Sub-technique of T1564 Hide Artifacts.View on attack.mitre.org
Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a ‘hidden’ file. These files don’t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface (GUI) prompts or with command line switches (dir /a for Windows and ls –a for Linux and macOS).
On Linux and Mac, users can mark specific files as hidden simply by putting a “.” as the first character in the file or folder name . Files and folders that start with a period, ‘.’, are by default hidden from being viewed in the Finder application and standard command-line utilities like “ls”. Users must specifically change settings to have these files viewable.
Files on macOS can also be marked with the UF_HIDDEN flag which prevents them from being seen in Finder.app, but still allows them to be seen in Terminal.app . On Windows, users can mark specific files as hidden by using the attrib.exe binary. Many applications create these hidden files and folders to store information so that it doesn’t clutter up the user’s workspace. For example, SSH utilities create a .ssh folder that’s hidden and contains the user’s known hosts and keys.
Additionally, adversaries may name files in a manner that would allow the file to be hidden such as naming a file only a “space” character.
Adversaries can use this to their advantage to hide files and folders anywhere on the system and evading a typical user or system analysis that does not incorporate investigation of hidden files.
Rules on DetectionCode tagged with T1564.001.
| Rule | Level | Log source |
|---|---|---|
| PowerShell Logging Disabled Via Registry Key Tampering | high | windows / registry_set |
| Registry Persistence via Service in Safe Mode | high | windows / registry_set |
| Set Suspicious Files as System Files Using Attrib.EXE | high | windows / process_creation |
| Displaying Hidden Files Feature Disabled | medium | windows / registry_set |
| Hiding Files with Attrib.exe | medium | windows / process_creation |
| Use Icacls to Hide File to Everyone | medium | windows / process_creation |
| Hidden Files and Directories | low | linux / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Disable Show Hidden Files | Anomaly | NULL | Sysmon EventID 13 |
| MacOS Hidden Files and Directories | Anomaly | NULL | Osquery Results |
| Reg exe used to hide files directories via registry keys | TTP | NULL | Sysmon EventID 1 |
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 has saved files with hidden file attributes. |
| GroupAPT32 | APT32's macOS backdoor hides the clientID file via a chflags function. |
| GroupFIN13 | FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information. |
| GroupFIN7 | FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden. |
| GroupHAFNIUM | HAFNIUM has hidden files on a compromised host. |
| GroupLazarus Group | Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application. |
| GroupLuminousMoth | LuminousMoth has used malware to store malicious binaries in hidden directories on victim's USB drives. |
| GroupMustang Panda | Mustang Panda's PlugX variant has created a hidden folder on USB drives named |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla has created hidden folders. |
| MalwareAppleJeus | AppleJeus has added a leading |
| MalwareAttor | Attor can set attributes of log files and directories to HIDDEN, SYSTEM, ARCHIVE, or a combination of those. |
| Toolattrib | attrib can be used to make files or directories hidden. |
| MalwareBackConfig | BackConfig has the ability to set folders or files to be hidden from the Windows Explorer default view. |
| MalwareCalisto | Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
| MalwareCarberp | Carberp has created a hidden file in the Startup folder of the current user. |
| Malwareccf32 | ccf32 has created a hidden directory on targeted systems, naming it after the current local time (year, month, and day). |
| Used by | Procedure example |
|---|---|
| CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda stored encrypted payloads associated with PlugX installation in hidden directories during RedDelta Modified PlugX Infection Chain Operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.