Real-world descriptions of how a group, tool or campaign used a technique.
15 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.004 NTFS File Attributes |
MalwarePowerDuke | PowerDuke hides many of its backdoor payloads in an alternate data stream (ADS). |
| T1564.004 NTFS File Attributes |
MalwarePOWERSOURCE | If the victim is using PowerShell 3.0 or later, POWERSOURCE writes its decoded payload to an alternate data stream (ADS) named kernel32.dll that is saved in |
| T1564.004 NTFS File Attributes |
MalwareWastedLocker | WastedLocker has the ability to save and execute files as an alternate data stream (ADS). |
| T1564.004 NTFS File Attributes |
MalwareRegin | The Regin malware platform uses Extended Attributes to store encrypted executables. |
| T1564.004 NTFS File Attributes |
MalwareZeroaccess | Some variants of the Zeroaccess Trojan have been known to store data in Extended Attributes. |
| T1564.004 NTFS File Attributes |
MalwareAnchor | Anchor has used NTFS to hide files. |
| T1564.004 NTFS File Attributes |
MalwareGazer | Gazer stores configuration items in alternate data streams (ADSs) if the Registry is not accessible. |
| T1564.004 NTFS File Attributes |
MalwareLatrodectus | Latrodectus can delete itself while its process is still running through the use of an alternate data stream. |
| T1564.004 NTFS File Attributes |
MalwareValak | Valak has the ability save and execute files as alternate data streams (ADS). |
| T1564.004 NTFS File Attributes |
MalwareLoJax | LoJax has loaded an embedded NTFS DXE driver to be able to access and write to NTFS partitions. |
| T1564.004 NTFS File Attributes |
MalwareDEADEYE | The DEADEYE.EMBED variant of DEADEYE can embed its payload in an alternate data stream of a local file. |
| T1564.004 NTFS File Attributes |
MalwareAstaroth | Astaroth can abuse alternate data streams (ADS) to store content for malicious payloads. |
| T1564.004 NTFS File Attributes |
MalwareBitPaymer | BitPaymer has copied itself to the |
| T1564.004 NTFS File Attributes |
Toolesentutl | esentutl can be used to read and write alternate data streams. |
| T1564.004 NTFS File Attributes |
ToolExpand | Expand can be used to download or copy a file into an alternate data stream. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.