1200KM / simulation
T1564.003 Hidden Window — Attack Simulation
Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks. Adversaries may abuse these functionalities to hide otherwise visible windows from users so as not to alert…
Technique description
Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks. Adversaries may abuse these functionalities to hide otherwise visible windows from users so as not to alert…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Headless Browser Accessing Mockbin
Procedure 0ad9ab92-c48c-4f08-9b20-9633277c4646; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Hidden Window-Conhost Execution
Procedure 5510d22f-2595-4911-8456-4d630c978616; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Hidden Window
Procedure f151ee37-9e2b-47e6-80e4-550b9f999b7a; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Deep Panda · G0009
- APT3 · G0022
- FIN7 · G0046
- Gamaredon Group · G0047
- APT32 · G0050
- CopyKittens · G0052
- Magic Hound · G0059
- APT19 · G0073
- Gorgon Group · G0078
- DarkHydrus · G0079
- Kimsuky · G0094
- APT-C-36 · G0099
- Higaisa · G0126
- Nomadic Octopus · G0133
- ToddyCat · G1022
- Medusa Group · G1051
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.