Real-world descriptions of how a group, tool or campaign used a technique.
138 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareROKRAT | ROKRAT can encrypt data prior to exfiltration by using an RSA public key. |
| T1027 Obfuscated Files or Information |
MalwareCORESHELL | CORESHELL obfuscates strings using a custom stream cipher. |
| T1027 Obfuscated Files or Information |
MalwarePlugX | PlugX can use API hashing and modify the names of strings to evade detection. |
| T1027 Obfuscated Files or Information |
MalwareNOOPLDR | NOOPLDR can use control flow flattening to help hide malicious code. |
| T1027 Obfuscated Files or Information |
MalwareLumma Stealer | Lumma Stealer has used SmartAssembly to obfuscate .NET payloads. |
| T1027 Obfuscated Files or Information |
MalwareDustySky | The DustySky dropper uses a function to obfuscate the name of functions and other parts of the malware. |
| T1027 Obfuscated Files or Information |
MalwareEpic | Epic heavily obfuscates its code to make analysis more difficult. |
| T1027 Obfuscated Files or Information |
MalwareCuba | Cuba has used multiple layers of obfuscation to avoid analysis, including its Base64 encoded payload. |
| T1027 Obfuscated Files or Information |
MalwareClambling | The Clambling executable has been obfuscated when dropped on a compromised host. |
| T1027 Obfuscated Files or Information |
MalwareDarkGate | DarkGate uses a hard-coded string as a seed, along with the victim machine hardware identifier and input text, to generate a unique string used as an internal mutex value to evade static detection based on mutexes. |
| T1027 Obfuscated Files or Information |
MalwareSVCReady | SVCReady can encrypt victim data with an RC4 cipher. |
| T1027 Obfuscated Files or Information |
MalwareCarbanak | Carbanak encrypts strings to make analysis more difficult. |
| T1027 Obfuscated Files or Information |
MalwareXTunnel | A version of XTunnel introduced in July 2015 obfuscated the binary using opaque predicates and other techniques in a likely attempt to obfuscate it and bypass security products. |
| T1027 Obfuscated Files or Information |
MalwareHydraq | Hydraq uses basic obfuscation in the form of spaghetti code. |
| T1027 Obfuscated Files or Information |
MalwareSaint Bot | Saint Bot has been obfuscated to help avoid detection. |
| T1027 Obfuscated Files or Information |
MalwareLODEINFO | LODEINFO has used control flow flattening to obfuscate code. |
| T1027 Obfuscated Files or Information |
MalwareBundlore | Bundlore has obfuscated data with base64, AES, RC4, and bz2. |
| T1027 Obfuscated Files or Information |
MalwareFooder | Fooder has stored its embedded payload in encrypted form within the binary, using a hardcoded key modified at runtime to produce the AES decryption key. |
| T1027 Obfuscated Files or Information |
MalwareTrojan.Karagany | Trojan.Karagany can base64 encode and AES-128-CBC encrypt data prior to transmission. |
| T1027 Obfuscated Files or Information |
MalwareShamoon | Shamoon contains base64-encoded strings. |
| T1027 Obfuscated Files or Information |
MalwareBPFDoor | BPFDoor can require a password to activate the backdoor and uses RC4 encryption or static library encryption `libtomcrypt`. |
| T1027 Obfuscated Files or Information |
MalwareOopsIE | OopsIE uses the Confuser protector to obfuscate an embedded .Net Framework assembly used for C2. OopsIE also encodes collected data in hexadecimal format before writing to files on disk and obfuscates strings. |
| T1027 Obfuscated Files or Information |
MalwareStreamEx | StreamEx obfuscates some commands by using statically programmed fragments of strings when starting a DLL. It also uses a one-byte xor against 0x91 to encode configuration data. |
| T1027 Obfuscated Files or Information |
MalwareBoxCaon | BoxCaon used the "StackStrings" obfuscation technique to hide malicious functionalities. |
| T1027 Obfuscated Files or Information |
MalwareNightClub | NightClub can obfuscate strings using the congruential generator `(LCG): staten+1 = (690069 × staten + 1) mod 232`. |
| T1027 Obfuscated Files or Information |
MalwareSDBbot | SDBbot has the ability to XOR the strings for its installer component with a hardcoded 128 byte key. |
| T1027 Obfuscated Files or Information |
MalwareRTM | RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm. |
| T1027 Obfuscated Files or Information |
MalwareSodaMaster | SodaMaster can use "stackstrings" for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareStrelaStealer | StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives. |
| T1027 Obfuscated Files or Information |
MalwareDrovorub | Drovorub has used XOR encrypted payloads in WebSocket client to server messages. |
| T1027 Obfuscated Files or Information |
MalwareKobalos | Kobalos encrypts all strings using RC4 and bundles all functionality into a single function call. |
| T1027 Obfuscated Files or Information |
MalwareRyuk | Ryuk can use anti-disassembly and code transformation obfuscation techniques. |
| T1027 Obfuscated Files or Information |
MalwareFinal1stspy | Final1stspy obfuscates strings with base64 encoding. |
| T1027 Obfuscated Files or Information |
MalwareFinFisher | FinFisher is heavily obfuscated in many ways, including through the use of spaghetti code in its functions in an effort to confuse disassembly programs. It also uses a custom XOR algorithm to obfuscate code. |
| T1027 Obfuscated Files or Information |
MalwareCobalt Strike | Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata. |
| T1027 Obfuscated Files or Information |
MalwareSUNBURST | SUNBURST obfuscated collected system information using a FNV-1a + XOR algorithm. |
| T1027 Obfuscated Files or Information |
MalwareValak | Valak has the ability to base64 encode and XOR encrypt strings. |
| T1027 Obfuscated Files or Information |
MalwareSamurai | Samurai can encrypt the names of requested APIs. |
| T1027 Obfuscated Files or Information |
MalwarePoisonIvy | PoisonIvy hides any strings related to its own indicators of compromise. |
| T1027 Obfuscated Files or Information |
MalwareNanoCore | NanoCore’s plugins were obfuscated with Eazfuscater.NET 3.3. |
| T1027 Obfuscated Files or Information |
MalwareTajMahal | TajMahal has used an encrypted Virtual File System to store plugins. |
| T1027 Obfuscated Files or Information |
MalwareDaserf | Daserf uses encrypted Windows APIs and also encrypts data using the alternative base64+RC4 or the Caesar cipher. |
| T1027 Obfuscated Files or Information |
MalwareCarbon | Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm. |
| T1027 Obfuscated Files or Information |
MalwarePisloader | Pisloader obfuscates files by splitting strings into smaller sub-strings and including "garbage" strings that are never used. The malware also uses return-oriented programming (ROP) technique and single-byte XOR to obfuscate data. |
| T1027 Obfuscated Files or Information |
MalwareRamsay | Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. Ramsay can also embed information within document footers. |
| T1027 Obfuscated Files or Information |
MalwarePillowmint | Pillowmint has obfuscated the AES key used for encryption. |
| T1027 Obfuscated Files or Information |
MalwareSUNSPOT | SUNSPOT encrypted log entries it collected with the stream cipher RC4 using a hard-coded key. It also uses AES128-CBC encrypted blobs for SUNBURST source code and data extracted from the SolarWinds Orion <MsBuild.exe</code> process. |
| T1027 Obfuscated Files or Information |
MalwareANELLDR | ANELLDR code implements anti-analysis techniques including control flow flattening and Mixed Boolean Arithmetic (MBA). |
| T1027 Obfuscated Files or Information |
MalwareBoomBox | BoomBox can encrypt data using AES prior to exfiltration. |
| T1027 Obfuscated Files or Information |
MalwarePUNCHTRACK | PUNCHTRACK is loaded and executed by a highly obfuscated launcher. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.