Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.007 Dynamic API Resolution |
MalwareHiddenFace | HiddenFace can dynamically resolve Windows APIs. |
| T1027.013 Encrypted/Encoded File |
MalwareHiddenFace | HiddenFace has encrypted its payload with AES. |
| T1033 System Owner/User Discovery |
MalwareHiddenFace | HiddenFace can collect the username associated with the compromised host. |
| T1053.005 Scheduled Task |
MalwareHiddenFace | HiddenFace has used scheduled tasks for execution and persistence. |
| T1057 Process Discovery |
MalwareHiddenFace | HiddenFace can check running processes against a list of blocklisted applications. |
| T1070.006 Timestomp |
MalwareHiddenFace | HiddenFace can alter timestamps for directory content on targeted machines. |
| T1082 System Information Discovery |
MalwareHiddenFace | HiddenFace can enumerate the hostname and username of the compromised system. |
| T1095 Non-Application Layer Protocol |
MalwareHiddenFace | HiddenFace can use a custom TCP protocol over Port 443 for C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHiddenFace | HiddenFace has the ability to decrypt its payload prior to execution. |
| T1480.002 Mutual Exclusion |
MalwareHiddenFace | HiddenFace can create a mutex to ensure only one instance is running at a time. |
| T1497.003 Time Based Checks |
MalwareHiddenFace | HiddenFace can sleep randomly between 30 and 60 seconds to avoid behavioral analysis. |
| T1518.001 Security Software Discovery |
MalwareHiddenFace | HiddenFace can identify processes identified with security applications and tooling. |
| T1568.002 Domain Generation Algorithms |
MalwareHiddenFace | HiddenFace has used dynamic domain generation algorithms in C2. |
| T1573.001 Symmetric Cryptography |
MalwareHiddenFace | HiddenFace can use a randomly selected symmetric encryption algorithm for C2. |
| T1686.003 Windows Host Firewall |
MalwareHiddenFace | HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.