Real-world descriptions of how a group, tool or campaign used a technique.
73 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareStrelaStealer | StrelaStealer variants have used packers to obfuscate payloads and make analysis more difficult. |
| T1027.002 Software Packing |
MalwareLiteDuke | LiteDuke has been packed with multiple layers of encryption. |
| T1027.002 Software Packing |
MalwareBazar | Bazar has a variant with a packed payload. |
| T1027.002 Software Packing |
MalwareXLoader | XLoader uses various packers, including CyaX, to obfuscate malicious executables. |
| T1027.002 Software Packing |
MalwareZebrocy | Zebrocy's Delphi variant was packed with UPX. |
| T1027.002 Software Packing |
MalwareFinFisher | A FinFisher variant uses a custom packer. |
| T1027.002 Software Packing |
MalwareHotCroissant | HotCroissant has used the open source UPX executable packer. |
| T1027.002 Software Packing |
MalwareValak | Valak has used packed DLL payloads. |
| T1027.002 Software Packing |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a variant that is packed with UPX. |
| T1027.002 Software Packing |
MalwareDaserf | A version of Daserf uses the MPRESS packer. |
| T1027.002 Software Packing |
MalwareSysUpdate | SysUpdate has been packed with VMProtect. |
| T1027.002 Software Packing |
MalwareClop | Clop has been packed to help avoid detection. |
| T1027.002 Software Packing |
MalwareLokibot | Lokibot has used several packing methods for obfuscation. |
| T1027.002 Software Packing |
MalwareEgregor | Egregor's payloads are custom-packed, archived and encrypted to prevent analysis. |
| T1027.002 Software Packing |
MalwareMelcoz | Melcoz has been packed with VMProtect and Themida. |
| T1027.002 Software Packing |
MalwareTroll Stealer | Troll Stealer has been delivered as a VMProtect-packed binary. |
| T1027.002 Software Packing |
MalwareAstaroth | Astaroth uses a software packer called Pe123\RPolyCryptor. |
| T1027.002 Software Packing |
MalwareQakBot | QakBot can encrypt and pack malicious payloads. |
| T1027.002 Software Packing |
MalwarejRAT | jRAT payloads have been packed. |
| T1027.002 Software Packing |
MalwareDok | Dok is packed with an UPX executable packer. |
| T1027.002 Software Packing |
MalwareH1N1 | H1N1 uses a custom packing algorithm. |
| T1027.002 Software Packing |
ToolCSPY Downloader | CSPY Downloader has been packed with UPX. |
| T1027.002 Software Packing |
ToolDonut | Donut can generate packed code modules. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.