Indicator Removal: Relocate Malware

Once a payload is delivered, adversaries may reproduce copies of the same malware on the victim system to remove evidence of their presence and/or avoid defenses. Copying malware payloads to new locations may also be combined with File Deletion to cleanup older artifacts.

Relocating malware may be a part of many actions intended to evade defenses. For example, adversaries may copy and rename payloads to better blend into the local environment (i.e., Match Legitimate Name or Location).[1] Payloads may also be repositioned to target File/Path Exclusions as well as specific locations associated with establishing Persistence.[2]

Relocating malicious payloads may also hinder defensive analysis, especially to separate these payloads from earlier events (such as User Execution and Phishing) that may have generated alerts or otherwise drawn attention from defenders.

ID: T1070.010
Sub-technique of:  T1070
Tactic: Defense Evasion
Platforms: Linux, Network, Windows, macOS
Contributors: Matt Anderson, @‌nosecurething, Huntress
Version: 1.0
Created: 31 May 2024
Last Modified: 13 October 2024

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.

Detection

ID Data Source Data Component Detects
DS0022 File File Modification

Monitor for changes to files that may highlight malware or otherwise potentially malicious payloads being copied between different file/folder locations on a host.

References