Real-world descriptions of how a group, tool or campaign used a technique.
43 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.003 Hidden Window |
MalwareTrickBot | TrickBot has used a hidden VNC (hVNC) window to monitor the victim and collect information stealthily. |
| T1564.003 Hidden Window |
MalwareQuietSieve | QuietSieve has the ability to execute payloads in a hidden window. |
| T1564.003 Hidden Window |
MalwareAvosLocker | AvosLocker has hidden its console window by using the `ShowWindow` API function. |
| T1564.003 Hidden Window |
MalwareWindTail | WindTail can instruct the OS to execute an application without a dock icon or menu. |
| T1564.003 Hidden Window |
MalwareUrsnif | Ursnif droppers have used COM properties to execute malware in hidden windows. |
| T1564.003 Hidden Window |
MalwareTsundere Botnet | Tsundere Botnet’s MSI installer has used `-WindowStyle Hidden` to hide Tsundere Botnet’s execution from the user. |
| T1564.003 Hidden Window |
MalwareInvisibleFerret | InvisibleFerret has executed Python instances of the browser module “.n2/bow” utilizing the `CREATE_NO_WINDOW` process creation flag. |
| T1564.003 Hidden Window |
MalwareSharpDisco | SharpDisco can hide windows using `ProcessWindowStyle.Hidden`. |
| T1564.003 Hidden Window |
MalwareStrongPity | StrongPity has the ability to hide the console window for its document search module from the user. |
| T1564.003 Hidden Window |
MalwareMedusa Ransomware | Medusa Ransomware has utilized the `ShowWindow` function to hide current window. |
| T1564.003 Hidden Window |
MalwareBOOKWORM | BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module. |
| T1564.003 Hidden Window |
MalwareHAMMERTOSS | HAMMERTOSS has used |
| T1564.003 Hidden Window |
MalwareIMAPLoader | IMAPLoader hides the Windows Console window created by its execution by directly importing the `kernel32.dll` and `user32.dll` libraries `GetConsoleWindow` and `ShowWindow` APIs. |
| T1564.003 Hidden Window |
MalwareSystemBC | SystemBC has utilized the `-WindowStyle Hidden -ep bypass -file `to conceal PowerShell windows. |
| T1564.003 Hidden Window |
MalwareCANONSTAGER | CANONSTAGER has created a new window with a height and width of zero to remain hidden on the screen. |
| T1564.003 Hidden Window |
MalwareSnip3 | Snip3 can execute PowerShell scripts in a hidden window. |
| T1564.003 Hidden Window |
MalwareInvisiMole | InvisiMole has executed legitimate tools in hidden windows. |
| T1564.003 Hidden Window |
MalwarePowerShower | PowerShower has added a registry key so future powershell.exe instances are spawned with coordinates for a window position off-screen by default. |
| T1564.003 Hidden Window |
MalwareKeyBoy | KeyBoy uses |
| T1564.003 Hidden Window |
MalwarePlugX | PlugX has the ability to execute a command on a hidden desktop. |
| T1564.003 Hidden Window |
MalwareLumma Stealer | Lumma Stealer has utilized the .NET `ProcessStartInfo` class features to prevent the process from creating a visible window through setting the `CreateNoWindow` setting to “True,” which allows the executed command or script to run without displaying a command prompt window. |
| T1564.003 Hidden Window |
MalwareCuba | Cuba has executed hidden PowerShell windows. |
| T1564.003 Hidden Window |
MalwarePureCrypter | PureCrypter can set `ProcessWindowStyle.Hidden` to hide windows on victim machines. |
| T1564.003 Hidden Window |
MalwareGlassWorm | GlassWorm has leveraged Hidden Virtual Network Computing (HVNC) to remain undetected and conduct execution of collection and communication actions. |
| T1564.003 Hidden Window |
MalwareMetamorfo | Metamorfo has hidden its GUI using the ShowWindow() WINAPI call. |
| T1564.003 Hidden Window |
MalwareQUIETCANARY | QUIETCANARY can execute processes in a hidden window. |
| T1564.003 Hidden Window |
MalwareLockBit 2.0 | LockBit 2.0 can execute command line arguments in a hidden window. |
| T1564.003 Hidden Window |
MalwareHotCroissant | HotCroissant has the ability to hide the window for operations performed on a given file. |
| T1564.003 Hidden Window |
MalwareOilBooster | OilBooster can hide its console window upon execution through the `ShowWindow` API. |
| T1564.003 Hidden Window |
MalwareKivars | Kivars has the ability to conceal its activity through hiding active windows. |
| T1564.003 Hidden Window |
MalwareBONDUPDATER | BONDUPDATER uses |
| T1564.003 Hidden Window |
MalwareMeteor | Meteor can hide its console window upon execution to decrease its visibility to a victim. |
| T1564.003 Hidden Window |
MalwareKOCTOPUS | KOCTOPUS has used |
| T1564.003 Hidden Window |
MalwareKevin | Kevin can hide the current window from the targeted user via the `ShowWindow` API function. |
| T1564.003 Hidden Window |
MalwareAgent Tesla | Agent Tesla has used |
| T1564.003 Hidden Window |
MalwareAstaroth | Astaroth loads its module with the XSL script parameter |
| T1564.003 Hidden Window |
MalwareWarzoneRAT | WarzoneRAT has the ability of performing remote desktop access via a hVNC window for decreased visibility. |
| T1564.003 Hidden Window |
ToolSILENTTRINITY | SILENTTRINITY has the ability to set its window state to hidden. |
| T1564.003 Hidden Window |
ToolAsyncRAT | AsyncRAT can hide the execution of scheduled tasks using `ProcessWindowStyle.Hidden`. |
| T1564.003 Hidden Window |
ToolRemcos | Remcos can set `ProcessWindowStyle.Hidden` to hide windows. |
| T1564.003 Hidden Window |
ToolMCMD | MCMD can modify processes to prevent them from being visible on the desktop. |
| T1564.003 Hidden Window |
ToolKoadic | Koadic has used the command |
| T1564.003 Hidden Window |
ToolQuasarRAT | QuasarRAT can hide process windows and make web requests invisible to the compromised user. Requests marked as invisible have been sent with user-agent string `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A` though QuasarRAT can only be run on Windows systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.