Real-world descriptions of how a group, tool or campaign used a technique.
73 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareTrickBot | TrickBot leverages a custom packer to obfuscate its functionality. |
| T1027.002 Software Packing |
MalwareBLINDINGCAN | BLINDINGCAN has been packed with the UPX packer. |
| T1027.002 Software Packing |
MalwareSpark | Spark has been packed with Enigma Protector to obfuscate its contents. |
| T1027.002 Software Packing |
MalwareTorisma | Torisma has been packed with Iz4 compression. |
| T1027.002 Software Packing |
Malwareyty | yty packs a plugin with UPX. |
| T1027.002 Software Packing |
MalwareCOATHANGER | The first stage of COATHANGER is delivered as a packed file. |
| T1027.002 Software Packing |
MalwareMisdat | Misdat was typically packed using UPX. |
| T1027.002 Software Packing |
MalwareHeartCrypt | HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection. |
| T1027.002 Software Packing |
MalwareAppleSeed | AppleSeed has used UPX packers for its payload DLL. |
| T1027.002 Software Packing |
MalwareNETWIRE | NETWIRE has used .NET packer tools to evade detection. |
| T1027.002 Software Packing |
MalwareGreyEnergy | GreyEnergy is packed for obfuscation. |
| T1027.002 Software Packing |
MalwareEmotet | Emotet has used custom packers to protect its payloads. |
| T1027.002 Software Packing |
MalwareTomiris | Tomiris has been packed with UPX. |
| T1027.002 Software Packing |
MalwareMachete | Machete has been packed with NSIS. |
| T1027.002 Software Packing |
MalwareSquirrelwaffle | Squirrelwaffle has been packed with a custom packer to hide payloads. |
| T1027.002 Software Packing |
MalwareHildegard | Hildegard has packed ELF files into other binaries. |
| T1027.002 Software Packing |
MalwareFYAnti | FYAnti has used ConfuserEx to pack its .NET module. |
| T1027.002 Software Packing |
MalwareZeroT | Some ZeroT DLL files have been packed with UPX. |
| T1027.002 Software Packing |
MalwareRaspberry Robin | Raspberry Robin contains multiple payloads that are packed for defense evasion purposes and unpacked on runtime. |
| T1027.002 Software Packing |
MalwareRaindrop | Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm. |
| T1027.002 Software Packing |
MalwareIcedID | IcedID has packed and encrypted its loader module. |
| T1027.002 Software Packing |
MalwareVERMIN | VERMIN is initially packed. |
| T1027.002 Software Packing |
MalwareDarkComet | DarkComet has the option to compress its payload using UPX or MPRESS. |
| T1027.002 Software Packing |
MalwareFatDuke | FatDuke has been regularly repacked by its operators to create large binaries and evade detection. |
| T1027.002 Software Packing |
MalwareLucifer | Lucifer has used UPX packed binaries. |
| T1027.002 Software Packing |
MalwareDRATzarus | DRATzarus's dropper can be packed with UPX. |
| T1027.002 Software Packing |
MalwareShimRat | ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack. |
| T1027.002 Software Packing |
MalwareChina Chopper | China Chopper's client component is packed with UPX. |
| T1027.002 Software Packing |
MalwareGoldMax | GoldMax has been packed for obfuscation. |
| T1027.002 Software Packing |
MalwareCostaBricks | CostaBricks can implement a custom-built virtual machine mechanism to obfuscate its code. |
| T1027.002 Software Packing |
MalwareHyperBro | HyperBro has the ability to pack its payload. |
| T1027.002 Software Packing |
MalwareAnchor | Anchor has come with a packed payload. |
| T1027.002 Software Packing |
MalwareBabuk | Versions of Babuk have been packed. |
| T1027.002 Software Packing |
MalwareDyre | Dyre has been delivered with encrypted resources and must be unpacked for execution. |
| T1027.002 Software Packing |
MalwareBisonal | Bisonal has used the MPRESS packer and similar tools for obfuscation. |
| T1027.002 Software Packing |
MalwareS-Type | Some S-Type samples have been packed with UPX. |
| T1027.002 Software Packing |
MalwareSeaDuke | SeaDuke has been packed with the UPX packer. |
| T1027.002 Software Packing |
MalwareCuba | Cuba has a packed payload when delivered. |
| T1027.002 Software Packing |
MalwareMongall | Mongall has been packed with Themida. |
| T1027.002 Software Packing |
MalwareLockBit 3.0 | LockBit 3.0 can use code packing to hinder analysis. |
| T1027.002 Software Packing |
MalwareLatrodectus | The Latrodectus payload has been packed for obfuscation. |
| T1027.002 Software Packing |
MalwareSaint Bot | Saint Bot has been packed using a dark market crypter. |
| T1027.002 Software Packing |
MalwareSagerunex | Sagerunex has used VMProtect to pack and obscure itself. |
| T1027.002 Software Packing |
MalwareUroburos | Uroburos uses a custom packer. |
| T1027.002 Software Packing |
MalwareMetamorfo | Metamorfo has used VMProtect to pack and protect files. |
| T1027.002 Software Packing |
MalwareTrojan.Karagany | Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer. |
| T1027.002 Software Packing |
MalwareKONNI | KONNI has been packed for obfuscation. |
| T1027.002 Software Packing |
MalwareRedLine Stealer | RedLine Stealer has used obfuscation tools such as DNGuard and Boxed App to pack their code. |
| T1027.002 Software Packing |
MalwareOopsIE | OopsIE uses the SmartAssembly obfuscator to pack an embedded .Net Framework assembly used for C2. |
| T1027.002 Software Packing |
MalwareSDBbot | SDBbot has used a packed installer file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.