47
Groups Using This
1
Tactics
4
Platforms
14
Prevalence Rank
Description

Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint. There are tools available from the host operating system to perform cleanup, but adversaries may use other tools as well. Examples of built-in Command and Scripting Interpreter functions include del on Windows, rm or unlink on Linux and macOS, and `rm` on ESXi.

View MITRE record โ†—

Platforms
ESXiLinuxmacOSWindows
Groups Using T1070.004 (47)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0032
Lazarus Group
๐Ÿ‡ฐ๐Ÿ‡ต North Korea93 techniques26 software
G0007
APT28
๐Ÿ‡ท๐Ÿ‡บ Russia93 techniques29 software
G0129
Mustang Panda
๐Ÿ‡ท๐Ÿ‡บ Russia85 techniques23 software
G0096
APT41
๐Ÿ‡จ๐Ÿ‡ณ China82 techniques32 software
G1017
Volt Typhoon
๐Ÿ‡จ๐Ÿ‡ณ China81 techniques17 software
G0034
Sandworm Team
๐Ÿ‡ท๐Ÿ‡บ Russia79 techniques27 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0047
Gamaredon Group
๐Ÿ‡ท๐Ÿ‡บ Russia70 techniques6 software
G0016
APT29
๐Ÿ‡ท๐Ÿ‡บ Russia66 techniques49 software
G0102
Wizard Spider
๐Ÿ‡ท๐Ÿ‡บ Russia64 techniques22 software
G0114
Chimera
๐Ÿ‡จ๐Ÿ‡ณ China59 techniques6 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G1051
Medusa Group
57 techniques5 software
G0082
APT38
๐Ÿ‡ฐ๐Ÿ‡ต North Korea56 techniques6 software
G0139
TeamTNT
56 techniques4 software
G0035
Dragonfly
๐Ÿ‡ท๐Ÿ‡บ Russia56 techniques10 software
G1052
Contagious Interview
๐Ÿ‡ฐ๐Ÿ‡ต North Korea54 techniques4 software
G0087
APT39
๐Ÿ‡ฎ๐Ÿ‡ท Iran53 techniques11 software
G1048
UNC3886
๐Ÿ‡จ๐Ÿ‡ณ China49 techniques8 software
G1043
BlackByte
48 techniques8 software
G1003
Ember Bear
๐Ÿ‡ท๐Ÿ‡บ Russia47 techniques11 software
G0045
menuPass
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques25 software
G0022
APT3
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G1054
MirrorFace
๐Ÿ‡จ๐Ÿ‡ณ China43 techniques16 software
G0040
Patchwork
๐Ÿ‡จ๐Ÿ‡ณ China41 techniques8 software
G1039
RedCurl
๐Ÿ‡ท๐Ÿ‡บ Russia41 techniques0 software
G0060
BRONZE BUTLER
๐Ÿ‡จ๐Ÿ‡ณ China40 techniques14 software
G0037
FIN6
40 techniques12 software
G0081
Tropic Trooper
40 techniques6 software
G0061
FIN8
36 techniques11 software
G0106
Rocke
๐Ÿ‡จ๐Ÿ‡ณ China36 techniques0 software
G0143
Aquatic Panda
๐Ÿ‡จ๐Ÿ‡ณ China35 techniques6 software
G0080
Cobalt Group
34 techniques6 software
G1023
APT5
๐Ÿ‡จ๐Ÿ‡ณ China29 techniques13 software
G0091
Silence
๐Ÿ‡ท๐Ÿ‡บ Russia28 techniques3 software
G1040
Play
26 techniques9 software
G1032
INC Ransom
25 techniques8 software
G0026
APT18
12 techniques5 software
G0051
FIN10
11 techniques1 software
G0120
Evilnum
11 techniques3 software
G0053
FIN5
๐Ÿ‡ท๐Ÿ‡บ Russia11 techniques6 software
G1013
Metador
9 techniques2 software
G0089
The White Company
๐Ÿ‡ต๐Ÿ‡ฐ Pakistan7 techniques2 software
G0043
Group5
๐Ÿ‡ฎ๐Ÿ‡ท Iran4 techniques2 software
โ†‘