ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027×

138 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareROKRAT

ROKRAT can encrypt data prior to exfiltration by using an RSA public key.

T1027
Obfuscated Files or Information
MalwareCORESHELL

CORESHELL obfuscates strings using a custom stream cipher.

T1027
Obfuscated Files or Information
MalwarePlugX

PlugX can use API hashing and modify the names of strings to evade detection.

T1027
Obfuscated Files or Information
MalwareNOOPLDR

NOOPLDR can use control flow flattening to help hide malicious code.

T1027
Obfuscated Files or Information
MalwareLumma Stealer

Lumma Stealer has used SmartAssembly to obfuscate .NET payloads.

T1027
Obfuscated Files or Information
MalwareDustySky

The DustySky dropper uses a function to obfuscate the name of functions and other parts of the malware.

T1027
Obfuscated Files or Information
MalwareEpic

Epic heavily obfuscates its code to make analysis more difficult.

T1027
Obfuscated Files or Information
MalwareCuba

Cuba has used multiple layers of obfuscation to avoid analysis, including its Base64 encoded payload.

T1027
Obfuscated Files or Information
MalwareClambling

The Clambling executable has been obfuscated when dropped on a compromised host.

T1027
Obfuscated Files or Information
MalwareDarkGate

DarkGate uses a hard-coded string as a seed, along with the victim machine hardware identifier and input text, to generate a unique string used as an internal mutex value to evade static detection based on mutexes.

T1027
Obfuscated Files or Information
MalwareSVCReady

SVCReady can encrypt victim data with an RC4 cipher.

T1027
Obfuscated Files or Information
MalwareCarbanak

Carbanak encrypts strings to make analysis more difficult.

T1027
Obfuscated Files or Information
MalwareXTunnel

A version of XTunnel introduced in July 2015 obfuscated the binary using opaque predicates and other techniques in a likely attempt to obfuscate it and bypass security products.

T1027
Obfuscated Files or Information
MalwareHydraq

Hydraq uses basic obfuscation in the form of spaghetti code.

T1027
Obfuscated Files or Information
MalwareSaint Bot

Saint Bot has been obfuscated to help avoid detection.

T1027
Obfuscated Files or Information
MalwareLODEINFO

LODEINFO has used control flow flattening to obfuscate code.

T1027
Obfuscated Files or Information
MalwareBundlore

Bundlore has obfuscated data with base64, AES, RC4, and bz2.

T1027
Obfuscated Files or Information
MalwareFooder

Fooder has stored its embedded payload in encrypted form within the binary, using a hardcoded key modified at runtime to produce the AES decryption key.

T1027
Obfuscated Files or Information
MalwareTrojan.Karagany

Trojan.Karagany can base64 encode and AES-128-CBC encrypt data prior to transmission.

T1027
Obfuscated Files or Information
MalwareShamoon

Shamoon contains base64-encoded strings.

T1027
Obfuscated Files or Information
MalwareBPFDoor

BPFDoor can require a password to activate the backdoor and uses RC4 encryption or static library encryption `libtomcrypt`.

T1027
Obfuscated Files or Information
MalwareOopsIE

OopsIE uses the Confuser protector to obfuscate an embedded .Net Framework assembly used for C2. OopsIE also encodes collected data in hexadecimal format before writing to files on disk and obfuscates strings.

T1027
Obfuscated Files or Information
MalwareStreamEx

StreamEx obfuscates some commands by using statically programmed fragments of strings when starting a DLL. It also uses a one-byte xor against 0x91 to encode configuration data.

T1027
Obfuscated Files or Information
MalwareBoxCaon

BoxCaon used the "StackStrings" obfuscation technique to hide malicious functionalities.

T1027
Obfuscated Files or Information
MalwareNightClub

NightClub can obfuscate strings using the congruential generator `(LCG): staten+1 = (690069 × staten + 1) mod 232`.

T1027
Obfuscated Files or Information
MalwareSDBbot

SDBbot has the ability to XOR the strings for its installer component with a hardcoded 128 byte key.

T1027
Obfuscated Files or Information
MalwareRTM

RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm.

T1027
Obfuscated Files or Information
MalwareSodaMaster

SodaMaster can use "stackstrings" for obfuscation.

T1027
Obfuscated Files or Information
MalwareStrelaStealer

StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives.

T1027
Obfuscated Files or Information
MalwareDrovorub

Drovorub has used XOR encrypted payloads in WebSocket client to server messages.

T1027
Obfuscated Files or Information
MalwareKobalos

Kobalos encrypts all strings using RC4 and bundles all functionality into a single function call.

T1027
Obfuscated Files or Information
MalwareRyuk

Ryuk can use anti-disassembly and code transformation obfuscation techniques.

T1027
Obfuscated Files or Information
MalwareFinal1stspy

Final1stspy obfuscates strings with base64 encoding.

T1027
Obfuscated Files or Information
MalwareFinFisher

FinFisher is heavily obfuscated in many ways, including through the use of spaghetti code in its functions in an effort to confuse disassembly programs. It also uses a custom XOR algorithm to obfuscate code.

T1027
Obfuscated Files or Information
MalwareCobalt Strike

Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata.

T1027
Obfuscated Files or Information
MalwareSUNBURST

SUNBURST obfuscated collected system information using a FNV-1a + XOR algorithm.

T1027
Obfuscated Files or Information
MalwareValak

Valak has the ability to base64 encode and XOR encrypt strings.

T1027
Obfuscated Files or Information
MalwareSamurai

Samurai can encrypt the names of requested APIs.

T1027
Obfuscated Files or Information
MalwarePoisonIvy

PoisonIvy hides any strings related to its own indicators of compromise.

T1027
Obfuscated Files or Information
MalwareNanoCore

NanoCore’s plugins were obfuscated with Eazfuscater.NET 3.3.

T1027
Obfuscated Files or Information
MalwareTajMahal

TajMahal has used an encrypted Virtual File System to store plugins.

T1027
Obfuscated Files or Information
MalwareDaserf

Daserf uses encrypted Windows APIs and also encrypts data using the alternative base64+RC4 or the Caesar cipher.

T1027
Obfuscated Files or Information
MalwareCarbon

Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm.

T1027
Obfuscated Files or Information
MalwarePisloader

Pisloader obfuscates files by splitting strings into smaller sub-strings and including "garbage" strings that are never used. The malware also uses return-oriented programming (ROP) technique and single-byte XOR to obfuscate data.

T1027
Obfuscated Files or Information
MalwareRamsay

Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. Ramsay can also embed information within document footers.

T1027
Obfuscated Files or Information
MalwarePillowmint

Pillowmint has obfuscated the AES key used for encryption.

T1027
Obfuscated Files or Information
MalwareSUNSPOT

SUNSPOT encrypted log entries it collected with the stream cipher RC4 using a hard-coded key. It also uses AES128-CBC encrypted blobs for SUNBURST source code and data extracted from the SolarWinds Orion <MsBuild.exe</code> process.

T1027
Obfuscated Files or Information
MalwareANELLDR

ANELLDR code implements anti-analysis techniques including control flow flattening and Mixed Boolean Arithmetic (MBA).

T1027
Obfuscated Files or Information
MalwareBoomBox

BoomBox can encrypt data using AES prior to exfiltration.

T1027
Obfuscated Files or Information
MalwarePUNCHTRACK

PUNCHTRACK is loaded and executed by a highly obfuscated launcher.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.