ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1564.001×

13 examples

TechniqueUsed byProcedure example
T1564.001
Hidden Files and Directories
GroupAPT32

APT32's macOS backdoor hides the clientID file via a chflags function.

T1564.001
Hidden Files and Directories
GroupHAFNIUM

HAFNIUM has hidden files on a compromised host.

T1564.001
Hidden Files and Directories
GroupFIN7

FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden.

T1564.001
Hidden Files and Directories
GroupMustang Panda

Mustang Panda's PlugX variant has created a hidden folder on USB drives named RECYCLE.BIN to store malicious executables and collected data. Mustang Panda has also modified file attributes to `hidden` and `system`.

T1564.001
Hidden Files and Directories
GroupRocke

Rocke downloaded a file "libprocesshider", which could hide files on the target system.

T1564.001
Hidden Files and Directories
GroupTropic Trooper

Tropic Trooper has created a hidden directory under C:\ProgramData\Apple\Updates\ and C:\Users\Public\Documents\Flash\.

T1564.001
Hidden Files and Directories
GroupRedCurl

RedCurl added the “hidden” file attribute to original files, manipulating victims to click on malicious LNK files.

T1564.001
Hidden Files and Directories
GroupLuminousMoth

LuminousMoth has used malware to store malicious binaries in hidden directories on victim's USB drives.

T1564.001
Hidden Files and Directories
GroupAPT28

APT28 has saved files with hidden file attributes.

T1564.001
Hidden Files and Directories
GroupLazarus Group

Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application.

T1564.001
Hidden Files and Directories
GroupTransparent Tribe

Transparent Tribe can hide legitimate directories and replace them with malicious copies of the same name.

T1564.001
Hidden Files and Directories
GroupFIN13

FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information.

T1564.001
Hidden Files and Directories
GroupTeamPCP

TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.