ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1070.004×

47 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
GroupAPT38

APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process.

T1070.004
File Deletion
GroupBlackByte

BlackByte deleted ransomware executables post-encryption.

T1070.004
File Deletion
GroupAPT3

APT3 has a tool that can delete files.

T1070.004
File Deletion
GroupKimsuky

Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk. Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads. Kimsuky has also removed remnants of files used for delivery to include .log and .zip files.

T1070.004
File Deletion
GroupVolt Typhoon

Volt Typhoon has run `rd /S` to delete their working directories and deleted systeminfo.dat from `C:\Users\Public\Documentsfiles`.

T1070.004
File Deletion
GroupPatchwork

Patchwork removed certain files and replaced them so they could not be retrieved.

T1070.004
File Deletion
GroupAPT41

APT41 deleted files from the system.

T1070.004
File Deletion
GroupDragonfly

Dragonfly has deleted many of its files used during operations as part of cleanup, including removing applications and deleting screenshots.

T1070.004
File Deletion
GroupEvilnum

Evilnum has deleted files used during infection.

T1070.004
File Deletion
GroupmenuPass

A menuPass macro deletes files after it has decoded and decompressed them.

T1070.004
File Deletion
GroupAPT32

APT32's macOS backdoor can receive a “delete” command.

T1070.004
File Deletion
GroupFIN6

FIN6 has removed files from victim machines.

T1070.004
File Deletion
GroupGamaredon Group

Gamaredon Group tools can delete files used during an operation.

T1070.004
File Deletion
GroupTeamTNT

TeamTNT has used a payload that removes itself after running. TeamTNT also has deleted locally staged files for collecting credentials or scan results for local IP addresses after exfiltrating them.

T1070.004
File Deletion
GroupSandworm Team

Sandworm Team has used backdoors that can delete files used in an attack from an infected system.

T1070.004
File Deletion
GroupAPT18

APT18 actors deleted tools and batch files from victim systems.

T1070.004
File Deletion
GroupMustang Panda

Mustang Panda will delete their tools and files, and kill processes after their objectives are reached.

T1070.004
File Deletion
GroupRocke

Rocke has deleted files on infected machines.

T1070.004
File Deletion
GroupAPT39

APT39 has used malware to delete files after they are deployed on a compromised host.

T1070.004
File Deletion
GroupUNC3886

UNC3886 has used the the esxcli command line to remove files created by malicious vSphere Installation Bundles from disk.

T1070.004
File Deletion
GroupContagious Interview

Contagious Interview has configured malware to remove archives used in collection activities following successful exfiltration.

T1070.004
File Deletion
GroupOilRig

OilRig has deleted files associated with their payload after execution.

T1070.004
File Deletion
GroupTropic Trooper

Tropic Trooper has deleted dropper files on an infected system using command scripts.

T1070.004
File Deletion
GroupAquatic Panda

Aquatic Panda has deleted malicious executables from compromised machines.

T1070.004
File Deletion
GroupThe White Company

The White Company has the ability to delete its malware entirely from the target system.

T1070.004
File Deletion
GroupGroup5

Malware used by Group5 is capable of remotely deleting files from victims.

T1070.004
File Deletion
GroupRedCurl

RedCurl has deleted files after execution.

T1070.004
File Deletion
GroupFIN5

FIN5 uses SDelete to clean up the environment and attempt to prevent detection.

T1070.004
File Deletion
GroupAPT29

APT29 has used SDelete to remove artifacts from victim networks.

T1070.004
File Deletion
GroupChimera

Chimera has performed file deletion to evade detection.

T1070.004
File Deletion
GroupMirrorFace

MirrorFace has deleted directories containing malware and archives with files collected from the victim environment.

T1070.004
File Deletion
GroupMedusa Group

Medusa Group has deleted previously installed tools.

T1070.004
File Deletion
GroupBRONZE BUTLER

The BRONZE BUTLER uploader or malware the uploader uses command to delete the RAR archives after they have been exfiltrated.

T1070.004
File Deletion
GroupEmber Bear

Ember Bear deletes files related to lateral movement to avoid detection.

T1070.004
File Deletion
GroupAPT28

APT28 has intentionally deleted computer files to cover their tracks, including with use of the program CCleaner.

T1070.004
File Deletion
GroupMetador

Metador has quickly deleted `cbd.exe` from a compromised host following the successful deployment of their malware.

T1070.004
File Deletion
GroupAPT5

APT5 has deleted scripts and web shells to evade detection.

T1070.004
File Deletion
GroupLazarus Group

Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim. Lazarus Group also uses secure file deletion to delete files from the victim.

T1070.004
File Deletion
GroupINC Ransom

INC Ransom has uninstalled tools from compromised endpoints after use.

T1070.004
File Deletion
GroupSilence

Silence has deleted artifacts, including scheduled tasks, communicates files from the C2 and other logs.

T1070.004
File Deletion
GroupCobalt Group

Cobalt Group deleted the DLL dropper from the victim’s machine to cover their tracks.

T1070.004
File Deletion
GroupWizard Spider

Wizard Spider has used file deletion to remove some modules and configurations from an infected host after use.

T1070.004
File Deletion
GroupPlay

Play has used tools including Wevtutil to remove malicious files from compromised hosts.

T1070.004
File Deletion
GroupMagic Hound

Magic Hound has deleted and overwrote files to cover tracks.

T1070.004
File Deletion
GroupThreat Group-3390

Threat Group-3390 has deleted existing logs and exfiltrated file archives from a victim.

T1070.004
File Deletion
GroupFIN10

FIN10 has used batch scripts and scheduled tasks to delete critical system files.

T1070.004
File Deletion
GroupFIN8

FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.