ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.013×

195 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareRifdoor

Rifdoor has encrypted strings with a single byte XOR algorithm.

T1027.013
Encrypted/Encoded File
MalwareCuckoo Stealer

Cuckoo Stealer strings are XOR-encrypted.

T1027.013
Encrypted/Encoded File
MalwareWastedLocker

The WastedLocker payload includes encrypted strings stored within the .bss section of the binary file.

T1027.013
Encrypted/Encoded File
MalwareVolgmer

A Volgmer variant is encoded using a simple XOR cipher.

T1027.013
Encrypted/Encoded File
MalwareWhisperGate

WhisperGate can Base64 encode strings, store downloaded files in reverse byte order, and use the Eazfuscator tool to obfuscate its third stage.

T1027.013
Encrypted/Encoded File
MalwareZeroT

ZeroT has encrypted its payload with RC4.

T1027.013
Encrypted/Encoded File
MalwareSkidmap

Skidmap has encrypted it's main payload using 3DES.

T1027.013
Encrypted/Encoded File
MalwareSamSam

SamSam has been seen using AES or DES to encrypt payloads and payload components.

T1027.013
Encrypted/Encoded File
MalwareMispadu

Mispadu uses a custom algorithm to obfuscate its internal strings and uses hardcoded keys.

Mispadu also uses encoded configuration files and has encoded payloads using Base64.

T1027.013
Encrypted/Encoded File
MalwareRaindrop

Raindrop encrypted its payload using a simple XOR algorithm with a single-byte key.

T1027.013
Encrypted/Encoded File
MalwareRustyWater

RustyWater has encrypted all strings in the code using position independent XOR encryption.

T1027.013
Encrypted/Encoded File
MalwareFysbis

Fysbis has been encrypted using XOR and RC4.

T1027.013
Encrypted/Encoded File
MalwareIcedID

IcedID has utilzed encrypted binaries and base64 encoded strings.

T1027.013
Encrypted/Encoded File
MalwareVERMIN

VERMIN is obfuscated using the obfuscation tool called ConfuserEx.

T1027.013
Encrypted/Encoded File
MalwareDCSrv

DCSrv's configuration is encrypted.

T1027.013
Encrypted/Encoded File
MalwareBOOSTWRITE

BOOSTWRITE has encoded its payloads using a ChaCha stream cipher with a 256-bit key and 64-bit Initialization vector (IV) to evade detection.

T1027.013
Encrypted/Encoded File
MalwareRising Sun

Configuration data used by Rising Sun has been encrypted using an RC4 stream algorithm.

T1027.013
Encrypted/Encoded File
MalwareChrommme

Chrommme can encrypt sections of its code to evade detection.

T1027.013
Encrypted/Encoded File
MalwareSocGholish

SocGholish has single or double Base-64 encoded references to its second-stage server URLs.

T1027.013
Encrypted/Encoded File
MalwareHi-Zor

Hi-Zor uses various XOR techniques to obfuscate its components.

T1027.013
Encrypted/Encoded File
MalwareLightSpy

LightSpy encrypts the C2 configuration file using AES with a static key, while the module `.dylib` files use a rolling one-byte encoding for obfuscation.

T1027.013
Encrypted/Encoded File
MalwareGoldMax

GoldMax has written AES-encrypted and Base64-encoded configuration files to disk.

T1027.013
Encrypted/Encoded File
MalwareKeyBoy

In one version of KeyBoy, string obfuscation routines were used to hide many of the critical values referenced in the malware.

T1027.013
Encrypted/Encoded File
MalwareHyperBro

HyperBro can be delivered encrypted to a compromised host.

T1027.013
Encrypted/Encoded File
MalwareBeaverTail

BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions.

T1027.013
Encrypted/Encoded File
MalwareSplatDropper

SplatDropper has also utilized XOR encrypted payload.

T1027.013
Encrypted/Encoded File
MalwarePlugX

PlugX has leveraged XOR encryption with the key of 123456789.

T1027.013
Encrypted/Encoded File
MalwareReaver

Reaver encrypts some of its files with XOR.

T1027.013
Encrypted/Encoded File
MalwareBisonal

Bisonal's DLL file and non-malicious decoy file are encrypted with RC4 and some function name strings are obfuscated.

T1027.013
Encrypted/Encoded File
MalwareNOOPLDR

The NOOPLDR payload is encrypted with AES256-CBC.

T1027.013
Encrypted/Encoded File
MalwareLumma Stealer

Lumma Stealer has used AES-encrypted payloads contained within PowerShell scripts.

T1027.013
Encrypted/Encoded File
MalwareRemsec

Some data in Remsec is encrypted using RC5 in CBC mode, AES-CBC with a hardcoded key, RC4, or Salsa20. Some data is also base64-encoded.

T1027.013
Encrypted/Encoded File
MalwareLightNeuron

LightNeuron encrypts its configuration files with AES-256.

T1027.013
Encrypted/Encoded File
MalwareKEYPLUG

KEYPLUG can use a hardcoded one-byte XOR encoded configuration file.

T1027.013
Encrypted/Encoded File
MalwarePureCrypter

PureCrypter has used SmartAssembly and NET-Reactor for string encryption and control flow obfuscation.

T1027.013
Encrypted/Encoded File
MalwareDarkGate

DarkGate drops an encrypted PE file, pe.bin, and decrypts it during installation. DarkGate also uses custom base64 encoding schemas in later variations to obfuscate payloads.

T1027.013
Encrypted/Encoded File
MalwareNanHaiShu

NanHaiShu encodes files in Base64.

T1027.013
Encrypted/Encoded File
MalwareLockBit 3.0

The LockBit 3.0 payload includes an encrypted main component.

T1027.013
Encrypted/Encoded File
MalwareFoggyWeb

FoggyWeb has been XOR-encoded.

T1027.013
Encrypted/Encoded File
MalwareHOMEFRY

Some strings in HOMEFRY are obfuscated with XOR x56.

T1027.013
Encrypted/Encoded File
MalwareElise

Elise encrypts several of its files, including configuration files.

T1027.013
Encrypted/Encoded File
MalwareGazer

Gazer logs its actions into files that are encrypted with 3DES. It also uses RSA to encrypt resources.

T1027.013
Encrypted/Encoded File
MalwareLatrodectus

Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings.

T1027.013
Encrypted/Encoded File
MalwareLODEINFO

The LODEINFO loader module contains XOR-encrypted shellcode.

T1027.013
Encrypted/Encoded File
MalwareTYPEFRAME

APIs and strings in some TYPEFRAME variants are RC4 encrypted. Another variant is encoded with XOR.

T1027.013
Encrypted/Encoded File
MalwareSagerunex

Sagerunex can be passed a reference to an XOR-encrypted configuration file at runtime.

T1027.013
Encrypted/Encoded File
MalwareLP-Notes

LP-Notes has used a custom addition-based function and a string stacking function for string encryption.

T1027.013
Encrypted/Encoded File
MalwareBendyBear

BendyBear has encrypted payloads using RC4 and XOR.

T1027.013
Encrypted/Encoded File
MalwareGlassWorm

GlassWorm has leveraged AES-256-CBC encryption to obfuscate its malicious JavaScript payload. GlassWorm has also utilized Base64 encoding to obfuscate the C2 details stored in the Solana memo field.

T1027.013
Encrypted/Encoded File
MalwareUroburos

Uroburos can use AES and CAST-128 encryption to obfuscate resources.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.