Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.003 Hidden Window |
GroupAPT3 | APT3 has been known to use |
| T1564.003 Hidden Window |
GroupKimsuky | Kimsuky has used an information gathering module that will hide an AV software window from the victim. Kimsuky has also been known to use `-WindowStyle Hidden` to conceal PowerShell windows. |
| T1564.003 Hidden Window |
GroupGorgon Group | Gorgon Group has used |
| T1564.003 Hidden Window |
GroupAPT32 | APT32 has used the WindowStyle parameter to conceal PowerShell windows. |
| T1564.003 Hidden Window |
GroupGamaredon Group | Gamaredon Group has used |
| T1564.003 Hidden Window |
GroupFIN7 | FIN7 has used .txt files to conceal PowerShell commands. |
| T1564.003 Hidden Window |
GroupHigaisa | Higaisa used a payload that creates a hidden window. |
| T1564.003 Hidden Window |
GroupDarkHydrus | DarkHydrus has used |
| T1564.003 Hidden Window |
GroupMedusa Group | Medusa Group has utilized the `ShowWindow` API function to hide the current window. |
| T1564.003 Hidden Window |
GroupDeep Panda | Deep Panda has used |
| T1564.003 Hidden Window |
GroupToddyCat | ToddyCat has hidden malicious scripts using `powershell.exe -windowstyle hidden`. |
| T1564.003 Hidden Window |
GroupAPT28 | APT28 has used the WindowStyle parameter to conceal PowerShell windows. |
| T1564.003 Hidden Window |
GroupAPT-C-36 | APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. |
| T1564.003 Hidden Window |
GroupCopyKittens | CopyKittens has used |
| T1564.003 Hidden Window |
GroupVOID MANTICORE | VOID MANTICORE has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`. |
| T1564.003 Hidden Window |
GroupMagic Hound | Magic Hound malware has a function to determine whether the C2 server wishes to execute the newly dropped file in a hidden window. |
| T1564.003 Hidden Window |
GroupAPT19 | APT19 used |
| T1564.003 Hidden Window |
GroupNomadic Octopus | Nomadic Octopus executed PowerShell in a hidden window. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.