Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
GroupZIRCONIUM | ZIRCONIUM has used multi-stage packers for exploit code. |
| T1027.002 Software Packing |
GroupRocke | Rocke's miner has created UPX-packed files in the Windows Start Menu Folder. |
| T1027.002 Software Packing |
GroupAPT39 | APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection. |
| T1027.002 Software Packing |
GroupTA2541 | TA2541 has used a .NET packer to obfuscate malicious files. |
| T1027.002 Software Packing |
GroupAoqin Dragon | Aoqin Dragon has used the Themida packer to obfuscate malicious payloads. |
| T1027.002 Software Packing |
GroupThe White Company | The White Company has obfuscated their payloads through packing. |
| T1027.002 Software Packing |
GroupSaint Bear | Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload. |
| T1027.002 Software Packing |
GroupMoustachedBouncer | MoustachedBouncer has used malware plugins packed with Themida. |
| T1027.002 Software Packing |
GroupStorm-0501 | Storm-0501 has used Themida to pack Cobalt Strike payloads. |
| T1027.002 Software Packing |
GroupTA505 | TA505 has used UPX to obscure malicious code. |
| T1027.002 Software Packing |
GroupAPT29 | APT29 used UPX to pack files. |
| T1027.002 Software Packing |
GroupDark Caracal | Dark Caracal has used UPX to pack Bandook. |
| T1027.002 Software Packing |
GroupMedusa Group | Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard. |
| T1027.002 Software Packing |
GroupThreat Group-3390 | Threat Group-3390 has packed malware and tools, including using VMProtect. |
| T1027.003 Steganography |
GroupMuddyWater | MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg. |
| T1027.003 Steganography |
GroupAndariel | Andariel has hidden malicious executables within PNG files. |
| T1027.003 Steganography |
GroupAPT37 | APT37 uses steganography to send images to users that are embedded with shellcode. |
| T1027.003 Steganography |
GroupTropic Trooper | Tropic Trooper has used JPG files with encrypted payloads to mask their backdoor routines and evade detection. |
| T1027.003 Steganography |
GroupLeviathan | Leviathan has used steganography to hide stolen data inside other files stored on Github. |
| T1027.003 Steganography |
GroupBRONZE BUTLER | BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads. |
| T1027.003 Steganography |
GroupTA551 | TA551 has hidden encoded data for malware DLLs in a PNG. |
| T1027.003 Steganography |
GroupAPT-C-36 | APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files. |
| T1027.003 Steganography |
GroupEarth Lusca | Earth Lusca has used steganography to hide shellcode in a BMP image file. |
| T1027.003 Steganography |
GroupTeamPCP | TeamPCP has hidden malicious payloads in the frame data of WAV audio files. |
| T1027.004 Compile After Delivery |
GroupMuddyWater | MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code. |
| T1027.004 Compile After Delivery |
GroupGamaredon Group | Gamaredon Group has compiled the source code for a downloader directly on the infected system using the built-in |
| T1027.004 Compile After Delivery |
GroupRocke | Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC). |
| T1027.004 Compile After Delivery |
GroupSea Turtle | Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments. |
| T1027.005 Indicator Removal from Tools |
GroupGALLIUM | GALLIUM ensured each payload had a unique hash, including by using different types of packers. |
| T1027.005 Indicator Removal from Tools |
GroupAPT3 | APT3 has been known to remove indicators of compromise from tools. |
| T1027.005 Indicator Removal from Tools |
GroupPatchwork | Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes. |
| T1027.005 Indicator Removal from Tools |
GroupUNC3886 | UNC3886 has replaced atomic indicators mentioned in threat intelligence publications, sometimes as quickly as under a week after release. |
| T1027.005 Indicator Removal from Tools |
GroupOilRig | OilRig has tested malware samples to determine AV detection and subsequently modified the samples to ensure AV evasion. |
| T1027.005 Indicator Removal from Tools |
GroupTurla | Based on comparison of Gazer versions, Turla made an effort to obfuscate strings in the malware that could be used as IoCs, including the mutex name and named pipe. |
| T1027.005 Indicator Removal from Tools |
GroupDeep Panda | Deep Panda has updated and modified its malware, resulting in different hash values that evade detection. |
| T1027.006 HTML Smuggling |
GroupAPT29 | APT29 has embedded an ISO file within an HTML attachment that contained JavaScript code to initiate malware execution. |
| T1027.007 Dynamic API Resolution |
GroupKimsuky | Kimsuky has leveraged dynamic API resolution using custom hashing techniques. |
| T1027.007 Dynamic API Resolution |
GroupMustang Panda | Mustang Panda has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API. |
| T1027.007 Dynamic API Resolution |
GroupLazarus Group | Lazarus Group has used a custom hashing method to resolve APIs used in shellcode. |
| T1027.009 Embedded Payloads |
GroupTA577 | TA577 has used LNK files to execute embedded DLLs. |
| T1027.009 Embedded Payloads |
GroupLazarus Group | Lazarus Group has distributed malicious payloads embedded in PNG files. |
| T1027.009 Embedded Payloads |
GroupMoonstone Sleet | Moonstone Sleet embedded payloads in trojanized software for follow-on execution. |
| T1027.010 Command Obfuscation |
GroupKimsuky | Kimsuky has encoded malicious PowerShell scripts using Base64. |
| T1027.010 Command Obfuscation |
GroupPatchwork | Patchwork has obfuscated a script with Crypto Obfuscator. |
| T1027.010 Command Obfuscation |
GroupAPT32 | APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell. |
| T1027.010 Command Obfuscation |
GroupMuddyWater | MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupFIN6 | FIN6 has used encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupGamaredon Group | Gamaredon Group has used obfuscated or encrypted scripts. |
| T1027.010 Command Obfuscation |
GroupLeafminer | Leafminer obfuscated scripts that were used on victim machines. |
| T1027.010 Command Obfuscation |
GroupFIN7 | FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.