Skip to content

T1070.009 Clear Persistence

Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity. This may involve various actions, such as removing services, deleting executables, Modify Registry, Plist File Modification, or other methods of cleanup to prevent defenders from collecting evidence of their persistent presence.1 Adversaries may also delete accounts previously created to maintain persistence (i.e. Create Account).2

In some instances, artifacts of persistence may also be removed once an adversary’s persistence is executed in order to prevent errors with the new instance of the malware.3

Item Value
ID T1070.009
Sub-techniques T1070.001, T1070.002, T1070.003, T1070.004, T1070.005, T1070.006, T1070.007, T1070.008, T1070.009, T1070.010
Tactics TA0005
Platforms ESXi, Linux, Windows, macOS
Version 1.2
Created 29 July 2022
Last Modified 16 April 2025

Procedure Examples

ID Name Description
S0534 Bazar Bazar’s loader can delete scheduled tasks created by a previous instance of the malware.3
S0632 GrimAgent GrimAgent can delete previously created tasks on a compromised host.13
S1132 IPsec Helper IPsec Helper can delete various service traces related to persistent execution when commanded.6
S1190 Kapeka Kapeka will clear registry values used for persistent configuration storage when uninstalled.9
S0669 KOCTOPUS KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure.11
S0500 MCMD MCMD has the ability to remove set Registry Keys, including those used for persistence.4
S0083 Misdat Misdat is capable of deleting Registry keys used for persistence.1
S0385 njRAT njRAT is capable of manipulating and deleting registry keys, including those used for persistence.10
S0517 Pillowmint Pillowmint can uninstall the malicious service from an infected machine.8
S0013 PlugX PlugX has deleted registry keys that store data and maintained persistence.7
S1130 Raspberry Robin Raspberry Robin uses a RunOnce Registry key for persistence, where the key is removed after its use on reboot then re-added by the malware after it resumes execution.14
S0148 RTM RTM has the ability to remove Registry entries that it created for persistence.15
S0085 S-Type S-Type has deleted accounts it has created.1
S1232 SplatDropper SplatDropper has deleted its malicious payload and removed its own created service to avoid leaving traces of its presence on victim devices.12
S0559 SUNBURST SUNBURST removed IFEO registry values to clean up traces of persistence.5

Mitigations

ID Mitigation Description
M1029 Remote Data Storage Automatically forward events to a log server or data repository to prevent conditions in which the adversary can locate and manipulate data on the local system. When possible, minimize time delay on event reporting to avoid prolonged storage on the local system.
M1022 Restrict File and Directory Permissions Protect generated event files that are stored locally with proper permissions and authentication and limit opportunities for adversaries to increase privileges by preventing Privilege Escalation opportunities.

References


  1. Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021. 

  2. Nick Biasini. (2022, August 10). Cisco Talos shares insights related to recent cyber attack on Cisco. Retrieved March 9, 2023. 

  3. Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020. 

  4. Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020. 

  5. MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021. 

  6. Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024. 

  7. Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025. 

  8. Trustwave SpiderLabs. (2020, June 22). Pillowmint: FIN7’s Monkey Thief . Retrieved July 27, 2020. 

  9. Mohammad Kazem Hassan Nejad, WithSecure. (2024, April 17). KAPEKA A novel backdoor spotted in Eastern Europe. Retrieved January 6, 2025. 

  10. Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019. 

  11. Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024. 

  12. Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025. 

  13. Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024. 

  14. Microsoft Threat Intelligence. (2022, October 27). Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity. Retrieved May 17, 2024. 

  15. Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.