Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupMirrorFace | MirrorFace has used Base64 encoded shellcode in infection chains to evade detection. |
| T1027.013 Encrypted/Encoded File |
GroupDarkhotel | Darkhotel has obfuscated code using RC4, XOR, and RSA. |
| T1027.013 Encrypted/Encoded File |
GroupWhitefly | Whitefly has encrypted the payload used for C2. |
| T1027.013 Encrypted/Encoded File |
GroupAPT28 | APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4. |
| T1027.013 Encrypted/Encoded File |
GroupMalteiro | Malteiro has used scripts encoded in Base64 certificates to distribute malware to victims. |
| T1027.013 Encrypted/Encoded File |
GroupMetador | Metador has encrypted their payloads. |
| T1027.013 Encrypted/Encoded File |
GroupFox Kitten | Fox Kitten has base64 encoded payloads to avoid detection. |
| T1027.013 Encrypted/Encoded File |
GroupAPT-C-36 | APT-C-36 has used encoded and obfuscated files, images, and executables. |
| T1027.013 Encrypted/Encoded File |
GroupLazarus Group | Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names. |
| T1027.013 Encrypted/Encoded File |
GroupTransparent Tribe | Transparent Tribe has dropped encoded executables on compromised hosts. |
| T1027.013 Encrypted/Encoded File |
GroupMoonstone Sleet | Moonstone Sleet has used encrypted payloads within files for follow-on execution and defense evasion. |
| T1027.013 Encrypted/Encoded File |
GroupInception | Inception has encrypted malware payloads dropped on victim machines with AES and RC4 encryption. |
| T1027.013 Encrypted/Encoded File |
GroupMagic Hound | Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES. |
| T1027.013 Encrypted/Encoded File |
GroupThreat Group-3390 | A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder. |
| T1027.013 Encrypted/Encoded File |
GroupAPT33 | APT33 has used base64 to encode payloads. |
| T1027.013 Encrypted/Encoded File |
GroupAPT19 | APT19 used Base64 to obfuscate payloads. |
| T1027.015 Compression |
GroupKimsuky | Kimsuky has delivered malicious payloads within Zip archives. |
| T1027.015 Compression |
GroupGamaredon Group | Gamaredon Group has delivered malicious payloads within compressed archives and zip files. |
| T1027.015 Compression |
GroupTA2541 | TA2541 has used compressed and char-encoded scripts in operations. |
| T1027.015 Compression |
GroupHigaisa | Higaisa used Base64 encoded compressed payloads. |
| T1027.015 Compression |
GroupLeviathan | Leviathan has obfuscated code using gzip compression. |
| T1027.015 Compression |
GroupMofang | Mofang has compressed the ShimRat executable within malicious email attachments. |
| T1027.015 Compression |
GroupMolerats | Molerats has delivered compressed executables within ZIP files to victims. |
| T1027.015 Compression |
GroupVOID MANTICORE | VOID MANTICORE has compressed their payloads by leveraging zip files. |
| T1027.015 Compression |
GroupWIRTE | WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation. |
| T1027.015 Compression |
GroupThreat Group-3390 | Threat Group-3390 malware is compressed with LZNT1 compression. |
| T1027.016 Junk Code Insertion |
GroupKimsuky | Kimsuky has obfuscated code by filling scripts with junk code and concatenating strings to hamper analysis and detection. |
| T1027.016 Junk Code Insertion |
GroupAPT32 | APT32 includes garbage code to mislead anti-malware software and researchers. |
| T1027.016 Junk Code Insertion |
GroupGamaredon Group | Gamaredon Group has obfuscated .NET executables by inserting junk code. |
| T1027.016 Junk Code Insertion |
GroupFIN7 | FIN7 has used random junk code to obfuscate malware code. |
| T1027.016 Junk Code Insertion |
GroupMustang Panda | Mustang Panda has used junk code within their DLL files to hinder analysis. |
| T1027.016 Junk Code Insertion |
GroupAPT-C-36 | APT-C-36 has used junk characters to obfuscate malicious scripts. |
| T1029 Scheduled Transfer |
GroupHigaisa | Higaisa sent the victim computer identifier in a User-Agent string back to the C2 server every 10 minutes. |
| T1030 Data Transfer Size Limits |
GroupAPT41 | APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection. |
| T1030 Data Transfer Size Limits |
GroupLuminousMoth | LuminousMoth has split archived files into multiple parts to bypass a 5MB limit. |
| T1030 Data Transfer Size Limits |
GroupAPT28 | APT28 has split archived exfiltration files into chunks smaller than 1MB. |
| T1030 Data Transfer Size Limits |
GroupPlay | Play has split victims' files into chunks for exfiltration. |
| T1030 Data Transfer Size Limits |
GroupThreat Group-3390 | Threat Group-3390 actors have split RAR files for exfiltration into parts. |
| T1033 System Owner/User Discovery |
GroupAPT38 | APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users. |
| T1033 System Owner/User Discovery |
GroupGALLIUM | GALLIUM used |
| T1033 System Owner/User Discovery |
GroupAPT3 | An APT3 downloader uses the Windows command |
| T1033 System Owner/User Discovery |
GroupKimsuky | Kimsuky has gathered the identity of the user by querying `System.Security.Principal` namespace using the `GetCurrent()` method. |
| T1033 System Owner/User Discovery |
GroupVolt Typhoon | Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names. |
| T1033 System Owner/User Discovery |
GroupPatchwork | Patchwork collected the victim username and whether it was running as admin, then sent the information to its C2 server. |
| T1033 System Owner/User Discovery |
GroupAPT41 | APT41 has executed |
| T1033 System Owner/User Discovery |
GroupDragonfly | Dragonfly used the command |
| T1033 System Owner/User Discovery |
GroupAPT32 | APT32 collected the victim's username and executed the |
| T1033 System Owner/User Discovery |
GroupHAFNIUM | HAFNIUM has used `whoami` to gather user information. |
| T1033 System Owner/User Discovery |
GroupMuddyWater | MuddyWater has used malware that can collect the victim’s username. |
| T1033 System Owner/User Discovery |
GroupGamaredon Group | A Gamaredon Group file stealer can gather the victim's username to send to a C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.