Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.001 Hidden Files and Directories |
GroupAPT32 | APT32's macOS backdoor hides the clientID file via a chflags function. |
| T1564.001 Hidden Files and Directories |
GroupHAFNIUM | HAFNIUM has hidden files on a compromised host. |
| T1564.001 Hidden Files and Directories |
GroupFIN7 | FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden. |
| T1564.001 Hidden Files and Directories |
GroupMustang Panda | Mustang Panda's PlugX variant has created a hidden folder on USB drives named |
| T1564.001 Hidden Files and Directories |
GroupRocke | Rocke downloaded a file "libprocesshider", which could hide files on the target system. |
| T1564.001 Hidden Files and Directories |
GroupTropic Trooper | Tropic Trooper has created a hidden directory under |
| T1564.001 Hidden Files and Directories |
GroupRedCurl | RedCurl added the “hidden” file attribute to original files, manipulating victims to click on malicious LNK files. |
| T1564.001 Hidden Files and Directories |
GroupLuminousMoth | LuminousMoth has used malware to store malicious binaries in hidden directories on victim's USB drives. |
| T1564.001 Hidden Files and Directories |
GroupAPT28 | APT28 has saved files with hidden file attributes. |
| T1564.001 Hidden Files and Directories |
GroupLazarus Group | Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application. |
| T1564.001 Hidden Files and Directories |
GroupTransparent Tribe | Transparent Tribe can hide legitimate directories and replace them with malicious copies of the same name. |
| T1564.001 Hidden Files and Directories |
GroupFIN13 | FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information. |
| T1564.001 Hidden Files and Directories |
GroupTeamPCP | TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.