Trusted Design

T1143 - Hidden Window

概要

Adversaries may implement hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks. Adversaries may abuse operating system functionality to hide otherwise visible windows from users so as not to alert the user to adversary activity on the system.

Windows

There are a variety of features in scripting languages in Windows, such as PowerShell, Jscript, and VBScript to make windows hidden. One example of this is powershell.exe -WindowStyle Hidden. (Citation: PowerShell About 2019)

Mac

The configurations for how applications run on macOS are listed in property list (plist) files. One of the tags in these files can be apple.awt.UIElement, which allows for Java applications to prevent the application's icon from appearing in the Dock. A common use for this is when applications run in the system tray, but don't also want to show up in the Dock. However, adversaries can abuse this feature and hide their running window.(Citation: Antiquated Mac Malware)

管理者によるコメント

MITRE ATT&CKにおいて、T1143は「Hidden Window(非表示ウィンドウ)」として定義されている「防御回避(Defense Evasion)」のテクニックです。

攻撃者がプログラムやスクリプト(cmd.exe、powershell.exe、VBScriptなど)を実行する際、GUIウィンドウ(黒いコマンドプロンプト画面など)を意図的に非表示(非可視)にした状態でバックグラウンド実行させる手法です。

1. 概要(攻撃者は何を実現できるのか?)

この手法で攻撃者は、「ユーザーに画面上の異常(一瞬の黒い画面のチラつき等)を悟られることなく、裏で悪意ある操作を完結させること」を実現します。

2. 攻撃の流れ

Windowsの構造上、プロセス起動時のパラメータやAPI呼び出しオプションで簡単にウィンドウを非表示にできます。

  1. 初期侵入 / トリガーの起動:
    悪意あるマクロ付きOffice文書(VBA)、 malicious LNK ファイル、または既存のスケジュールタスク経由でコードがキックされます。

  2. 非表示フラグを伴うプロセス起動(T1143の発動):
    攻撃者は以下のような手法で非表示属性を指定してプロセスを起動します。

    • PowerShellのオプション指定: powershell.exe -WindowStyle Hidden -ExecutionPolicy Bypass -File C:\Windows\Temp\script.ps1

    -WindowStyle Hidden(または -w h)フラグを指定することで、PowerShell画面を立ち上げずに実行します。

    • VBScript / WScript.Shell の悪用:
      Set objShell = CreateObject("WScript.Shell") objShell.Run "cmd.exe /c C:\Windows\Temp\payload.bat", 0, False

    第二引数の 0 が SW_HIDE(ウィンドウ非表示)を意味します。

    • Win32 APIの呼び出し:
      CreateProcess APIを呼び出す際、STARTUPINFO 構造体の wShowWindow メンバーに SW_HIDE(0)を設定します。
  3. バックグラウンド処理の完結(目的達成):
    ユーザーの画面には何の変化も現れないまま、裏でC2サーバーとの通信や永続化メカニズムの書き込みが完了します。

3. 防御・対策

画面上で見えない場合でも、OSのカーネルレベルではプロセスが確実に生成・実行されているため、プロセスコマンドラインログの監視が最大の防御策になります。

4. Important Points(重要ポイント)

5. 関連する主なCWE

6. 関連する代表的な事例

実務上のアドバイス:
SOCやセキュリティ運用のルール作成において、「powershell.exe + -WindowStyle Hidden(または -w h などの短縮形)」 を含むコマンドラインは、正規の管理スクリプトでも稀に使われますが、初期侵入(Word/Excel/LNK/ブラウザ等からの起動)と組み合わさった場合はほぼ確実に攻撃(Malicious)です。

親プロセスが Explorer.exe 以外(特に Office系、PDF閲覧ソフト、Webブラウザ)である場合に限定して検知ロジック(SIEM / EDRアラート)を組むことで、False Positive(誤検知)を劇的に減らしつつ、高精度で本手法(旧T1143 / 現T1564.003)を捉えることができます。

分析

この攻撃手法を利用する脅威アクター

この攻撃手法を利用する脅威アクターは登録されていません。

関連する CVE

攻撃手法 – 脅威アクター Graph


← Technique一覧に戻る ← Tactics一覧に戻る