ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1564.003×

43 examples

TechniqueUsed byProcedure example
T1564.003
Hidden Window
MalwareTrickBot

TrickBot has used a hidden VNC (hVNC) window to monitor the victim and collect information stealthily.

T1564.003
Hidden Window
MalwareQuietSieve

QuietSieve has the ability to execute payloads in a hidden window.

T1564.003
Hidden Window
MalwareAvosLocker

AvosLocker has hidden its console window by using the `ShowWindow` API function.

T1564.003
Hidden Window
MalwareWindTail

WindTail can instruct the OS to execute an application without a dock icon or menu.

T1564.003
Hidden Window
MalwareUrsnif

Ursnif droppers have used COM properties to execute malware in hidden windows.

T1564.003
Hidden Window
MalwareTsundere Botnet

Tsundere Botnet’s MSI installer has used `-WindowStyle Hidden` to hide Tsundere Botnet’s execution from the user.

T1564.003
Hidden Window
MalwareInvisibleFerret

InvisibleFerret has executed Python instances of the browser module “.n2/bow” utilizing the `CREATE_NO_WINDOW` process creation flag.

T1564.003
Hidden Window
MalwareSharpDisco

SharpDisco can hide windows using `ProcessWindowStyle.Hidden`.

T1564.003
Hidden Window
MalwareStrongPity

StrongPity has the ability to hide the console window for its document search module from the user.

T1564.003
Hidden Window
MalwareMedusa Ransomware

Medusa Ransomware has utilized the `ShowWindow` function to hide current window.

T1564.003
Hidden Window
MalwareBOOKWORM

BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module.

T1564.003
Hidden Window
MalwareHAMMERTOSS

HAMMERTOSS has used -WindowStyle hidden to conceal PowerShell windows.

T1564.003
Hidden Window
MalwareIMAPLoader

IMAPLoader hides the Windows Console window created by its execution by directly importing the `kernel32.dll` and `user32.dll` libraries `GetConsoleWindow` and `ShowWindow` APIs.

T1564.003
Hidden Window
MalwareSystemBC

SystemBC has utilized the `-WindowStyle Hidden -ep bypass -file `to conceal PowerShell windows.

T1564.003
Hidden Window
MalwareCANONSTAGER

CANONSTAGER has created a new window with a height and width of zero to remain hidden on the screen.

T1564.003
Hidden Window
MalwareSnip3

Snip3 can execute PowerShell scripts in a hidden window.

T1564.003
Hidden Window
MalwareInvisiMole

InvisiMole has executed legitimate tools in hidden windows.

T1564.003
Hidden Window
MalwarePowerShower

PowerShower has added a registry key so future powershell.exe instances are spawned with coordinates for a window position off-screen by default.

T1564.003
Hidden Window
MalwareKeyBoy

KeyBoy uses -w Hidden to conceal a PowerShell window that downloads a payload.

T1564.003
Hidden Window
MalwarePlugX

PlugX has the ability to execute a command on a hidden desktop.

T1564.003
Hidden Window
MalwareLumma Stealer

Lumma Stealer has utilized the .NET `ProcessStartInfo` class features to prevent the process from creating a visible window through setting the `CreateNoWindow` setting to “True,” which allows the executed command or script to run without displaying a command prompt window.

T1564.003
Hidden Window
MalwareCuba

Cuba has executed hidden PowerShell windows.

T1564.003
Hidden Window
MalwarePureCrypter

PureCrypter can set `ProcessWindowStyle.Hidden` to hide windows on victim machines.

T1564.003
Hidden Window
MalwareGlassWorm

GlassWorm has leveraged Hidden Virtual Network Computing (HVNC) to remain undetected and conduct execution of collection and communication actions.

T1564.003
Hidden Window
MalwareMetamorfo

Metamorfo has hidden its GUI using the ShowWindow() WINAPI call.

T1564.003
Hidden Window
MalwareQUIETCANARY

QUIETCANARY can execute processes in a hidden window.

T1564.003
Hidden Window
MalwareLockBit 2.0

LockBit 2.0 can execute command line arguments in a hidden window.

T1564.003
Hidden Window
MalwareHotCroissant

HotCroissant has the ability to hide the window for operations performed on a given file.

T1564.003
Hidden Window
MalwareOilBooster

OilBooster can hide its console window upon execution through the `ShowWindow` API.

T1564.003
Hidden Window
MalwareKivars

Kivars has the ability to conceal its activity through hiding active windows.

T1564.003
Hidden Window
MalwareBONDUPDATER

BONDUPDATER uses -windowstyle hidden to conceal a PowerShell window that downloads a payload.

T1564.003
Hidden Window
MalwareMeteor

Meteor can hide its console window upon execution to decrease its visibility to a victim.

T1564.003
Hidden Window
MalwareKOCTOPUS

KOCTOPUS has used -WindowsStyle Hidden to hide the command window.

T1564.003
Hidden Window
MalwareKevin

Kevin can hide the current window from the targeted user via the `ShowWindow` API function.

T1564.003
Hidden Window
MalwareAgent Tesla

Agent Tesla has used ProcessWindowStyle.Hidden to hide windows.

T1564.003
Hidden Window
MalwareAstaroth

Astaroth loads its module with the XSL script parameter vShow set to zero, which opens the application with a hidden window.

T1564.003
Hidden Window
MalwareWarzoneRAT

WarzoneRAT has the ability of performing remote desktop access via a hVNC window for decreased visibility.

T1564.003
Hidden Window
ToolSILENTTRINITY

SILENTTRINITY has the ability to set its window state to hidden.

T1564.003
Hidden Window
ToolAsyncRAT

AsyncRAT can hide the execution of scheduled tasks using `ProcessWindowStyle.Hidden`.

T1564.003
Hidden Window
ToolRemcos

Remcos can set `ProcessWindowStyle.Hidden` to hide windows.

T1564.003
Hidden Window
ToolMCMD

MCMD can modify processes to prevent them from being visible on the desktop.

T1564.003
Hidden Window
ToolKoadic

Koadic has used the command Powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden to hide its window.

T1564.003
Hidden Window
ToolQuasarRAT

QuasarRAT can hide process windows and make web requests invisible to the compromised user. Requests marked as invisible have been sent with user-agent string `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A` though QuasarRAT can only be run on Windows systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.