Sub-technique of T1070 Indicator Removal.View on attack.mitre.org
Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity. This may involve various actions, such as removing services, deleting executables, Modify Registry, Plist File Modification, or other methods of cleanup to prevent defenders from collecting evidence of their persistent presence. Adversaries may also delete accounts previously created to maintain persistence (i.e. Create Account).
In some instances, artifacts of persistence may also be removed once an adversary’s persistence is executed in order to prevent errors with the new instance of the malware.
Rules on DetectionCode tagged with T1070.009.
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareBazar | Bazar's loader can delete scheduled tasks created by a previous instance of the malware. |
| MalwareGrimAgent | GrimAgent can delete previously created tasks on a compromised host. |
| MalwareIPsec Helper | IPsec Helper can delete various service traces related to persistent execution when commanded. |
| MalwareKapeka | Kapeka will clear registry values used for persistent configuration storage when uninstalled. |
| MalwareKOCTOPUS | KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure. |
| ToolMCMD | MCMD has the ability to remove set Registry Keys, including those used for persistence. |
| MalwareMisdat | Misdat is capable of deleting Registry keys used for persistence. |
| MalwarenjRAT | njRAT is capable of manipulating and deleting registry keys, including those used for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.