Compliance Node Overview
MITRE ATT&CK T1070.010 (Relocate Malware) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Once a payload is delivered, adversaries may reproduce copies of the same malware on the victim system to remove evidence of their presence and/or avoid defenses. Copying malware payloads to new locations may also be combined with File Deletion to cleanup older artifacts. Relocating malware may be a part of many actions intended to evade defenses. For example, adversaries may copy and rename payloads to better blend into the local environment (i.e., Match Legitimate Name or Location). Affected platforms: Linux, macOS, Windows, Network. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-16, AC-17, AC-18, CA-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1070/010/
SHA-256 integrity: 54c4b44fbd0af5618bfa3bcf74678b40492191a1a0a5cb9f5784c9b598f3b15a
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1070.010: Relocate Malware (https://attack.mitre.org/techniques/T1070/010/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access