ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1564.003×

18 examples

TechniqueUsed byProcedure example
T1564.003
Hidden Window
GroupAPT3

APT3 has been known to use -WindowStyle Hidden to conceal PowerShell windows.

T1564.003
Hidden Window
GroupKimsuky

Kimsuky has used an information gathering module that will hide an AV software window from the victim. Kimsuky has also been known to use `-WindowStyle Hidden` to conceal PowerShell windows.

T1564.003
Hidden Window
GroupGorgon Group

Gorgon Group has used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1564.003
Hidden Window
GroupAPT32

APT32 has used the WindowStyle parameter to conceal PowerShell windows.

T1564.003
Hidden Window
GroupGamaredon Group

Gamaredon Group has used hidcon to run batch files in a hidden console window. Gamaredon Group has also executed PowerShell in a hidden window.

T1564.003
Hidden Window
GroupFIN7

FIN7 has used .txt files to conceal PowerShell commands.

T1564.003
Hidden Window
GroupHigaisa

Higaisa used a payload that creates a hidden window.

T1564.003
Hidden Window
GroupDarkHydrus

DarkHydrus has used -WindowStyle Hidden to conceal PowerShell windows.

T1564.003
Hidden Window
GroupMedusa Group

Medusa Group has utilized the `ShowWindow` API function to hide the current window.

T1564.003
Hidden Window
GroupDeep Panda

Deep Panda has used -w hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1564.003
Hidden Window
GroupToddyCat

ToddyCat has hidden malicious scripts using `powershell.exe -windowstyle hidden`.

T1564.003
Hidden Window
GroupAPT28

APT28 has used the WindowStyle parameter to conceal PowerShell windows.

T1564.003
Hidden Window
GroupAPT-C-36

APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution.

T1564.003
Hidden Window
GroupCopyKittens

CopyKittens has used -w hidden and -windowstyle hidden to conceal PowerShell windows.

T1564.003
Hidden Window
GroupVOID MANTICORE

VOID MANTICORE has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`.

T1564.003
Hidden Window
GroupMagic Hound

Magic Hound malware has a function to determine whether the C2 server wishes to execute the newly dropped file in a hidden window.

T1564.003
Hidden Window
GroupAPT19

APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1564.003
Hidden Window
GroupNomadic Octopus

Nomadic Octopus executed PowerShell in a hidden window.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.