Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupSandworm Team | Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor. |
| T1027.010 Command Obfuscation |
GroupSidewinder | Sidewinder has used base64 encoding for scripts. |
| T1027.010 Command Obfuscation |
GroupContagious Interview | Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions. |
| T1027.010 Command Obfuscation |
GroupAquatic Panda | Aquatic Panda has encoded PowerShell commands in Base64. |
| T1027.010 Command Obfuscation |
GroupTurla | Turla has used encryption (including salted 3DES via PowerSploit's |
| T1027.010 Command Obfuscation |
GroupTA505 | TA505 has used base64 encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupChimera | Chimera has encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupMedusa Group | Medusa Group has obfuscated PowerShell scripts with Base64 encoding. Medusa Group has also obfuscated the code of dropped kernel drivers using a software known as Safengine Shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code. |
| T1027.010 Command Obfuscation |
GroupTA551 | TA551 has used obfuscated variable names in a JavaScript configuration file. |
| T1027.010 Command Obfuscation |
GroupLazyScripter | LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques. |
| T1027.010 Command Obfuscation |
GroupFox Kitten | Fox Kitten has base64 encoded scripts to avoid detection. |
| T1027.010 Command Obfuscation |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has executed base64 encoded PowerShell scripts on compromised hosts. |
| T1027.010 Command Obfuscation |
GroupSilence | Silence has used environment variable string substitution for obfuscation. |
| T1027.010 Command Obfuscation |
GroupCobalt Group | Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4. |
| T1027.010 Command Obfuscation |
GroupWizard Spider | Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupPlay | Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts. |
| T1027.010 Command Obfuscation |
GroupHEXANE | HEXANE has used Base64-encoded scripts. |
| T1027.010 Command Obfuscation |
GroupWIRTE | WIRTE has XOR encrypted command line strings to conceal malware execution chains. |
| T1027.010 Command Obfuscation |
GroupMagic Hound | Magic Hound has used base64-encoded commands. |
| T1027.010 Command Obfuscation |
GroupFIN8 | FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads. |
| T1027.010 Command Obfuscation |
GroupAPT19 | APT19 used Base64 to obfuscate executed commands. |
| T1027.011 Fileless Storage |
GroupAPT32 | APT32's backdoor has stored its configuration in a registry key. |
| T1027.011 Fileless Storage |
GroupTurla | Turla has used the Registry to store encrypted and encoded payloads. |
| T1027.012 LNK Icon Smuggling |
GroupKimsuky | Kimsuky has used the LNK icon location to execute malicious scripts. Kimsuky has also padded the LNK target field properties with extra spaces to obscure the script. |
| T1027.012 LNK Icon Smuggling |
GroupGamaredon Group | Gamaredon Group has used LNK files to hide malicious scripts for execution. |
| T1027.012 LNK Icon Smuggling |
GroupMustang Panda | Mustang Panda has utilized LNK files to hide malicious scripts for execution. Mustang Panda has also leveraged LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary. |
| T1027.013 Encrypted/Encoded File |
GroupElderwood | Elderwood has encrypted documents and malicious executables. |
| T1027.013 Encrypted/Encoded File |
GroupKimsuky | Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads. |
| T1027.013 Encrypted/Encoded File |
GroupmenuPass | menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40. |
| T1027.013 Encrypted/Encoded File |
GroupAPT32 | APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor. |
| T1027.013 Encrypted/Encoded File |
GroupStorm-1811 | Storm-1811 XOR encodes a Cobalt Strike installation payload in a DLL file that is decoded with a hardcoded key when called by a legitimate 7zip installation process. |
| T1027.013 Encrypted/Encoded File |
GroupTeamTNT | TeamTNT has encrypted its binaries via AES and encoded files using Base64. |
| T1027.013 Encrypted/Encoded File |
GroupAPT18 | APT18 obfuscates strings in the payload. |
| T1027.013 Encrypted/Encoded File |
GroupSidewinder | Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads. |
| T1027.013 Encrypted/Encoded File |
GroupAPT39 | APT39 has used malware to drop encrypted CAB files. |
| T1027.013 Encrypted/Encoded File |
GroupContagious Interview | Contagious Interview has used hexadecimal string encoding to hide critical JavaScript module names, function names, and C2 URLs, which are decoded dynamically at runtime. |
| T1027.013 Encrypted/Encoded File |
GroupTA2541 | TA2541 has used compressed and char-encoded scripts in operations. |
| T1027.013 Encrypted/Encoded File |
GroupMoses Staff | Moses Staff has used obfuscated web shells in their operations. |
| T1027.013 Encrypted/Encoded File |
GroupOilRig | OilRig has encrypted and encoded data in its malware, including by using base64. |
| T1027.013 Encrypted/Encoded File |
GroupHigaisa | Higaisa used Base64 encoded compressed payloads. |
| T1027.013 Encrypted/Encoded File |
GroupTropic Trooper | Tropic Trooper has encrypted configuration files. |
| T1027.013 Encrypted/Encoded File |
GroupPutter Panda | Droppers used by Putter Panda use RC4 or a 16-byte XOR key consisting of the bytes 0xA0 – 0xAF to obfuscate payloads. |
| T1027.013 Encrypted/Encoded File |
GroupSaint Bear | Saint Bear initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader. |
| T1027.013 Encrypted/Encoded File |
GroupLeviathan | Leviathan has obfuscated code using base64. |
| T1027.013 Encrypted/Encoded File |
GroupGroup5 | Group5 disguised its malicious binaries with several layers of obfuscation, including encrypting the files. |
| T1027.013 Encrypted/Encoded File |
GroupBlue Mockingbird | Blue Mockingbird has obfuscated the wallet address in the payload binary. |
| T1027.013 Encrypted/Encoded File |
GroupTA505 | TA505 has password-protected malicious Word documents. |
| T1027.013 Encrypted/Encoded File |
GroupBITTER | BITTER has used a RAR SFX dropper to deliver malware. |
| T1027.013 Encrypted/Encoded File |
GroupMofang | Mofang has encrypted payloads before they are downloaded to victims. |
| T1027.013 Encrypted/Encoded File |
GroupDark Caracal | Dark Caracal has obfuscated strings in Bandook by base64 encoding, and then encrypting them. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.