# T1564.004 NTFS File Attributes

> As of 2026-10-05, T1564.004 (NTFS File Attributes) appears in 11 tracked threats, first reported 2026-02-27 and most recently 2026-08-29, with linked actors including TA578 - G1038, APT43, Kimsuky; it most often appears alongside T1059.003 (Windows Command Shell).

- **Tracked threats:** 11 (1 critical, 8 high, 2 medium)
- **First seen:** 2026-02-27
- **Last seen:** 2026-08-29
- **Threat actors:** 6
- **Detection rules:** 34 (counts only; Blue tier and above)

## Key facts

- **ID:** T1564.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1564
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1564/004/

## Activity timeline

T1564.004 first appeared in tracked threats on 2026-02-27 and was most recently reported on 2026-08-29. The busiest month was 2026-07 with 5 reports, and 11 of the 11 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T1564.004 NTFS File Attributes is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1564 Hide Artifacts](https://intel.threadlinqs.com/technique/T1564). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 1 critical, 8 high, 2 medium.

Threats that use T1564.004 most often also use [T1059.003 Windows Command Shell](https://intel.threadlinqs.com/technique/T1059.003) (10 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (9 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (9 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (9 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1564.004; the most frequent are [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) (2), [APT43](https://intel.threadlinqs.com/actor/APT43) (1), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) (1), [LenAI](https://intel.threadlinqs.com/actor/LenAI) (1), [Periwinkle Tempest](https://intel.threadlinqs.com/actor/Periwinkle%20Tempest) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1564.004.

- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)

## Data sources

Telemetry that can reveal T1564.004, per MITRE ATT&CK.

- Command — Command Execution
- File — File Metadata, File Modification
- Process — OS API Execution, Process Creation

## Threat actors using it

- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 2
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [LenAI](https://intel.threadlinqs.com/actor/LenAI) — 1
- [Periwinkle Tempest](https://intel.threadlinqs.com/actor/Periwinkle%20Tempest) — 1
- [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) — 1

## Tracked threats

11 tracked threats use T1564.004.

- [ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked…](https://intel.threadlinqs.com/threat/TL-2026-2199) — high — 2026-08-29
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)](https://intel.threadlinqs.com/threat/TL-2026-1651) — high — 2026-07-23
- [Fake Game Downloads Deliver Amatera Stealer via Ren'Py Loader, MSBuild Abuse, and EtherHiding C2](https://intel.threadlinqs.com/threat/TL-2026-1569) — high — 2026-07-20
- [Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…](https://intel.threadlinqs.com/threat/TL-2026-1486) — medium — 2026-07-18
- [Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo\[.\]org…](https://intel.threadlinqs.com/threat/TL-2026-1483) — high — 2026-07-18
- [GhostTree / GhostBranch: Recursive NTFS Directory Junctions Abused to Evade Recursive File Scanners and Hide…](https://intel.threadlinqs.com/threat/TL-2026-0821) — medium — 2026-06-16
- [Kimsuky (Velvet Chollima) PebbleDash Cluster — HelloDoor, httpMalice, httpTroy/MemLoad & VS Code Remote…](https://intel.threadlinqs.com/threat/TL-2026-0626) — high — 2026-05-29
- [Operation GriefLure — China-Nexus APT Spear-Phishing Targeting Viettel (Vietnam Military Telecom) and St.…](https://intel.threadlinqs.com/threat/TL-2026-0476) — high — 2026-05-07
- [AI Supply Chain Abuse — 575 Trojanized OpenClaw/ClawHub Skills + Hugging Face Malware Staging (Acronis TRU)](https://intel.threadlinqs.com/threat/TL-2026-0447) — high — 2026-05-01
- [Aeternum C2 Botnet — Polygon Blockchain Smart Contract C2, Takedown-Resistant Infrastructure, LenAI MaaS](https://intel.threadlinqs.com/threat/TL-2026-0151) — critical — 2026-02-27

## Detection coverage

Threadlinqs maintains 34 detection rules mapped to T1564.004 (SPL 10, KQL 12, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.

34 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1564 Hide Artifacts](https://intel.threadlinqs.com/technique/T1564) — 174 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1564.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
