Hidden Window

T1564.003

Sub-technique of T1564 Hide Artifacts.View on attack.mitre.org

About this technique

Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks.

Adversaries may abuse these functionalities to hide otherwise visible windows from users so as not to alert the user to adversary activity on the system.

On macOS, the configurations for how applications run are listed in property list (plist) files. One of the tags in these files can be apple.awt.UIElement, which allows for Java applications to prevent the application's icon from appearing in the Dock. A common use for this is when applications run in the system tray, but don't also want to show up in the Dock.

Similarly, on Windows there are a variety of features in scripting languages, such as PowerShell, Jscript, and Visual Basic to make windows hidden. One example of this is powershell.exe -WindowStyle Hidden.

The Windows Registry can also be edited to hide application windows from the current user. For example, by setting the `WindowPosition` subkey in the `HKEY_CURRENT_USER\Console\%SystemRoot%_System32_WindowsPowerShell_v1.0_PowerShell.exe` Registry key to a maximum value, PowerShell windows will open off screen and be hidden.

In addition, Windows supports the `CreateDesktop()` API that can create a hidden desktop window with its own corresponding explorer.exe process. All applications running on the hidden desktop window, such as a hidden VNC (hVNC) session, will be invisible to other desktops windows.

Adversaries may also leverage cmd.exe as a parent process, and then utilize a LOLBin, such as DeviceCredentialDeployment.exe, to hide windows.

Detection rules11

Rules on DetectionCode tagged with T1564.003.

Sigma8

RuleLevelLog source
File Download with Headless Browserhighwindows / process_creation
HackTool - Covenant PowerShell Launcherhighwindows / process_creation
Potential Data Stealing Via Chromium Headless Debugginghighwindows / process_creation
Cmd Launched with Hidden Start Flags to Suspicious Targetsmediumwindows / process_creation
Powershell Executed From Headless ConHost Processmediumwindows / process_creation
PUA - AdvancedRun Executionmediumwindows / process_creation
Suspicious PowerShell WindowStyle Optionmediumwindows / ps_script
Browser Execution In Headless Modelowwindows / process_creation

Splunk3

RuleTypeRiskData source
Headless Browser Mockbin or Mocky RequestTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Headless Browser UsageAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows ConHost with Headless ArgumentTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups18

Software43

Show 19 more

Campaigns0

None recorded.

Procedure examples61

Groups18

Used byProcedure example
GroupAPT-C-36

APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution.

GroupAPT19

APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

GroupAPT28

APT28 has used the WindowStyle parameter to conceal PowerShell windows.

GroupAPT3

APT3 has been known to use -WindowStyle Hidden to conceal PowerShell windows.

GroupAPT32

APT32 has used the WindowStyle parameter to conceal PowerShell windows.

GroupCopyKittens

CopyKittens has used -w hidden and -windowstyle hidden to conceal PowerShell windows.

GroupDarkHydrus

DarkHydrus has used -WindowStyle Hidden to conceal PowerShell windows.

GroupDeep Panda

Deep Panda has used -w hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

View all 18 groups examples

Software43

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has used ProcessWindowStyle.Hidden to hide windows.

MalwareAstaroth

Astaroth loads its module with the XSL script parameter vShow set to zero, which opens the application with a hidden window.

ToolAsyncRAT

AsyncRAT can hide the execution of scheduled tasks using `ProcessWindowStyle.Hidden`.

MalwareAvosLocker

AvosLocker has hidden its console window by using the `ShowWindow` API function.

MalwareBONDUPDATER

BONDUPDATER uses -windowstyle hidden to conceal a PowerShell window that downloads a payload.

MalwareBOOKWORM

BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module.

MalwareCANONSTAGER

CANONSTAGER has created a new window with a height and width of zero to remain hidden on the screen.

MalwareCuba

Cuba has executed hidden PowerShell windows.

View all 43 software examples

References8

  1. Anatomy of an hVNC Attack Open source
    Keshet, Lior. Kessem, Limor. (2017, January 25). Anatomy of an hVNC Attack. Retrieved November 28, 2023.
  2. Antiquated Mac Malware Open source
    Thomas Reed. (2017, January 18). New Mac backdoor using antiquated code. Retrieved July 5, 2017.
  3. Cantoris Computing Open source
    Cantoris. (2016, July 22). PowerShell Malware. Retrieved December 12, 2024.
  4. Cybereason - Hidden Malicious Remote Access Open source
    Cybereason Security Services Team. (n.d.). Behind Closed Doors: The Rise of Hidden Malicious Remote Access. Retrieved July 22, 2025.
  5. Hidden VNC Open source
    Hutchins, Marcus. (2015, September 13). Hidden VNC for Beginners. Retrieved November 28, 2023.
  6. LOLBAS Project GitHub Device Cred Dep Open source
    Elliot Killick. (n.d.). /DeviceCredentialDeployment.exe. Retrieved July 22, 2025.
  7. PowerShell About 2019 Open source
    Wheeler, S. et al.. (2019, May 1). About PowerShell.exe. Retrieved October 11, 2019.
  8. SecureList BlueNoroff Device Cred Dev Open source
    Seongsu Park. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved July 22, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.