070.004 File Deletion |
GroupCobalt Group | Cobalt Group deleted the DLL dropper from the victim’s machine to cover their tracks. |
| T1070.004 File Deletion |
GroupWizard Spider | Wizard Spider has used file deletion to remove some modules and configurations from an infected host after use. |
| T1070.004 File Deletion |
GroupPlay | Play has used tools including Wevtutil to remove malicious files from compromised hosts. |
| T1070.004 File Deletion |
GroupMagic Hound | Magic Hound has deleted and overwrote files to cover tracks. |
| T1070.004 File Deletion |
GroupThreat Group-3390 | Threat Group-3390 has deleted existing logs and exfiltrated file archives from a victim. |
| T1070.004 File Deletion |
GroupFIN10 | FIN10 has used batch scripts and scheduled tasks to delete critical system files. |
| T1070.004 File Deletion |
GroupFIN8 | FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.