FORENSIA

ATT&CK · T1564.003 · sub-technique

Hidden Window

Tactics: stealth

About

Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks. Adversaries may abuse these functionalities to hide otherwise visible windows from users so as not to alert the user to adversary activity on the system. On macOS, the configurations for how applications run are listed in property list (plist) files. One of the tags in these files can be <code>apple.awt.UIElement</code>, which allows for Java applications to prevent the application's icon from appearing in the Dock. A common use for this is when applications run in the system tray, but don't also want to show up in the Dock. Similarly, on Windows there are a variety of features in scripting languages, such as PowerShell, Jscript, and Visual Basic to make windows hidden. One example of this is <code>powershell.exe -WindowStyle Hidden</code>. The Windows Registry can also be edited to hide application windows from the current user. For example, by setting the `WindowPosition` subkey in the `HKEY_CURRENT_USER\Console\%SystemRoot%_System32_WindowsPowerShell_v1.0_PowerShell.exe` Registry key to a maximum value, PowerShell windows will open off screen and be hidden. In addition, Windows supports the `CreateDesktop()` API that can create a hidden desktop window with its own corresponding <code>explorer.exe</code> process. All applications running on the hidden desktop window, such as a hidden VNC (hVNC) session, will be invisible to other desktops windows. Adversaries may also leverage cmd.exe as a parent process, and then utilize a LOLBin, such as DeviceCredentialDeployment.exe, to hide windows.

Platforms: Linux, macOS, WindowsParent: T1564 Hide ArtifactsMITRE ATT&CK ↗

Used by actors

18 known groups

Software

43 malware/tools implement this

PlugXHAMMERTOSSKoadicInvisiMoleQuasarRATTrickBotAgent TeslaRemcosBONDUPDATERAstarothUrsnifKeyBoyHotCroissantKivarsPowerShowerMetamorfoWindTailStrongPityMCMDCubaKOCTOPUSWarzoneRATQuietSieveMeteorSILENTTRINITYKevinAvosLockerQUIETCANARYSnip3AsyncRATSharpDiscoIMAPLoaderOilBoosterLockBit 2.0Lumma StealerBOOKWORMCANONSTAGERMedusa RansomwareInvisibleFerretSystemBCGlassWormPureCrypterTsundere Botnet

Corpus indicators tagged with this technique

186 indicators in the corpus carry T1564.003.

IndicatorTypeFamilySevSrc
a628ad47fe93ee7413cca90aeca8f9540bfcd5ccdbeb4d9914670b3ef66247f4sha256cryptojacking802
938054c6bb7dc737fce16513b2882808f199c2f892f808d439525a1650d49089sha256cryptojacking802
969b0bfd605aa2cddf353f3638b0dee26b1c2305600231e055fa6d7786a879fesha256cryptojacking802
47854deb456cb08c651b7f9ae2f9d87c72d0719de6af233340632efb3c1980f4sha256phishing801
45126b353f1636103da356121cd00b229b635b41b99d91166e6d7d9037482242sha256cryptojacking802
810614290bdb14d2ddf10f65f8adc988a8272764f2a9e2c378e52fad162da344sha256cryptojacking802
f57e010541fb4ccbf23aefc4a827f753a6ff3f8792d9c04c3eea83f6963c6baesha256phishing801
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ahash802
78945c844fc23dd3446cf17987edeeb6cc21986820c92df82a126af24a5a38d1hash802
f6e4b09ef788adef3f65fd2b99da8f5be5391be29471676dc07040a56c8fdfabhash802
ec1cac2ada6726623b4bafb94c204c359ce7cdf5325909137fc0e6aef506783fsha256cryptojacking802
235a64e3520b1c2c27763122b303f78aee8d7c083dfd9f1eb936cd5174383609sha256cryptojacking802
86819efe7319b664920ba2e1fd4b079a4e6b5eaaebeeb1adb2c1c8dc3c81ee0csha256cryptojacking802
4ce45e016a304d813e67b29a08265b2101c2e15a09ace5de6539cad02567affesha256supply_chain801
d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384hash802
09c121225fe254676a27c21943506714hashphishing802
3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5dhash802
6a69ea2ce3fea0ebfd7a32a1dfc4251bd4d7d8a4fbd44aaa47b82290d0414a9fhash802
d89bb4b23a67814ef511e4e9dda7ad36fa519a322fa7c25ea451c7dd7ef61e54hash802
7b7981c99d59595fe15377df84695bb72ce0b85560a3935f930657b2d162e5efsha256phishing801
adcd15f3d6b87f84d106ea426fa824fd20c9d64f6d199ce92580884290785f30sha256phishing801
d7d2f0ee187549f3f4a114d716be12521fbf62d6d26e2ac23d2a32d521d08fd8sha256phishing801
33760b2aa86deea5805e647197c34ef5hashphishing802
3a87cab1e8c6868a7939eb422f1851ecc746405cda6b3d3502b9d8eedc360898hashphishing802
9abebe5a34eefb80db12bf8d51bfe7f7hashphishing802
e576a61e1a2ba71e764647bb2f0883c2f8fa4d591799c60d21a84230ee7a5b63sha256cryptojacking802
5f7bb80bf85c1fae7413eb534cc2f022402c8753f75666525adb1dc85a677f4chashphishing802
129de16fe69763f767d8249279a2c4a1a6deafadd1a84563bd84b258ea010bffsha256cryptojacking802
308351124c496d4f4effee65ab828506abf70385773c167ab1f32a7f030385achash802
a2e7989742c6b6436ebb47507881946e4f662080dff71d104eb9a9554f38af7asha256cryptojacking802

Showing the top 30 by severity of 186.