ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupSandworm Team

Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor.

T1027.010
Command Obfuscation
GroupSidewinder

Sidewinder has used base64 encoding for scripts.

T1027.010
Command Obfuscation
GroupContagious Interview

Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions.

T1027.010
Command Obfuscation
GroupAquatic Panda

Aquatic Panda has encoded PowerShell commands in Base64.

T1027.010
Command Obfuscation
GroupTurla

Turla has used encryption (including salted 3DES via PowerSploit's Out-EncryptedScript.ps1), random variable names, and base64 encoding to obfuscate PowerShell commands and payloads.

T1027.010
Command Obfuscation
GroupTA505

TA505 has used base64 encoded PowerShell commands.

T1027.010
Command Obfuscation
GroupChimera

Chimera has encoded PowerShell commands.

T1027.010
Command Obfuscation
GroupMedusa Group

Medusa Group has obfuscated PowerShell scripts with Base64 encoding. Medusa Group has also obfuscated the code of dropped kernel drivers using a software known as Safengine Shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code.

T1027.010
Command Obfuscation
GroupTA551

TA551 has used obfuscated variable names in a JavaScript configuration file.

T1027.010
Command Obfuscation
GroupLazyScripter

LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques.

T1027.010
Command Obfuscation
GroupFox Kitten

Fox Kitten has base64 encoded scripts to avoid detection.

T1027.010
Command Obfuscation
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has executed base64 encoded PowerShell scripts on compromised hosts.

T1027.010
Command Obfuscation
GroupSilence

Silence has used environment variable string substitution for obfuscation.

T1027.010
Command Obfuscation
GroupCobalt Group

Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4.

T1027.010
Command Obfuscation
GroupWizard Spider

Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands.

T1027.010
Command Obfuscation
GroupPlay

Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.

T1027.010
Command Obfuscation
GroupHEXANE

HEXANE has used Base64-encoded scripts.

T1027.010
Command Obfuscation
GroupWIRTE

WIRTE has XOR encrypted command line strings to conceal malware execution chains.

T1027.010
Command Obfuscation
GroupMagic Hound

Magic Hound has used base64-encoded commands.

T1027.010
Command Obfuscation
GroupFIN8

FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads.

T1027.010
Command Obfuscation
GroupAPT19

APT19 used Base64 to obfuscate executed commands.

T1027.011
Fileless Storage
GroupAPT32

APT32's backdoor has stored its configuration in a registry key.

T1027.011
Fileless Storage
GroupTurla

Turla has used the Registry to store encrypted and encoded payloads.

T1027.012
LNK Icon Smuggling
GroupKimsuky

Kimsuky has used the LNK icon location to execute malicious scripts. Kimsuky has also padded the LNK target field properties with extra spaces to obscure the script.

T1027.012
LNK Icon Smuggling
GroupGamaredon Group

Gamaredon Group has used LNK files to hide malicious scripts for execution.

T1027.012
LNK Icon Smuggling
GroupMustang Panda

Mustang Panda has utilized LNK files to hide malicious scripts for execution. Mustang Panda has also leveraged LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary.

T1027.013
Encrypted/Encoded File
GroupElderwood

Elderwood has encrypted documents and malicious executables.

T1027.013
Encrypted/Encoded File
GroupKimsuky

Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads.

T1027.013
Encrypted/Encoded File
GroupmenuPass

menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40.

T1027.013
Encrypted/Encoded File
GroupAPT32

APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor.

T1027.013
Encrypted/Encoded File
GroupStorm-1811

Storm-1811 XOR encodes a Cobalt Strike installation payload in a DLL file that is decoded with a hardcoded key when called by a legitimate 7zip installation process.

T1027.013
Encrypted/Encoded File
GroupTeamTNT

TeamTNT has encrypted its binaries via AES and encoded files using Base64.

T1027.013
Encrypted/Encoded File
GroupAPT18

APT18 obfuscates strings in the payload.

T1027.013
Encrypted/Encoded File
GroupSidewinder

Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads.

T1027.013
Encrypted/Encoded File
GroupAPT39

APT39 has used malware to drop encrypted CAB files.

T1027.013
Encrypted/Encoded File
GroupContagious Interview

Contagious Interview has used hexadecimal string encoding to hide critical JavaScript module names, function names, and C2 URLs, which are decoded dynamically at runtime.

T1027.013
Encrypted/Encoded File
GroupTA2541

TA2541 has used compressed and char-encoded scripts in operations.

T1027.013
Encrypted/Encoded File
GroupMoses Staff

Moses Staff has used obfuscated web shells in their operations.

T1027.013
Encrypted/Encoded File
GroupOilRig

OilRig has encrypted and encoded data in its malware, including by using base64.

T1027.013
Encrypted/Encoded File
GroupHigaisa

Higaisa used Base64 encoded compressed payloads.

T1027.013
Encrypted/Encoded File
GroupTropic Trooper

Tropic Trooper has encrypted configuration files.

T1027.013
Encrypted/Encoded File
GroupPutter Panda

Droppers used by Putter Panda use RC4 or a 16-byte XOR key consisting of the bytes 0xA0 – 0xAF to obfuscate payloads.

T1027.013
Encrypted/Encoded File
GroupSaint Bear

Saint Bear initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader.

T1027.013
Encrypted/Encoded File
GroupLeviathan

Leviathan has obfuscated code using base64.

T1027.013
Encrypted/Encoded File
GroupGroup5

Group5 disguised its malicious binaries with several layers of obfuscation, including encrypting the files.

T1027.013
Encrypted/Encoded File
GroupBlue Mockingbird

Blue Mockingbird has obfuscated the wallet address in the payload binary.

T1027.013
Encrypted/Encoded File
GroupTA505

TA505 has password-protected malicious Word documents.

T1027.013
Encrypted/Encoded File
GroupBITTER

BITTER has used a RAR SFX dropper to deliver malware.

T1027.013
Encrypted/Encoded File
GroupMofang

Mofang has encrypted payloads before they are downloaded to victims.

T1027.013
Encrypted/Encoded File
GroupDark Caracal

Dark Caracal has obfuscated strings in Bandook by base64 encoding, and then encrypting them.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.