FORENSIA

ATT&CK · T1564.002 · sub-technique

Hidden Users

Tactics: stealth

About

Adversaries may use hidden users to hide the presence of user accounts they create or modify. Administrators may want to hide users when there are many user accounts on a given system or if they want to hide their administrative or other management accounts from other users. In macOS, adversaries can create or modify a user to be hidden through manipulating plist files, folder attributes, and user attributes. To prevent a user from being shown on the login screen and in System Preferences, adversaries can set the userID to be under 500 and set the key value <code>Hide500Users</code> to <code>TRUE</code> in the <code>/Library/Preferences/com.apple.loginwindow</code> plist file. Every user has a userID associated with it. When the <code>Hide500Users</code> key value is set to <code>TRUE</code>, users with a userID under 500 do not appear on the login screen and in System Preferences. Using the command line, adversaries can use the <code>dscl</code> utility to create hidden user accounts by setting the <code>IsHidden</code> attribute to <code>1</code>. Adversaries can also hide a user’s home folder by changing the <code>chflags</code> to hidden. Adversaries may similarly hide user accounts in Windows. Adversaries can set the <code>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList</code> Registry key value to <code>0</code> for a specific user to prevent that user from being listed on the logon screen. On Linux systems, adversaries may hide user accounts from the login screen, also referred to as the greeter. The method an adversary may use depends on which Display Manager the distribution is currently using. For example, on an Ubuntu system using the GNOME Display Manger (GDM), accounts may be hidden from the greeter using the <code>gsettings</code> command (ex: <code>sudo -u gdm gsettings set org.gnome.login-screen disable-user-list true</code>). Display Managers are not anchored to specific distributions and may be changed by a user or adversary.

Platforms: Linux, macOS, WindowsParent: T1564 Hide ArtifactsMITRE ATT&CK ↗

Used by actors

2 known groups

Software

1 malware/tools implement this

SMOKEDHAM

Corpus indicators tagged with this technique

41 indicators in the corpus carry T1564.002.

IndicatorTypeFamilySevSrc
cve-2026-3102cve853
42add9475e67a1ccc6a6af94b5475d3defc01b85hash803
535f4337f261b6da20a3c614eb13270bed2d533ahash803
5f1f3689bcf23de1b280b5f35712946da0f7978fhash803
69331cfdac792dc79240e6a6bb6e803eabd70bebhash803
76253fb55aed707440e808ea78e7101318436b1chash803
954722b0c9c678b1313d1f8b204e102842dc5889hash803
9803604ec45f31f9ef75bcca1e1310d8ac1fc3a6hash803
dad26f61da7b8bccc78364411812be74c025b475hash803
edce72f59e4c1d136cd1946af70d334c19df858dhash803
a73cb9d5d46e19f3daa4a14cfe5d8fa4319a3d62452039e4972e6a316bbb26f4sha256802
02819d200d1424882af81cb504b3e8614b32397ahash803
17f8f8f34dfa737f36182fed7ff9e9814a114058hash803
901cfa97b1baaf908fd4a02bb52d970f576c4193hash803
ae4601a19d28332a3ec6ac31b385cdf53be53450hash803
c2d9d48b3b10bd58cdf5df9463e3ffcd60533ff3hash803
d2cb0d7a9ad2b5d4ea7c2da8aec62beb37cf36d6hash803
e05f1767c2a337910ed75e90288838d6d0541164hash803
e815a9b418d09c2d4bcd074c2c0bc21406eeb22fhash803
a4fbd707f4ce7ca68e6137cef1c56b6f408e5f0a0f148434d996bb98c3a21fffsha256802
1405a3c5e0aeb08012484134e16cdec4ab29b4a4hash803
29f1d346a6e71774c7dad25b90f446b2974393dfhash803
2423a5bf0fa7cb9ec09211630a5488629499691bhash803
http://tidio.cc/cdn-cgi/pe-purlsupply_chain752
http://a.opmnstr.com/app/js/api.min.jsurlsupply_chain752
http://a.trstplse.com/app/js/api.min.jsurlsupply_chain752
http://tidio.cc/cdn-cgi/urlsupply_chain752
http://tidio.cc/cdn-cgi/*urlsupply_chain752
http://tidio.cc/cdn-cgi/burlsupply_chain752
http://tidio.cc/cdn-cgi/lurlsupply_chain752

Showing the top 30 by severity of 41.