Hidden File System

T1564.005

Sub-technique of T1564 Hide Artifacts.View on attack.mitre.org

About this technique

Adversaries may use a hidden file system to conceal malicious activity from users and security tools. File systems provide a structure to store and access data from physical storage. Typically, a user engages with a file system through applications that allow them to access files and directories, which are an abstraction from their physical location (ex: disk sector). Standard file systems include FAT, NTFS, ext4, and APFS. File systems can also contain other structures, such as the Volume Boot Record (VBR) and Master File Table (MFT) in NTFS.

Adversaries may use their own abstracted file system, separate from the standard file system present on the infected system. In doing so, adversaries can hide the presence of malicious components and file input/output from security tools. Hidden file systems, sometimes referred to as virtual file systems, can be implemented in numerous ways. One implementation would be to store a file system in reserved disk space unused by disk structures or standard file system partitions. Another implementation could be for an adversary to drop their own portable partition image as a file on top of the standard file system. Adversaries may also fragment files across the existing file system structure in non-standard ways.

Detection rules0

Rules on DetectionCode tagged with T1564.005.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups2

Software4

Campaigns0

None recorded.

Procedure examples6

Groups2

Used byProcedure example
GroupEquation

Equation has used an encrypted virtual file system stored in the Windows Registry.

GroupStrider

Strider has used a hidden file system that is stored as a file on disk.

Software4

Used byProcedure example
MalwareBOOTRASH

BOOTRASH has used unallocated disk space between partitions for a hidden file system that stores components of the Nemesis bootkit.

MalwareComRAT

ComRAT has used a portable FAT16 partition image placed in %TEMP% as a hidden file system.

MalwareRegin

Regin has used a hidden file system to store some of its components.

MalwareUroburos

Uroburos can use concealed storage mechanisms including an NTFS or FAT-16 filesystem encrypted with CAST-128 in CBC mode.

References4

  1. ESET ComRAT May 2020 Open source
    Faou, M. (2020, May). From Agent.btz to ComRAT v4: A ten-year journey. Retrieved June 15, 2020.
  2. FireEye Bootkits Open source
    Andonov, D., et al. (2015, December 7). Thriving Beyond The Operating System: Financial Threat Group Targets Volume Boot Record. Retrieved May 13, 2016.
  3. Kaspersky Equation QA Open source
    Kaspersky Lab's Global Research and Analysis Team. (2015, February). Equation Group: Questions and Answers. Retrieved December 21, 2015.
  4. MalwareTech VFS Nov 2014 Open source
    Hutchins, M. (2014, November 28). Virtual File Systems for Beginners. Retrieved June 22, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.