Indicator Removal on Host: File Deletion

Adversaries may wipe a device or delete individual files in order to manipulate external outcomes or hide activity. An application must have administrator access to fully wipe the device, while individual files may not require special permissions to delete depending on their storage location.[1]

Stored data could include a variety of file formats, such as Office files, databases, stored emails, and custom file formats. The impact file deletion will have depends on the type of data as well as the goals and objectives of the adversary, but can include deleting update files to evade detection or deleting attacker-specified files for impact.

ID: T1630.002
Sub-technique of:  T1630
Tactic Type: Post-Adversary Device Access
Tactic: Defense Evasion
Platforms: Android
Version: 1.1
Created: 30 March 2022
Last Modified: 20 March 2023

Procedure Examples

ID Name Description
S0440 Agent Smith

Agent Smith deletes infected applications’ update packages when they are detected on the system, preventing updates.[2]

S0529 CarbonSteal

CarbonSteal has deleted call log entries coming from known C2 sources.[3]

S0505 Desert Scorpion

Desert Scorpion can delete copies of itself if additional APKs are downloaded to external storage.[4]

S0550 DoubleAgent

DoubleAgent has deleted or renamed specific files.[3]

S1080 Fakecalls

Fakecalls can manipulate a device’s call log, including deleting incoming calls.[5]

S0408 FlexiSpy

FlexiSpy can delete data from a compromised device.[6]

S0421 GolfSpy

GolfSpy can delete arbitrary files on the device.[7]

S0536 GPlayed

GPlayed can wipe the device.[8]

S1077 Hornbill

Hornbill can delete locally gathered files after uploading them to the C2 to avoid suspicion.[9]

S0485 Mandrake

Mandrake can delete all data from an infected device.[10]

S0407 Monokle

Monokle can delete arbitrary files on the device, and can also uninstall itself and clean up staging files.[11]

S0399 Pallas

Pallas has the ability to delete attacker-specified files from compromised devices.[12]

S0549 SilkBean

SilkBean can delete various piece of device data, such as contacts, call logs, applications, SMS messages, email, plugins, and files in external storage.[3]

S0558 Tiktok Pro

Tiktok Pro can delete attacker-specified files.[13]

S0418 ViceLeaker

ViceLeaker can delete arbitrary files from the device.[14]

S0489 WolfRAT

WolfRAT can delete files from the device.[15]

Mitigations

ID Mitigation Description
M1011 User Guidance

Users should be trained on what device administrator permission request prompts look like, and how to avoid granting permissions on phishing popups.

Detection

ID Data Source Data Component Detects
DS0041 Application Vetting Permissions Requests

Mobile security products can detect which applications can request device administrator permissions. Application vetting services could be extra scrutinous of applications that request device administrator permissions.

DS0042 User Interface System Settings

The user can view applications with administrator access through the device settings, and may also notice if user data is inexplicably missing.

References