Umbra Wiki attack-pattern attack-pattern/CAPEC-636
Back to wiki

CAPEC-636 — Hiding Malicious Data or Code within Files

provenance: imported · ATT&CK: T1001.002 T1027.003 T1027.004 T1218.001 T1221 · CWE: CWE-506

CAPEC-636: Hiding Malicious Data or Code within Files

MITRE CAPEC attack pattern

Status Draft
Typical severity High
Likelihood of attack
Catalogue CAPEC 3.9 (2023-01-24)

Description

Files on various operating systems can have a complex format which allows for the storage of other data, in addition to its contents. Often this is metadata about the file, such as a cached thumbnail for an image file. Unless utilities are invoked in a particular way, this data is not visible during the normal use of the file. It is possible for an attacker to store malicious data or code using these facilities, which would be difficult to discover.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-506

ATT&CK techniques: T1001.002, T1027.003, T1027.004, T1218.001, T1221

Prerequisites

  • The operating system must support a file system that allows for alternate data storage for a file.

Mitigations

  • Many tools are available to search for the hidden data. Scan regularly for such data using one of these tools.

Source