ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1564.001×

46 examples

TechniqueUsed byProcedure example
T1564.001
Hidden Files and Directories
MalwareCOATHANGER

COATHANGER creates and installs itself to a hidden installation directory.

T1564.001
Hidden Files and Directories
MalwareNETWIRE

NETWIRE can copy itself to and launch itself from hidden folders.

T1564.001
Hidden Files and Directories
MalwareiKitten

iKitten saves itself with a leading "." so that it's hidden from users by default.

T1564.001
Hidden Files and Directories
MalwareEnvyScout

EnvyScout can use hidden directories and files to hide malicious executables.

T1564.001
Hidden Files and Directories
MalwareMachete

Machete has the capability to exfiltrate stolen data to a hidden folder on a removable drive.

T1564.001
Hidden Files and Directories
MalwareDacls

Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application.

T1564.001
Hidden Files and Directories
MalwareCuckoo Stealer

Cuckoo Stealer has copied its binary and the victim's scraped password into a hidden folder in the `/Users` directory.

T1564.001
Hidden Files and Directories
MalwareWastedLocker

WastedLocker has copied a random file from the Windows System32 folder to the %APPDATA% location under a different hidden filename.

T1564.001
Hidden Files and Directories
MalwareInvisiMole

InvisiMole can create hidden system directories.

T1564.001
Hidden Files and Directories
MalwareCLAIMLOADER

CLAIMLOADER has modified file attributes to remain hidden to a standard user.

T1564.001
Hidden Files and Directories
MalwareFruitFly

FruitFly saves itself with a leading "." to make it a hidden file.

T1564.001
Hidden Files and Directories
MalwareOkrum

Before exfiltration, Okrum's backdoor has used hidden files to store logs and outputs from backdoor commands.

T1564.001
Hidden Files and Directories
MalwareREPTILE

REPTILE has the ability to communicate with the kernel-mode component to hide files.

T1564.001
Hidden Files and Directories
MalwareRising Sun

Rising Sun can modify file attributes to hide files.

T1564.001
Hidden Files and Directories
MalwarePlugX

PlugX can modify the characteristics of folders to hide them from the compromised user. PlugX has also modified file attributes to hidden and system.

T1564.001
Hidden Files and Directories
MalwareExplosive

Explosive has commonly set file and path attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareClambling

Clambling has the ability to set its file attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareDarkGate

DarkGate initial installation involves dropping several files to a hidden directory named after the victim machine name. Additionally, DarkGate uses attrib to hide a directory in the following command: ` C:\Windows\system32\attrib.exe” +h C:/rjtu/`.

T1564.001
Hidden Files and Directories
MalwareThiefQuest

ThiefQuest hides a copy of itself in the user's ~/Library directory by using a . at the beginning of the file name followed by 9 random characters.

T1564.001
Hidden Files and Directories
MalwareWannaCry

WannaCry uses attrib +h to make some of its files hidden.

T1564.001
Hidden Files and Directories
MalwareIxeshe

Ixeshe sets its own executable file's attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareMicropsia

Micropsia creates a new hidden directory to store all components' outputs in a dedicated sub-folder for each.

T1564.001
Hidden Files and Directories
MalwareAttor

Attor can set attributes of log files and directories to HIDDEN, SYSTEM, ARCHIVE, or a combination of those.

T1564.001
Hidden Files and Directories
Malwareccf32

ccf32 has created a hidden directory on targeted systems, naming it after the current local time (year, month, and day).

T1564.001
Hidden Files and Directories
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D sets the main loader file’s attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareCalisto

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

T1564.001
Hidden Files and Directories
MalwareCarberp

Carberp has created a hidden file in the Startup folder of the current user.

T1564.001
Hidden Files and Directories
MalwareSysUpdate

SysUpdate has the ability to set file attributes to hidden.

T1564.001
Hidden Files and Directories
MalwareBackConfig

BackConfig has the ability to set folders or files to be hidden from the Windows Explorer default view.

T1564.001
Hidden Files and Directories
MalwareLokibot

Lokibot has the ability to copy itself to a hidden file and directory.

T1564.001
Hidden Files and Directories
MalwarePoetRAT

PoetRAT has the ability to hide and unhide files.

T1564.001
Hidden Files and Directories
MalwareCoinTicker

CoinTicker downloads the following hidden files to evade detection and maintain persistence: /private/tmp/.info.enc, /private/tmp/.info.py, /private/tmp/.server.sh, ~/Library/LaunchAgents/.espl.plist, ~/Library/Containers/.[random string]/[random string].

T1564.001
Hidden Files and Directories
MalwareHIUPAN

HIUPAN has modified registry keys to ensure hidden files and extensions are not visible through the modification of `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced`.

T1564.001
Hidden Files and Directories
MalwareXCSSET

XCSSET uses a hidden folder named .xcassets and .git to embed itself in Xcode.

T1564.001
Hidden Files and Directories
MalwareAppleJeus

AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings.

T1564.001
Hidden Files and Directories
MalwareAgent Tesla

Agent Tesla has created hidden folders.

T1564.001
Hidden Files and Directories
MalwareQakBot

QakBot has placed its payload in hidden subdirectories.

T1564.001
Hidden Files and Directories
MalwareKomplex

The Komplex payload is stored in a hidden directory at /Users/Shared/.local/kextd.

T1564.001
Hidden Files and Directories
MalwareOSX/Shlayer

OSX/Shlayer has executed a .command script from a hidden directory in a mounted DMG.

T1564.001
Hidden Files and Directories
MalwareMacSpy

MacSpy stores itself in ~/Library/.DS_Stores/

T1564.001
Hidden Files and Directories
MalwareLoudMiner

LoudMiner has set the attributes of the VirtualBox directory and VBoxVmService parent directory to "hidden".

T1564.001
Hidden Files and Directories
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has been created with a hidden attribute to insure it's not visible to the victim.

T1564.001
Hidden Files and Directories
Toolattrib

attrib can be used to make files or directories hidden.

T1564.001
Hidden Files and Directories
ToolImminent Monitor

Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden.

T1564.001
Hidden Files and Directories
ToolQuasarRAT

QuasarRAT has the ability to set file attributes to "hidden" to hide files from the compromised user's view in Windows File Explorer.

T1564.001
Hidden Files and Directories
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a hidden directory in the user's home folder on Linux hosts to write a python backdoor.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.