Skip to content

T1070.006 Timestomp

Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files.

In Windows systems, both the $STANDARD_INFORMATION ($SI) and $FILE_NAME ($FN) attributes record times in a Master File Table (MFT) file.4 $SI (dates/time stamps) is displayed to the end user, including in the File System view, while $FN is dealt with by the kernel.5

Modifying the $SI attribute is the most common method of timestomping because it can be modified at the user level using API calls. $FN timestomping, however, typically requires interacting with the system kernel or moving or renaming a file.4

Adversaries modify timestamps on files so that they do not appear conspicuous to forensic investigators or file analysis tools. In order to evade detections that rely on identifying discrepancies between the $SI and $FN attributes, adversaries may also engage in “double timestomping” by modifying times on both attributes simultaneously.6

In Linux systems and on ESXi servers, threat actors may attempt to perform timestomping using commands such as touch -a -m -t <timestamp> <filename> (which sets access and modification times to a specific value) or touch -r <filename> <filename> (which sets access and modification times to match those of another file).31

Timestomping may be used along with file name Masquerading to hide malware and tools.2

Item Value
ID T1070.006
Sub-techniques T1070.001, T1070.002, T1070.003, T1070.004, T1070.005, T1070.006, T1070.007, T1070.008, T1070.009, T1070.010
Tactics TA0005
Platforms ESXi, Linux, Windows, macOS
Version 1.2
Created 31 January 2020
Last Modified 24 October 2025

Procedure Examples

ID Name Description
S0066 3PARA RAT 3PARA RAT has a command to set certain attributes such as creation/modification timestamps on files.45
G0007 APT28 APT28 has performed timestomping on victim files.55
G0016 APT29 APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory.63
G0050 APT32 APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID.596061
G0082 APT38 APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.58
G1023 APT5 APT5 has modified file timestamps.56
S0438 Attor Attor has manipulated the time of last access to files and registry keys after they have been created or modified.36
S0239 Bankshot Bankshot modifies the time of a file as specified by the control server.12
S0570 BitPaymer BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool.18
S1181 BlackByte 2.0 Ransomware BlackByte 2.0 Ransomware can timestomp files for defense evasion and anti-forensics purposes.14
S0520 BLINDINGCAN BLINDINGCAN has modified file and directory timestamps.3031
S1226 BOOKWORM BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created. 51
S1161 BPFDoor BPFDoor uses the utimes() function to change the executable’s timestamp.33
C0032 C0032 During the C0032 campaign, TEMP.Veles used timestomping to modify the $STANDARD_INFORMATION attribute on tools.73
G0114 Chimera Chimera has used a Windows version of the Linux touch command to modify the date and time stamp on DLLs.64
S1149 CHIMNEYSWEEP CHIMNEYSWEEP can time stomp its executable, previously dating it between 2010 to 2021.49
S0020 China Chopper China Chopper’s server component can change the timestamp of files.373839
S0154 Cobalt Strike Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in.2122
C0029 Cutting Edge During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity.7170
S0687 Cyclops Blink Cyclops Blink has the ability to use the Linux API function utime to change the timestamps of modified firmware update images.9
S0021 Derusbi The Derusbi malware supports timestomping.2019
S0081 Elise Elise performs timestomping of a CAB file it creates.27
S0363 Empire Empire can timestomp any files or payloads placed on a target machine to help them blend in.7
S0568 EVILNUM EVILNUM has changed the creation date of files.29
S0181 FALLCHILL FALLCHILL can modify file or directory timestamps.13
S0168 Gazer For early Gazer versions, the compilation timestamp was faked.10
S0666 Gelsemium Gelsemium has the ability to perform timestomping of files on targeted systems.42
S0260 InvisiMole InvisiMole samples were timestomped by the authors by setting the PE timestamps to all zero values. InvisiMole also has a built-in command to modify file times.41
S0387 KeyBoy KeyBoy time-stomped its DLL in order to evade detection.28
G0094 Kimsuky Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics.62
S0641 Kobalos Kobalos can modify timestamps of replaced files, such as ssh with the added credential stealer or sshd used to deploy Kobalos.34
G0032 Lazarus Group Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files.67656668
S1016 MacMa MacMa has the capability to create and modify file timestamps.32
S1059 metaMain metaMain can change the CreationTime, LastAccessTime, and LastWriteTime file time attributes when executed with SYSTEM privileges.54
S0083 Misdat Many Misdat samples were programmed using Borland Delphi, which will mangle the default PE compile timestamp of a file.52
S1135 MultiLayer Wiper MultiLayer Wiper changes timestamps of overwritten files to either 1601.1.1 for NTFS filesystems, or 1980.1.1 for all other filesystems.48
G0129 Mustang Panda Mustang Panda has modified file timestamps from the export address table (EAT) in malware to make it difficult to identify creation times.51
S1090 NightClub NightClub can modify the Creation, Access, and Write timestamps for malicious DLLs to match those of the genuine Windows DLL user32.dll.16
S1100 Ninja Ninja can change or create the last access or write times.50
S0352 OSX_OCEANLOTUS.D OSX_OCEANLOTUS.D can use the touch -t command to change timestamps.2324
S0072 OwaAuth OwaAuth has a command to timestop a file or directory.15
S1031 PingPull PingPull has the ability to timestomp a file.35
S0150 POSHSPY POSHSPY modifies timestamps of all downloaded executables to match a randomly selected file created prior to 2013.46
S0393 PowerStallion PowerStallion modifies the MAC times of its local log files to match that of the victim’s desktop.ini file.25
S0078 Psylo Psylo has a command to conduct timestomping by setting a specified file’s timestamps to match those of a system file in the System32 directory.47
G0106 Rocke Rocke has changed the time stamp of certain files.69
S0185 SEASHARPEE SEASHARPEE can timestomp files on victims using a Web shell.26
S0140 Shamoon Shamoon can change the modified time for files to evade forensic detection.53
C0024 SolarWinds Compromise During the SolarWinds Compromise, APT29 modified timestamps of backdoors to match legitimate Windows files.72
S0603 Stuxnet Stuxnet extracts and writes driver files that match the times of other legitimate files.11
S0586 TAINTEDSCRIBE TAINTEDSCRIBE can change the timestamp of specified filenames.8
S0164 TDTESS After creating a new service for persistence, TDTESS sets the file creation time for the service to the creation time of the victim’s legitimate svchost.exe file.44
G1048 UNC3886 UNC3886 has used scripts to timestomp ESXi hosts prior to installing malicious vSphere Installation Bundles (VIBs).57
S1164 UPSTYLE UPSTYLE restores timestamps to original values following modification.40
S0136 USBStealer USBStealer sets the timestamps of its dropper files to the last-access and last-write timestamps of a standard Windows library chosen on the system.17
S0141 Winnti for Windows Winnti for Windows can set the timestamps for its worker and service components to match that of cmd.exe.43

References


  1. Asher Langton. (2022, December 9). A Custom Python Backdoor for VMWare ESXi Servers. Retrieved March 26, 2025. 

  2. Carvey, H. (2013, July 23). HowTo: Determine/Detect the use of Anti-Forensics Techniques. Retrieved June 3, 2016. 

  3. inversecos. (2022, August 4). Detecting Linux Anti-Forensics: Timestomping. Retrieved March 26, 2025. 

  4. Lina Lau. (2022, April 28). Defence Evasion Technique: Timestomping Detection – NTFS Forensics. Retrieved September 30, 2024. 

  5. Magnet Forensics. (2020, August 24). Expose Evidence of Timestomping with the NTFS Timestamp Mismatch Artifact. Retrieved June 20, 2024. 

  6. Matthew Dunwoody. (2022, April 28). I have seen double-timestomping ITW, including by APT29. Stay sharp out there.. Retrieved June 20, 2024. 

  7. Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016. 

  8. USG. (2020, May 12). MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE. Retrieved March 5, 2021. 

  9. ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017. 

  10. Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024. 

  11. Sherstobitoff, R. (2018, March 08). Hidden Cobra Targets Turkish Financial Sector With New Bankshot Implant. Retrieved May 18, 2018. 

  12. US-CERT. (2017, November 22). Alert (TA17-318A): HIDDEN COBRA – North Korean Remote Administration Tool: FALLCHILL. Retrieved December 7, 2017. 

  13. Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024. 

  14. Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018. 

  15. Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023. 

  16. Calvet, J. (2014, November 11). Sednit Espionage Group Attacking Air-Gapped Networks. Retrieved January 4, 2017. 

  17. Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021. 

  18. Fidelis Cybersecurity. (2016, February 29). The Turbo Campaign, Featuring Derusbi for 64-bit Linux. Retrieved March 2, 2016. 

  19. Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014. 

  20. Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017. 

  21. Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021. 

  22. Magisa, L. (2020, November 27). New MacOS Backdoor Connected to OceanLotus Surfaces. Retrieved December 2, 2020. 

  23. Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021. 

  24. Faou, M. and Dumont R.. (2019, May 29). A dive into Turla PowerShell usage. Retrieved June 14, 2019. 

  25. Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017. 

  26. Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016. 

  27. Parys, B. (2017, February 11). The KeyBoys are back in town. Retrieved June 13, 2019. 

  28. Adamitis, D. (2020, May 6). Phantom in the Command Shell. Retrieved November 17, 2024. 

  29. US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020. 

  30. NHS Digital . (2020, August 20). BLINDINGCAN Remote Access Trojan. Retrieved August 20, 2020. 

  31. M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022. 

  32. The Sandfly Security Team. (2022, May 11). BPFDoor - An Evasive Linux Backdoor Technical Analysis. Retrieved September 29, 2023. 

  33. M.Leveille, M., Sanmillan, I. (2021, January). A WILD KOBALOS APPEARS Tricksy Linux malware goes after HPCs. Retrieved August 24, 2021. 

  34. Unit 42. (2022, June 13). GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool. Retrieved August 7, 2022. 

  35. Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020. 

  36. FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018. 

  37. Lee, T., Hanzlik, D., Ahl, I. (2013, August 7). Breaking Down the China Chopper Web Shell - Part I. Retrieved March 27, 2015. 

  38. The Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), CERT New Zealand, the UK National Cyber Security Centre (UK NCSC) and the US National Cybersecurity and Communications Integration Center (NCCIC). (2018, October 11). Joint report on publicly available hacking tools. Retrieved March 11, 2019. 

  39. Volexity Threat Research. (2024, April 12). Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400). Retrieved November 20, 2024. 

  40. Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018. 

  41. Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021. 

  42. Novetta Threat Research Group. (2015, April 7). Winnti Analysis. Retrieved February 8, 2017. 

  43. ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017. 

  44. Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016. 

  45. Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017. 

  46. Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016. 

  47. Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024. 

  48. Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024. 

  49. Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024. 

  50. Robert Falcone. (2025, February 20). Stately Taurus Activity in Southeast Asia Links to Bookworm Malware. Retrieved July 21, 2025. 

  51. Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021. 

  52. Mundo, A., Roccia, T., Saavedra-Morales, J., Beek, C.. (2018, December 14). Shamoon Returns to Wipe Systems in Middle East, Europe . Retrieved May 29, 2020. 

  53. SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023. 

  54. Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016. 

  55. Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024. 

  56. Alexander Marvi, Brad Slaybaugh, Ron Craft, and Rufus Brown. (2023, June 13). VMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors. Retrieved March 26, 2025. 

  57. DHS/CISA. (2020, August 26). FASTCash 2.0: North Korea’s BeagleBoyz Robbing Banks. Retrieved September 29, 2021. 

  58. Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017. 

  59. Dumont, R. (2019, March 20). Fake or Fake: Keeping up with OceanLotus decoys. Retrieved April 1, 2019. 

  60. Dumont, R.. (2019, April 9). OceanLotus: macOS malware update. Retrieved April 15, 2019. 

  61. Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020. 

  62. Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023. 

  63. Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024. 

  64. Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Destructive Malware Report. Retrieved November 17, 2024. 

  65. Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Loaders, Installers and Uninstallers Report. Retrieved November 17, 2024. 

  66. Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016. 

  67. Sherstobitoff, R., Malhotra, A. (2018, April 24). Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide. Retrieved May 16, 2018. 

  68. Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019. 

  69. Lin, M. et al. (2024, February 27). Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts. Retrieved March 1, 2024. 

  70. Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024. 

  71. MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021. 

  72. Miller, S, et al. (2019, April 10). TRITON Actor TTP Profile, Custom Attack Tools, Detections, and ATT&CK Mapping. Retrieved April 16, 2019.