Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1564.001 Hidden Files and Directories |
GroupHAFNIUM | HAFNIUM has hidden files on a compromised host. |
| T1564.001 Hidden Files and Directories |
GroupFIN7 | FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden. |
| T1564.001 Hidden Files and Directories |
GroupMustang Panda | Mustang Panda's PlugX variant has created a hidden folder on USB drives named |
| T1564.001 Hidden Files and Directories |
GroupRocke | Rocke downloaded a file "libprocesshider", which could hide files on the target system. |
| T1564.001 Hidden Files and Directories |
GroupTropic Trooper | Tropic Trooper has created a hidden directory under |
| T1564.001 Hidden Files and Directories |
GroupRedCurl | RedCurl added the “hidden” file attribute to original files, manipulating victims to click on malicious LNK files. |
| T1564.001 Hidden Files and Directories |
GroupLuminousMoth | LuminousMoth has used malware to store malicious binaries in hidden directories on victim's USB drives. |
| T1564.001 Hidden Files and Directories |
GroupAPT28 | APT28 has saved files with hidden file attributes. |
| T1564.001 Hidden Files and Directories |
GroupLazarus Group | Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application. |
| T1564.001 Hidden Files and Directories |
GroupTransparent Tribe | Transparent Tribe can hide legitimate directories and replace them with malicious copies of the same name. |
| T1564.001 Hidden Files and Directories |
GroupFIN13 | FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information. |
| T1564.001 Hidden Files and Directories |
MalwareCOATHANGER | COATHANGER creates and installs itself to a hidden installation directory. |
| T1564.001 Hidden Files and Directories |
MalwareNETWIRE | NETWIRE can copy itself to and launch itself from hidden folders. |
| T1564.001 Hidden Files and Directories |
MalwareiKitten | iKitten saves itself with a leading "." so that it's hidden from users by default. |
| T1564.001 Hidden Files and Directories |
MalwareEnvyScout | EnvyScout can use hidden directories and files to hide malicious executables. |
| T1564.001 Hidden Files and Directories |
MalwareMachete | Machete has the capability to exfiltrate stolen data to a hidden folder on a removable drive. |
| T1564.001 Hidden Files and Directories |
MalwareDacls | Dacls has had its payload named with a dot prefix to make it hidden from view in the Finder application. |
| T1564.001 Hidden Files and Directories |
MalwareCuckoo Stealer | Cuckoo Stealer has copied its binary and the victim's scraped password into a hidden folder in the `/Users` directory. |
| T1564.001 Hidden Files and Directories |
MalwareWastedLocker | WastedLocker has copied a random file from the Windows System32 folder to the |
| T1564.001 Hidden Files and Directories |
MalwareInvisiMole | InvisiMole can create hidden system directories. |
| T1564.001 Hidden Files and Directories |
MalwareCLAIMLOADER | CLAIMLOADER has modified file attributes to remain hidden to a standard user. |
| T1564.001 Hidden Files and Directories |
MalwareFruitFly | FruitFly saves itself with a leading "." to make it a hidden file. |
| T1564.001 Hidden Files and Directories |
MalwareOkrum | Before exfiltration, Okrum's backdoor has used hidden files to store logs and outputs from backdoor commands. |
| T1564.001 Hidden Files and Directories |
MalwareREPTILE | REPTILE has the ability to communicate with the kernel-mode component to hide files. |
| T1564.001 Hidden Files and Directories |
MalwareRising Sun | Rising Sun can modify file attributes to hide files. |
| T1564.001 Hidden Files and Directories |
MalwarePlugX | PlugX can modify the characteristics of folders to hide them from the compromised user. PlugX has also modified file attributes to hidden and system. |
| T1564.001 Hidden Files and Directories |
MalwareExplosive | Explosive has commonly set file and path attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareClambling | Clambling has the ability to set its file attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareDarkGate | DarkGate initial installation involves dropping several files to a hidden directory named after the victim machine name. Additionally, DarkGate uses attrib to hide a directory in the following command: ` C:\Windows\system32\attrib.exe” +h C:/rjtu/`. |
| T1564.001 Hidden Files and Directories |
MalwareThiefQuest | ThiefQuest hides a copy of itself in the user's |
| T1564.001 Hidden Files and Directories |
MalwareWannaCry | |
| T1564.001 Hidden Files and Directories |
MalwareIxeshe | Ixeshe sets its own executable file's attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareMicropsia | Micropsia creates a new hidden directory to store all components' outputs in a dedicated sub-folder for each. |
| T1564.001 Hidden Files and Directories |
MalwareAttor | Attor can set attributes of log files and directories to HIDDEN, SYSTEM, ARCHIVE, or a combination of those. |
| T1564.001 Hidden Files and Directories |
Malwareccf32 | ccf32 has created a hidden directory on targeted systems, naming it after the current local time (year, month, and day). |
| T1564.001 Hidden Files and Directories |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D sets the main loader file’s attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareCalisto | Calisto uses a hidden directory named .calisto to store data from the victim’s machine before exfiltration. |
| T1564.001 Hidden Files and Directories |
MalwareCarberp | Carberp has created a hidden file in the Startup folder of the current user. |
| T1564.001 Hidden Files and Directories |
MalwareSysUpdate | SysUpdate has the ability to set file attributes to hidden. |
| T1564.001 Hidden Files and Directories |
MalwareBackConfig | BackConfig has the ability to set folders or files to be hidden from the Windows Explorer default view. |
| T1564.001 Hidden Files and Directories |
MalwareLokibot | Lokibot has the ability to copy itself to a hidden file and directory. |
| T1564.001 Hidden Files and Directories |
MalwarePoetRAT | PoetRAT has the ability to hide and unhide files. |
| T1564.001 Hidden Files and Directories |
MalwareCoinTicker | CoinTicker downloads the following hidden files to evade detection and maintain persistence: /private/tmp/.info.enc, /private/tmp/.info.py, /private/tmp/.server.sh, ~/Library/LaunchAgents/.espl.plist, ~/Library/Containers/.[random string]/[random string]. |
| T1564.001 Hidden Files and Directories |
MalwareHIUPAN | HIUPAN has modified registry keys to ensure hidden files and extensions are not visible through the modification of `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced`. |
| T1564.001 Hidden Files and Directories |
MalwareXCSSET | XCSSET uses a hidden folder named |
| T1564.001 Hidden Files and Directories |
MalwareAppleJeus | AppleJeus has added a leading |
| T1564.001 Hidden Files and Directories |
MalwareAgent Tesla | Agent Tesla has created hidden folders. |
| T1564.001 Hidden Files and Directories |
MalwareQakBot | QakBot has placed its payload in hidden subdirectories. |
| T1564.001 Hidden Files and Directories |
MalwareKomplex | The Komplex payload is stored in a hidden directory at |
| T1564.001 Hidden Files and Directories |
MalwareOSX/Shlayer | OSX/Shlayer has executed a .command script from a hidden directory in a mounted DMG. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.