Skip to content

T1628 Hide Artifacts

Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Mobile operating systems have features and developer APIs to hide various artifacts, such as an application’s launcher icon. These APIs have legitimate usages, such as hiding an icon to avoid application drawer clutter when an application does not have a usable interface. Adversaries may abuse these features and APIs to hide artifacts from the user to evade detection.

Item Value
ID T1628
Sub-techniques T1628.001, T1628.002
Tactics TA0030
Platforms Android
Version 1.1
Created 30 March 2022
Last Modified 20 March 2023

Detection

ID Data Source Data Component
DS0041 Application Vetting API Calls
DS0042 User Interface System Settings