ATT&CKReferencesESET HiddenFace 2024

ESET HiddenFace 2024

Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1027.007
Dynamic API Resolution
MalwareHiddenFace

HiddenFace can dynamically resolve Windows APIs.

T1027.013
Encrypted/Encoded File
MalwareHiddenFace

HiddenFace has encrypted its payload with AES.

T1033
System Owner/User Discovery
MalwareHiddenFace

HiddenFace can collect the username associated with the compromised host.

T1053.005
Scheduled Task
MalwareHiddenFace

HiddenFace has used scheduled tasks for execution and persistence.

T1057
Process Discovery
MalwareHiddenFace

HiddenFace can check running processes against a list of blocklisted applications.

T1070.006
Timestomp
MalwareHiddenFace

HiddenFace can alter timestamps for directory content on targeted machines.

T1082
System Information Discovery
MalwareHiddenFace

HiddenFace can enumerate the hostname and username of the compromised system.

T1095
Non-Application Layer Protocol
MalwareHiddenFace

HiddenFace can use a custom TCP protocol over Port 443 for C2.

T1140
Deobfuscate/Decode Files or Information
MalwareHiddenFace

HiddenFace has the ability to decrypt its payload prior to execution.

T1480.002
Mutual Exclusion
MalwareHiddenFace

HiddenFace can create a mutex to ensure only one instance is running at a time.

T1497.003
Time Based Checks
MalwareHiddenFace

HiddenFace can sleep randomly between 30 and 60 seconds to avoid behavioral analysis.

T1518.001
Security Software Discovery
MalwareHiddenFace

HiddenFace can identify processes identified with security applications and tooling.

T1568.002
Domain Generation Algorithms
MalwareHiddenFace

HiddenFace has used dynamic domain generation algorithms in C2.

T1573.001
Symmetric Cryptography
MalwareHiddenFace

HiddenFace can use a randomly selected symmetric encryption algorithm for C2.

T1686.003
Windows Host Firewall
MalwareHiddenFace

HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.