ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1564.004×

15 examples

TechniqueUsed byProcedure example
T1564.004
NTFS File Attributes
MalwarePowerDuke

PowerDuke hides many of its backdoor payloads in an alternate data stream (ADS).

T1564.004
NTFS File Attributes
MalwarePOWERSOURCE

If the victim is using PowerShell 3.0 or later, POWERSOURCE writes its decoded payload to an alternate data stream (ADS) named kernel32.dll that is saved in %PROGRAMDATA%\Windows\.

T1564.004
NTFS File Attributes
MalwareWastedLocker

WastedLocker has the ability to save and execute files as an alternate data stream (ADS).

T1564.004
NTFS File Attributes
MalwareRegin

The Regin malware platform uses Extended Attributes to store encrypted executables.

T1564.004
NTFS File Attributes
MalwareZeroaccess

Some variants of the Zeroaccess Trojan have been known to store data in Extended Attributes.

T1564.004
NTFS File Attributes
MalwareAnchor

Anchor has used NTFS to hide files.

T1564.004
NTFS File Attributes
MalwareGazer

Gazer stores configuration items in alternate data streams (ADSs) if the Registry is not accessible.

T1564.004
NTFS File Attributes
MalwareLatrodectus

Latrodectus can delete itself while its process is still running through the use of an alternate data stream.

T1564.004
NTFS File Attributes
MalwareValak

Valak has the ability save and execute files as alternate data streams (ADS).

T1564.004
NTFS File Attributes
MalwareLoJax

LoJax has loaded an embedded NTFS DXE driver to be able to access and write to NTFS partitions.

T1564.004
NTFS File Attributes
MalwareDEADEYE

The DEADEYE.EMBED variant of DEADEYE can embed its payload in an alternate data stream of a local file.

T1564.004
NTFS File Attributes
MalwareAstaroth

Astaroth can abuse alternate data streams (ADS) to store content for malicious payloads.

T1564.004
NTFS File Attributes
MalwareBitPaymer

BitPaymer has copied itself to the :bin alternate data stream of a newly created file.

T1564.004
NTFS File Attributes
Toolesentutl

esentutl can be used to read and write alternate data streams.

T1564.004
NTFS File Attributes
ToolExpand

Expand can be used to download or copy a file into an alternate data stream.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.