Clear Persistence

T1070.009

Sub-technique of T1070 Indicator Removal.View on attack.mitre.org

About this technique

Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity. This may involve various actions, such as removing services, deleting executables, Modify Registry, Plist File Modification, or other methods of cleanup to prevent defenders from collecting evidence of their persistent presence. Adversaries may also delete accounts previously created to maintain persistence (i.e. Create Account).

In some instances, artifacts of persistence may also be removed once an adversary’s persistence is executed in order to prevent errors with the new instance of the malware.

Detection rules0

Rules on DetectionCode tagged with T1070.009.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software15

Campaigns0

None recorded.

Procedure examples15

Software15

Used byProcedure example
MalwareBazar

Bazar's loader can delete scheduled tasks created by a previous instance of the malware.

MalwareGrimAgent

GrimAgent can delete previously created tasks on a compromised host.

MalwareIPsec Helper

IPsec Helper can delete various service traces related to persistent execution when commanded.

MalwareKapeka

Kapeka will clear registry values used for persistent configuration storage when uninstalled.

MalwareKOCTOPUS

KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure.

ToolMCMD

MCMD has the ability to remove set Registry Keys, including those used for persistence.

MalwareMisdat

Misdat is capable of deleting Registry keys used for persistence.

MalwarenjRAT

njRAT is capable of manipulating and deleting registry keys, including those used for persistence.

View all 15 software examples

References3

  1. Cylance Dust Storm Open source
    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.
  2. NCC Group Team9 June 2020 Open source
    Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020.
  3. Talos - Cisco Attack 2022 Open source
    Nick Biasini. (2022, August 10). Cisco Talos shares insights related to recent cyber attack on Cisco. Retrieved March 9, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.