Real-world descriptions of how a group, tool or campaign used a technique.
46 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.001 Hidden Files and Directories |
MalwareCOATHANGER | COATHANGER creates and installs itself to a hidden installation directory. |
| T1564.001 Hidden Files and Directories |
MalwareNETWIRE | NETWIRE can copy itself to and launch itself from hidden folders. |
| T1564.001 Hidden Files and Directories |
MalwareiKitten | iKitten saves itself with a leading "." so that it's hidden from users by default. |
| T1564.001 Hidden Files and Directories |
MalwareEnvyScout | EnvyScout can use hidden directories and files to hide malicious executables. |
| T1564.001 Hidden Files and Directories |
MalwareMachete | Machete has the capability to exfiltrate stolen data to a hidden folder on a removable drive. |
| T1564.001 Hidden Files and Directories |
MalwareDacls | Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application. |
| T1564.001 Hidden Files and Directories |
MalwareCuckoo Stealer | Cuckoo Stealer has copied its binary and the victim's scraped password into a hidden folder in the `/Users` directory. |
| T1564.001 Hidden Files and Directories |
MalwareWastedLocker | WastedLocker has copied a random file from the Windows System32 folder to the |
| T1564.001 Hidden Files and Directories |
MalwareInvisiMole | InvisiMole can create hidden system directories. |
| T1564.001 Hidden Files and Directories |
MalwareCLAIMLOADER | CLAIMLOADER has modified file attributes to remain hidden to a standard user. |
| T1564.001 Hidden Files and Directories |
MalwareFruitFly | FruitFly saves itself with a leading "." to make it a hidden file. |
| T1564.001 Hidden Files and Directories |
MalwareOkrum | Before exfiltration, Okrum's backdoor has used hidden files to store logs and outputs from backdoor commands. |
| T1564.001 Hidden Files and Directories |
MalwareREPTILE | REPTILE has the ability to communicate with the kernel-mode component to hide files. |
| T1564.001 Hidden Files and Directories |
MalwareRising Sun | Rising Sun can modify file attributes to hide files. |
| T1564.001 Hidden Files and Directories |
MalwarePlugX | PlugX can modify the characteristics of folders to hide them from the compromised user. PlugX has also modified file attributes to hidden and system. |
| T1564.001 Hidden Files and Directories |
MalwareExplosive | Explosive has commonly set file and path attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareClambling | Clambling has the ability to set its file attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareDarkGate | DarkGate initial installation involves dropping several files to a hidden directory named after the victim machine name. Additionally, DarkGate uses attrib to hide a directory in the following command: ` C:\Windows\system32\attrib.exe” +h C:/rjtu/`. |
| T1564.001 Hidden Files and Directories |
MalwareThiefQuest | ThiefQuest hides a copy of itself in the user's |
| T1564.001 Hidden Files and Directories |
MalwareWannaCry | |
| T1564.001 Hidden Files and Directories |
MalwareIxeshe | Ixeshe sets its own executable file's attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareMicropsia | Micropsia creates a new hidden directory to store all components' outputs in a dedicated sub-folder for each. |
| T1564.001 Hidden Files and Directories |
MalwareAttor | Attor can set attributes of log files and directories to HIDDEN, SYSTEM, ARCHIVE, or a combination of those. |
| T1564.001 Hidden Files and Directories |
Malwareccf32 | ccf32 has created a hidden directory on targeted systems, naming it after the current local time (year, month, and day). |
| T1564.001 Hidden Files and Directories |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D sets the main loader file’s attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareCalisto | Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
| T1564.001 Hidden Files and Directories |
MalwareCarberp | Carberp has created a hidden file in the Startup folder of the current user. |
| T1564.001 Hidden Files and Directories |
MalwareSysUpdate | SysUpdate has the ability to set file attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareBackConfig | BackConfig has the ability to set folders or files to be hidden from the Windows Explorer default view. |
| T1564.001 Hidden Files and Directories |
MalwareLokibot | Lokibot has the ability to copy itself to a hidden file and directory. |
| T1564.001 Hidden Files and Directories |
MalwarePoetRAT | PoetRAT has the ability to hide and unhide files. |
| T1564.001 Hidden Files and Directories |
MalwareCoinTicker | CoinTicker downloads the following hidden files to evade detection and maintain persistence: /private/tmp/.info.enc, /private/tmp/.info.py, /private/tmp/.server.sh, ~/Library/LaunchAgents/.espl.plist, ~/Library/Containers/.[random string]/[random string]. |
| T1564.001 Hidden Files and Directories |
MalwareHIUPAN | HIUPAN has modified registry keys to ensure hidden files and extensions are not visible through the modification of `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced`. |
| T1564.001 Hidden Files and Directories |
MalwareXCSSET | XCSSET uses a hidden folder named |
| T1564.001 Hidden Files and Directories |
MalwareAppleJeus | AppleJeus has added a leading |
| T1564.001 Hidden Files and Directories |
MalwareAgent Tesla | Agent Tesla has created hidden folders. |
| T1564.001 Hidden Files and Directories |
MalwareQakBot | QakBot has placed its payload in hidden subdirectories. |
| T1564.001 Hidden Files and Directories |
MalwareKomplex | The Komplex payload is stored in a hidden directory at |
| T1564.001 Hidden Files and Directories |
MalwareOSX/Shlayer | OSX/Shlayer has executed a .command script from a hidden directory in a mounted DMG. |
| T1564.001 Hidden Files and Directories |
MalwareMacSpy | MacSpy stores itself in |
| T1564.001 Hidden Files and Directories |
MalwareLoudMiner | LoudMiner has set the attributes of the VirtualBox directory and VBoxVmService parent directory to "hidden". |
| T1564.001 Hidden Files and Directories |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has been created with a hidden attribute to insure it's not visible to the victim. |
| T1564.001 Hidden Files and Directories |
Toolattrib | attrib can be used to make files or directories hidden. |
| T1564.001 Hidden Files and Directories |
ToolImminent Monitor | Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden. |
| T1564.001 Hidden Files and Directories |
ToolQuasarRAT | QuasarRAT has the ability to set file attributes to "hidden" to hide files from the compromised user's view in Windows File Explorer. |
| T1564.001 Hidden Files and Directories |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a hidden directory in the user's home folder on Linux hosts to write a python backdoor. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.