T1564.001Hidden Files and Directories
T1564.001 — Hidden Files and Directories is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 19 detection use cases covering it and 13 threat-intel articles citing it.
Defense Evasion
19Use cases
13Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1564 · Hide Artifacts
Use cases covering this technique (19)
Disable Show Hidden Files MacOS Hidden Files and Directories Reg exe used to hide files directories via registry keys [LLM] CoolClient sideloader staging: xcopy clones legit Windows Defender folder into fake Microsoft\Windows Defender dir [LLM] Still Sync TReload service persistence + implant CLI flags (--firefly/--console) [LLM] mrmustard persistence artifacts: mmcompat.pth and .tf_cache/hw_probe.pyc [LLM] SleeperGem payload drop: native binary written to hidden ~/.local/share/gcm/ [LLM] Miasma sync.js payload dropped to hidden 'NodeJS' directory [LLM] TuxBot/Akiru known ELF sample execution and drop (SHA256 pivot) [LLM] IronWorm preinstall loader: detached hidden binary executed from OS temp by node.exe [LLM] PHP CLI drops hidden /tmp dropper artefacts (Laravel-Lang autoload payload) [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) [LLM] Hidden .fullgc cryptominer binary written to /ql/data/db/ [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) [LLM] Linux Python RAT orphaned via nohup python3 /tmp/ld.py (Axios npm payload) [LLM] macOS Axios RAT daemon spoof + ad-hoc codesign of hidden /private/tmp binary [LLM] Process execution from masquerade directory C:\$Windows.~SXK (Discord/Roblox stealer)Articles citing this technique (13)
crit APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit art-48