Activity timeline
T1564 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-06 with 56 reports, and 173 of the 174 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1564 Hide Artifacts is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 174 of 2623 tracked threats (6.6%) to it; by severity that is 45 critical, 120 high, 9 medium.
Threats that use T1564 most often also use T1059 Command and Scripting Interpreter (126 threats), T1027 Obfuscated Files or Information (124 threats), T1071 Application Layer Protocol (112 threats), T1082 System Information Discovery (111 threats), T1036 Masquerading (109 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
92 tracked threat actors appear in the threats that use T1564; the most frequent are Contagious Interview (6), APT38 (4), Lazarus Group (4), Stardust Chollima (4), TeamPCP (4).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1564.
Data sources
Telemetry that can reveal T1564, per MITRE ATT&CK.
- Application Log — Application Log Content
- Command — Command Execution
- File — File Creation, File Metadata, File Modification
- Firmware — Firmware Modification
- Process — OS API Execution, Process Creation
- Script — Script Execution
- Service — Service Creation
- User Account — User Account Creation, User Account Metadata
- Windows Registry — Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 174 tracked threats that use T1564.
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Installcritical
- Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…critical
- Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Accesshigh
- StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitationcritical
- HexMage Magecart Campaign Uses Ethereum Smart Contracts for Resilient Card-Skimmer C2high
- TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industryhigh
- Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform…critical
- AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…critical
- SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asiahigh
- Picus Blue Report 2026: Security Controls Block Only 37% of Post-Compromise Attacker Actions Despite 69%…medium
- BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create Rogue Adminsmedium
- WordPress Supply Chain Attack via BdThemes Promotional API Feed Poisoning (Element Pack, Prime Slider, and 5…high
- AI Recommendation Poisoning: Prompt Injection via Deep-Linked 'Ask AI' Buttons Silently Alters LLM Memoryhigh
- Attackers Compile khunt Toolkit Inside Oracle Database to Escalate SQL Injection to Windows SYSTEM Accesscritical
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolencritical
- Fake AI Developer Tool Installers Delivering Infostealer via SEO Poisoning and Typosquattinghigh
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeovercritical
- Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto…medium
- North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum…high
- 1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)medium
- GenieLocker Ransomware: Toy Ghouls (Bearlyfy) Cross-Platform Attacks on Windows, Linux, and ESXihigh
- Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…critical
- AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Thefthigh
- Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004)critical
- Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…critical
- Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resiliencehigh
- Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…high
- Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect)high
Detection coverage
Threadlinqs maintains 124 detection rules mapped to T1564 (SPL 32, KQL 45, Sigma 47). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1564.001 Hidden Files and Directories — 84 tracked threats
- T1564.002 Hidden Users — 1 tracked threat
- T1564.003 Hidden Window — 37 tracked threats
- T1564.004 NTFS File Attributes — 11 tracked threats
- T1564.005 Hidden File System — 0 tracked threats
- T1564.006 Run Virtual Instance — 3 tracked threats
- T1564.007 VBA Stomping — 0 tracked threats
- T1564.008 Email Hiding Rules — 11 tracked threats
- T1564.009 Resource Forking — 0 tracked threats
- T1564.010 Process Argument Spoofing — 3 tracked threats
- T1564.011 Ignore Process Interrupts — 1 tracked threat
- T1564.012 File/Path Exclusions — 2 tracked threats
- T1564.013 Bind Mounts — 1 tracked threat
- T1564.014 Extended Attributes — 0 tracked threats