# T1564.003 Hidden Window

> As of 2026-10-05, T1564.003 (Hidden Window) appears in 37 tracked threats, first reported 2026-01-14 and most recently 2026-10-03, with linked actors including APT38, Andariel, Armored Likho; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 37 (2 critical, 32 high, 3 medium)
- **First seen:** 2026-01-14
- **Last seen:** 2026-10-03
- **Threat actors:** 22
- **Detection rules:** 86 (counts only; Blue tier and above)

## Key facts

- **ID:** T1564.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1564
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1564/003/

## Activity timeline

T1564.003 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 13 reports, and 37 of the 37 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1564.003 Hidden Window is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1564 Hide Artifacts](https://intel.threadlinqs.com/technique/T1564). Threadlinqs maps 37 of 2623 tracked threats (1.4%) to it; by severity that is 2 critical, 32 high, 3 medium.

Threats that use T1564.003 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (34 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (27 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (26 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (26 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (26 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

22 tracked threat actors appear in the threats that use T1564.003; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (3), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (2), [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) (2), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1564.003.

- [M1033 Limit Software Installation](https://attack.mitre.org/mitigations/M1033/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)

## Data sources

Telemetry that can reveal T1564.003, per MITRE ATT&CK.

- Command — Command Execution
- File — File Modification
- Process — Process Creation
- Script — Script Execution
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) — 2
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 1
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 1
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 1
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1

## Tracked threats

The 30 most recent of 37 tracked threats that use T1564.003.

- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation](https://intel.threadlinqs.com/threat/TL-2026-2250) — high — 2026-08-31
- [APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiye](https://intel.threadlinqs.com/threat/TL-2026-2213) — high — 2026-08-29
- [Dissection of a PHP Backdoor Leveraging php-win.exe for Stealthy Windows Persistence](https://intel.threadlinqs.com/threat/TL-2026-2149) — medium — 2026-08-26
- [Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi](https://intel.threadlinqs.com/threat/TL-2026-2056) — high — 2026-08-18
- [Fake GoogleTranslate Chrome Extension Enables Remote Browser Control and Credential Theft via Rust Loader…](https://intel.threadlinqs.com/threat/TL-2026-1976) — high — 2026-08-10
- [SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1880) — high — 2026-08-04
- [Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1833) — high — 2026-08-03
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [Joyfill npm Packages Compromised with Blockchain C2 Loader](https://intel.threadlinqs.com/threat/TL-2026-1771) — medium — 2026-07-30
- [BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-1719) — high — 2026-07-27
- [Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…](https://intel.threadlinqs.com/threat/TL-2026-1693) — high — 2026-07-25
- [FakeGit Campaign Uses 7,600 GitHub Repositories with AgentBaiting to Spread SmartLoader & StealC Malware](https://intel.threadlinqs.com/threat/TL-2026-1565) — high — 2026-07-20
- [Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAT](https://intel.threadlinqs.com/threat/TL-2026-1552) — high — 2026-07-19
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — high — 2026-07-16
- [SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1227) — high — 2026-07-11
- [Operation Muck and Load: Malicious Go Module (dnsub-scanning-tool) Fronts 222-Repo GitHub Malware Lure…](https://intel.threadlinqs.com/threat/TL-2026-1160) — high — 2026-07-08
- [Armored Likho APT Targets Government and Power Sector with New BusySnake Stealer via CVE-2025-9491 LNK Abuse](https://intel.threadlinqs.com/threat/TL-2026-1108) — high — 2026-07-03
- [Armored Likho APT Deploys BusySnake Python Stealer with PyArmor Obfuscation Against Government and Power…](https://intel.threadlinqs.com/threat/TL-2026-1097) — high — 2026-07-03
- [Remus Stealer: 64-bit Lumma-Derived Infostealer-as-a-Service with EtherHiding Blockchain C2 and…](https://intel.threadlinqs.com/threat/TL-2026-1080) — high — 2026-07-02
- [Edgecution: Payouts King Initial Access Broker Deploys Malicious Microsoft Edge Extension with Embedded…](https://intel.threadlinqs.com/threat/TL-2026-0917) — high — 2026-06-23
- [AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT PowerShell Banking Trojan Targeting Brazilian…](https://intel.threadlinqs.com/threat/TL-2026-0841) — high — 2026-06-17
- [DinDoor Deno-Based RAT — Fake AI/Audio Software on GitHub & SourceForge (ChatGPT/Claude/AutoTune/Kontakt)…](https://intel.threadlinqs.com/threat/TL-2026-0590) — high — 2026-05-26
- [PawsRunner Steganography Loader Delivers Evolved .NET PureLogs Infostealer](https://intel.threadlinqs.com/threat/TL-2026-0521) — high — 2026-05-17
- [Operation HumanitarianBait — PyArmor-Packed Python Surveillance Implant Targeting Russian-Speakers via…](https://intel.threadlinqs.com/threat/TL-2026-0474) — high — 2026-05-07
- [InstallFix Campaign — Fake Claude AI Installer via Google Ads Drops mshta/ZIP-HTA Polyglot, AMSI-Bypass…](https://intel.threadlinqs.com/threat/TL-2026-0463) — high — 2026-05-05
- [Axios npm Supply Chain Compromise — Malicious axios@1.14.1 and axios@0.30.4 Inject plain-crypto-js@4.2.1 RAT…](https://intel.threadlinqs.com/threat/TL-2026-0397) — critical — 2026-04-20
- [Fake Claude AI Download Site Delivers Trojanized Installer Deploying PlugX RAT via G DATA DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-0349) — high — 2026-04-10

## Related CVEs

CVEs referenced by the tracked threats that use T1564.003, most frequent first.

- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)

## Detection coverage

Threadlinqs maintains 86 detection rules mapped to T1564.003 (SPL 34, KQL 28, Sigma 24). Rule content is available to Blue tier accounts and above; this page shows counts only.

86 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1564 Hide Artifacts](https://intel.threadlinqs.com/technique/T1564) — 174 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1564.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
