Hidden Files and Directories

T1564.001

Sub-technique of T1564 Hide Artifacts.View on attack.mitre.org

About this technique

Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a ‘hidden’ file. These files don’t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface (GUI) prompts or with command line switches (dir /a for Windows and ls –a for Linux and macOS).

On Linux and Mac, users can mark specific files as hidden simply by putting a “.” as the first character in the file or folder name . Files and folders that start with a period, ‘.’, are by default hidden from being viewed in the Finder application and standard command-line utilities like “ls”. Users must specifically change settings to have these files viewable.

Files on macOS can also be marked with the UF_HIDDEN flag which prevents them from being seen in Finder.app, but still allows them to be seen in Terminal.app . On Windows, users can mark specific files as hidden by using the attrib.exe binary. Many applications create these hidden files and folders to store information so that it doesn’t clutter up the user’s workspace. For example, SSH utilities create a .ssh folder that’s hidden and contains the user’s known hosts and keys.

Additionally, adversaries may name files in a manner that would allow the file to be hidden such as naming a file only a “space” character.

Adversaries can use this to their advantage to hide files and folders anywhere on the system and evading a typical user or system analysis that does not incorporate investigation of hidden files.

Detection rules10

Rules on DetectionCode tagged with T1564.001.

Sigma7

RuleLevelLog source
PowerShell Logging Disabled Via Registry Key Tamperinghighwindows / registry_set
Registry Persistence via Service in Safe Modehighwindows / registry_set
Set Suspicious Files as System Files Using Attrib.EXEhighwindows / process_creation
Displaying Hidden Files Feature Disabledmediumwindows / registry_set
Hiding Files with Attrib.exemediumwindows / process_creation
Use Icacls to Hide File to Everyonemediumwindows / process_creation
Hidden Files and Directorieslowlinux / NULL

Splunk3

RuleTypeRiskData source
Disable Show Hidden FilesAnomalyNULLSysmon EventID 13
MacOS Hidden Files and DirectoriesAnomalyNULLOsquery Results
Reg exe used to hide files directories via registry keysTTPNULLSysmon EventID 1

Groups13

Software46

Show 22 more

Campaigns1

Procedure examples60

Groups13

Used byProcedure example
GroupAPT28

APT28 has saved files with hidden file attributes.

GroupAPT32

APT32's macOS backdoor hides the clientID file via a chflags function.

GroupFIN13

FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information.

GroupFIN7

FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden.

GroupHAFNIUM

HAFNIUM has hidden files on a compromised host.

GroupLazarus Group

Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application.

GroupLuminousMoth

LuminousMoth has used malware to store malicious binaries in hidden directories on victim's USB drives.

GroupMustang Panda

Mustang Panda's PlugX variant has created a hidden folder on USB drives named RECYCLE.BIN to store malicious executables and collected data. Mustang Panda has also modified file attributes to `hidden` and `system`.

View all 13 groups examples

Software46

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has created hidden folders.

MalwareAppleJeus

AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings.

MalwareAttor

Attor can set attributes of log files and directories to HIDDEN, SYSTEM, ARCHIVE, or a combination of those.

Toolattrib

attrib can be used to make files or directories hidden.

MalwareBackConfig

BackConfig has the ability to set folders or files to be hidden from the Windows Explorer default view.

MalwareCalisto

Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration.

MalwareCarberp

Carberp has created a hidden file in the Startup folder of the current user.

Malwareccf32

ccf32 has created a hidden directory on targeted systems, naming it after the current local time (year, month, and day).

View all 46 software examples

Campaigns1

Used byProcedure example
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda stored encrypted payloads associated with PlugX installation in hidden directories during RedDelta Modified PlugX Infection Chain Operations.

References3

  1. Antiquated Mac Malware Open source
    Thomas Reed. (2017, January 18). New Mac backdoor using antiquated code. Retrieved July 5, 2017.
  2. Sofacy Komplex Trojan Open source
    Dani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.
  3. WireLurker Open source
    Claud Xiao. (n.d.). WireLurker: A New Era in iOS and OS X Malware. Retrieved July 10, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.