ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
GroupZIRCONIUM

ZIRCONIUM has used multi-stage packers for exploit code.

T1027.002
Software Packing
GroupRocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1027.002
Software Packing
GroupAPT39

APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection.

T1027.002
Software Packing
GroupTA2541

TA2541 has used a .NET packer to obfuscate malicious files.

T1027.002
Software Packing
GroupAoqin Dragon

Aoqin Dragon has used the Themida packer to obfuscate malicious payloads.

T1027.002
Software Packing
GroupThe White Company

The White Company has obfuscated their payloads through packing.

T1027.002
Software Packing
GroupSaint Bear

Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload.

T1027.002
Software Packing
GroupMoustachedBouncer

MoustachedBouncer has used malware plugins packed with Themida.

T1027.002
Software Packing
GroupStorm-0501

Storm-0501 has used Themida to pack Cobalt Strike payloads.

T1027.002
Software Packing
GroupTA505

TA505 has used UPX to obscure malicious code.

T1027.002
Software Packing
GroupAPT29

APT29 used UPX to pack files.

T1027.002
Software Packing
GroupDark Caracal

Dark Caracal has used UPX to pack Bandook.

T1027.002
Software Packing
GroupMedusa Group

Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard.

T1027.002
Software Packing
GroupThreat Group-3390

Threat Group-3390 has packed malware and tools, including using VMProtect.

T1027.003
Steganography
GroupMuddyWater

MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg.

T1027.003
Steganography
GroupAndariel

Andariel has hidden malicious executables within PNG files.

T1027.003
Steganography
GroupAPT37

APT37 uses steganography to send images to users that are embedded with shellcode.

T1027.003
Steganography
GroupTropic Trooper

Tropic Trooper has used JPG files with encrypted payloads to mask their backdoor routines and evade detection.

T1027.003
Steganography
GroupLeviathan

Leviathan has used steganography to hide stolen data inside other files stored on Github.

T1027.003
Steganography
GroupBRONZE BUTLER

BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads.

T1027.003
Steganography
GroupTA551

TA551 has hidden encoded data for malware DLLs in a PNG.

T1027.003
Steganography
GroupAPT-C-36

APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files.

T1027.003
Steganography
GroupEarth Lusca

Earth Lusca has used steganography to hide shellcode in a BMP image file.

T1027.003
Steganography
GroupTeamPCP

TeamPCP has hidden malicious payloads in the frame data of WAV audio files.

T1027.004
Compile After Delivery
GroupMuddyWater

MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code.

T1027.004
Compile After Delivery
GroupGamaredon Group

Gamaredon Group has compiled the source code for a downloader directly on the infected system using the built-in Microsoft.CSharp.CSharpCodeProvider class.

T1027.004
Compile After Delivery
GroupRocke

Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC).

T1027.004
Compile After Delivery
GroupSea Turtle

Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments.

T1027.005
Indicator Removal from Tools
GroupGALLIUM

GALLIUM ensured each payload had a unique hash, including by using different types of packers.

T1027.005
Indicator Removal from Tools
GroupAPT3

APT3 has been known to remove indicators of compromise from tools.

T1027.005
Indicator Removal from Tools
GroupPatchwork

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

T1027.005
Indicator Removal from Tools
GroupUNC3886

UNC3886 has replaced atomic indicators mentioned in threat intelligence publications, sometimes as quickly as under a week after release.

T1027.005
Indicator Removal from Tools
GroupOilRig

OilRig has tested malware samples to determine AV detection and subsequently modified the samples to ensure AV evasion.

T1027.005
Indicator Removal from Tools
GroupTurla

Based on comparison of Gazer versions, Turla made an effort to obfuscate strings in the malware that could be used as IoCs, including the mutex name and named pipe.

T1027.005
Indicator Removal from Tools
GroupDeep Panda

Deep Panda has updated and modified its malware, resulting in different hash values that evade detection.

T1027.006
HTML Smuggling
GroupAPT29

APT29 has embedded an ISO file within an HTML attachment that contained JavaScript code to initiate malware execution.

T1027.007
Dynamic API Resolution
GroupKimsuky

Kimsuky has leveraged dynamic API resolution using custom hashing techniques.

T1027.007
Dynamic API Resolution
GroupMustang Panda

Mustang Panda has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.

T1027.007
Dynamic API Resolution
GroupLazarus Group

Lazarus Group has used a custom hashing method to resolve APIs used in shellcode.

T1027.009
Embedded Payloads
GroupTA577

TA577 has used LNK files to execute embedded DLLs.

T1027.009
Embedded Payloads
GroupLazarus Group

Lazarus Group has distributed malicious payloads embedded in PNG files.

T1027.009
Embedded Payloads
GroupMoonstone Sleet

Moonstone Sleet embedded payloads in trojanized software for follow-on execution.

T1027.010
Command Obfuscation
GroupKimsuky

Kimsuky has encoded malicious PowerShell scripts using Base64.

T1027.010
Command Obfuscation
GroupPatchwork

Patchwork has obfuscated a script with Crypto Obfuscator.

T1027.010
Command Obfuscation
GroupAPT32

APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell.

T1027.010
Command Obfuscation
GroupMuddyWater

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.

T1027.010
Command Obfuscation
GroupFIN6

FIN6 has used encoded PowerShell commands.

T1027.010
Command Obfuscation
GroupGamaredon Group

Gamaredon Group has used obfuscated or encrypted scripts.

T1027.010
Command Obfuscation
GroupLeafminer

Leafminer obfuscated scripts that were used on victim machines.

T1027.010
Command Obfuscation
GroupFIN7

FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.