# T1564 Hide Artifacts

> As of 2026-10-05, T1564 (Hide Artifacts) appears in 174 tracked threats, first reported 2021-11-25 and most recently 2026-09-25, with linked actors including Contagious Interview, APT38, Lazarus Group; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 174 (45 critical, 120 high, 9 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-09-25
- **Threat actors:** 92
- **Detection rules:** 124 (counts only; Blue tier and above)

## Key facts

- **ID:** T1564
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1564/

## Activity timeline

T1564 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-09-25. The busiest month was 2026-06 with 56 reports, and 173 of the 174 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1564 Hide Artifacts is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 174 of 2623 tracked threats (6.6%) to it; by severity that is 45 critical, 120 high, 9 medium.

Threats that use T1564 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (126 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (124 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (112 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (111 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (109 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

92 tracked threat actors appear in the threats that use T1564; the most frequent are [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (6), [APT38](https://intel.threadlinqs.com/actor/APT38) (4), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (4), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (4), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (4).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1564.

- [M1013 Application Developer Guidance](https://attack.mitre.org/mitigations/M1013/)
- [M1033 Limit Software Installation](https://attack.mitre.org/mitigations/M1033/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)

## Data sources

Telemetry that can reveal T1564, per MITRE ATT&CK.

- Application Log — Application Log Content
- Command — Command Execution
- File — File Creation, File Metadata, File Modification
- Firmware — Firmware Modification
- Process — OS API Execution, Process Creation
- Script — Script Execution
- Service — Service Creation
- User Account — User Account Creation, User Account Metadata
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 6
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 4
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 4
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 4
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 4
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 3
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 3
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 3
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 3
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [BlackSuit affiliate](https://intel.threadlinqs.com/actor/BlackSuit%20affiliate) — 2

## Tracked threats

The 30 most recent of 174 tracked threats that use T1564.

- [Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…](https://intel.threadlinqs.com/threat/TL-2026-2647) — high — 2026-09-25
- [Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Install](https://intel.threadlinqs.com/threat/TL-2026-2597) — critical — 2026-09-21
- [Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…](https://intel.threadlinqs.com/threat/TL-2026-2573) — critical — 2026-09-18
- [Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Access](https://intel.threadlinqs.com/threat/TL-2026-2453) — high — 2026-09-09
- [StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2356) — critical — 2026-09-06
- [HexMage Magecart Campaign Uses Ethereum Smart Contracts for Resilient Card-Skimmer C2](https://intel.threadlinqs.com/threat/TL-2026-2251) — high — 2026-08-31
- [TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industry](https://intel.threadlinqs.com/threat/TL-2026-2175) — high — 2026-08-28
- [Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform…](https://intel.threadlinqs.com/threat/TL-2026-2089) — critical — 2026-08-20
- [AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…](https://intel.threadlinqs.com/threat/TL-2026-2070) — critical — 2026-08-19
- [SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asia](https://intel.threadlinqs.com/threat/TL-2026-2068) — high — 2026-08-19
- [Picus Blue Report 2026: Security Controls Block Only 37% of Post-Compromise Attacker Actions Despite 69%…](https://intel.threadlinqs.com/threat/TL-2026-1983) — medium — 2026-08-11
- [BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create Rogue Admins](https://intel.threadlinqs.com/threat/TL-2026-1978) — medium — 2026-08-10
- [WordPress Supply Chain Attack via BdThemes Promotional API Feed Poisoning (Element Pack, Prime Slider, and 5…](https://intel.threadlinqs.com/threat/TL-2026-1971) — high — 2026-08-10
- [AI Recommendation Poisoning: Prompt Injection via Deep-Linked 'Ask AI' Buttons Silently Alters LLM Memory](https://intel.threadlinqs.com/threat/TL-2026-1922) — high — 2026-08-06
- [Attackers Compile khunt Toolkit Inside Oracle Database to Escalate SQL Injection to Windows SYSTEM Access](https://intel.threadlinqs.com/threat/TL-2026-1910) — critical — 2026-08-06
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolen](https://intel.threadlinqs.com/threat/TL-2026-1848) — critical — 2026-08-03
- [Fake AI Developer Tool Installers Delivering Infostealer via SEO Poisoning and Typosquatting](https://intel.threadlinqs.com/threat/TL-2026-1845) — high — 2026-08-03
- [N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeover](https://intel.threadlinqs.com/threat/TL-2026-1830) — critical — 2026-08-03
- [Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto…](https://intel.threadlinqs.com/threat/TL-2026-1820) — medium — 2026-08-02
- [North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum…](https://intel.threadlinqs.com/threat/TL-2026-1794) — high — 2026-07-31
- [1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)](https://intel.threadlinqs.com/threat/TL-2026-1791) — medium — 2026-07-31
- [GenieLocker Ransomware: Toy Ghouls (Bearlyfy) Cross-Platform Attacks on Windows, Linux, and ESXi](https://intel.threadlinqs.com/threat/TL-2026-1773) — high — 2026-07-30
- [Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…](https://intel.threadlinqs.com/threat/TL-2026-1766) — critical — 2026-07-30
- [AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Theft](https://intel.threadlinqs.com/threat/TL-2026-1811) — high — 2026-07-29
- [Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004)](https://intel.threadlinqs.com/threat/TL-2026-1767) — critical — 2026-07-29
- [Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…](https://intel.threadlinqs.com/threat/TL-2026-1763) — critical — 2026-07-29
- [Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience](https://intel.threadlinqs.com/threat/TL-2026-1738) — high — 2026-07-28
- [Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…](https://intel.threadlinqs.com/threat/TL-2026-1734) — high — 2026-07-28
- [Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect)](https://intel.threadlinqs.com/threat/TL-2026-1732) — high — 2026-07-27

## Related CVEs

CVEs referenced by the tracked threats that use T1564, most frequent first.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-11882](https://intel.threadlinqs.com/cve/CVE-2017-11882)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2017-8570](https://intel.threadlinqs.com/cve/CVE-2017-8570)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2019-19006](https://intel.threadlinqs.com/cve/CVE-2019-19006)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2022-22948](https://intel.threadlinqs.com/cve/CVE-2022-22948)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-20867](https://intel.threadlinqs.com/cve/CVE-2023-20867)
- [CVE-2023-34048](https://intel.threadlinqs.com/cve/CVE-2023-34048)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-58136](https://intel.threadlinqs.com/cve/CVE-2024-58136)
- [CVE-2025-21590](https://intel.threadlinqs.com/cve/CVE-2025-21590)
- [CVE-2025-32432](https://intel.threadlinqs.com/cve/CVE-2025-32432)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-55183](https://intel.threadlinqs.com/cve/CVE-2025-55183)
- [CVE-2025-55184](https://intel.threadlinqs.com/cve/CVE-2025-55184)
- [CVE-2025-64328](https://intel.threadlinqs.com/cve/CVE-2025-64328)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2025-67779](https://intel.threadlinqs.com/cve/CVE-2025-67779)
- [CVE-2026-10735](https://intel.threadlinqs.com/cve/CVE-2026-10735)

## Detection coverage

Threadlinqs maintains 124 detection rules mapped to T1564 (SPL 32, KQL 45, Sigma 47). Rule content is available to Blue tier accounts and above; this page shows counts only.

124 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1564.001 Hidden Files and Directories](https://intel.threadlinqs.com/technique/T1564.001) — 84 tracked threats
- T1564.002 Hidden Users — 1 tracked threat
- [T1564.003 Hidden Window](https://intel.threadlinqs.com/technique/T1564.003) — 37 tracked threats
- [T1564.004 NTFS File Attributes](https://intel.threadlinqs.com/technique/T1564.004) — 11 tracked threats
- T1564.005 Hidden File System — 0 tracked threats
- T1564.006 Run Virtual Instance — 3 tracked threats
- T1564.007 VBA Stomping — 0 tracked threats
- [T1564.008 Email Hiding Rules](https://intel.threadlinqs.com/technique/T1564.008) — 11 tracked threats
- T1564.009 Resource Forking — 0 tracked threats
- T1564.010 Process Argument Spoofing — 3 tracked threats
- T1564.011 Ignore Process Interrupts — 1 tracked threat
- T1564.012 File/Path Exclusions — 2 tracked threats
- T1564.013 Bind Mounts — 1 tracked threat
- T1564.014 Extended Attributes — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1564
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
