Real-world descriptions of how a group, tool or campaign used a technique.
195 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareRifdoor | Rifdoor has encrypted strings with a single byte XOR algorithm. |
| T1027.013 Encrypted/Encoded File |
MalwareCuckoo Stealer | Cuckoo Stealer strings are XOR-encrypted. |
| T1027.013 Encrypted/Encoded File |
MalwareWastedLocker | The WastedLocker payload includes encrypted strings stored within the .bss section of the binary file. |
| T1027.013 Encrypted/Encoded File |
MalwareVolgmer | A Volgmer variant is encoded using a simple XOR cipher. |
| T1027.013 Encrypted/Encoded File |
MalwareWhisperGate | WhisperGate can Base64 encode strings, store downloaded files in reverse byte order, and use the Eazfuscator tool to obfuscate its third stage. |
| T1027.013 Encrypted/Encoded File |
MalwareZeroT | ZeroT has encrypted its payload with RC4. |
| T1027.013 Encrypted/Encoded File |
MalwareSkidmap | Skidmap has encrypted it's main payload using 3DES. |
| T1027.013 Encrypted/Encoded File |
MalwareSamSam | SamSam has been seen using AES or DES to encrypt payloads and payload components. |
| T1027.013 Encrypted/Encoded File |
MalwareMispadu | Mispadu uses a custom algorithm to obfuscate its internal strings and uses hardcoded keys. Mispadu also uses encoded configuration files and has encoded payloads using Base64. |
| T1027.013 Encrypted/Encoded File |
MalwareRaindrop | Raindrop encrypted its payload using a simple XOR algorithm with a single-byte key. |
| T1027.013 Encrypted/Encoded File |
MalwareRustyWater | RustyWater has encrypted all strings in the code using position independent XOR encryption. |
| T1027.013 Encrypted/Encoded File |
MalwareFysbis | Fysbis has been encrypted using XOR and RC4. |
| T1027.013 Encrypted/Encoded File |
MalwareIcedID | IcedID has utilzed encrypted binaries and base64 encoded strings. |
| T1027.013 Encrypted/Encoded File |
MalwareVERMIN | VERMIN is obfuscated using the obfuscation tool called ConfuserEx. |
| T1027.013 Encrypted/Encoded File |
MalwareDCSrv | DCSrv's configuration is encrypted. |
| T1027.013 Encrypted/Encoded File |
MalwareBOOSTWRITE | BOOSTWRITE has encoded its payloads using a ChaCha stream cipher with a 256-bit key and 64-bit Initialization vector (IV) to evade detection. |
| T1027.013 Encrypted/Encoded File |
MalwareRising Sun | Configuration data used by Rising Sun has been encrypted using an RC4 stream algorithm. |
| T1027.013 Encrypted/Encoded File |
MalwareChrommme | Chrommme can encrypt sections of its code to evade detection. |
| T1027.013 Encrypted/Encoded File |
MalwareSocGholish | SocGholish has single or double Base-64 encoded references to its second-stage server URLs. |
| T1027.013 Encrypted/Encoded File |
MalwareHi-Zor | Hi-Zor uses various XOR techniques to obfuscate its components. |
| T1027.013 Encrypted/Encoded File |
MalwareLightSpy | LightSpy encrypts the C2 configuration file using AES with a static key, while the module `.dylib` files use a rolling one-byte encoding for obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareGoldMax | GoldMax has written AES-encrypted and Base64-encoded configuration files to disk. |
| T1027.013 Encrypted/Encoded File |
MalwareKeyBoy | In one version of KeyBoy, string obfuscation routines were used to hide many of the critical values referenced in the malware. |
| T1027.013 Encrypted/Encoded File |
MalwareHyperBro | HyperBro can be delivered encrypted to a compromised host. |
| T1027.013 Encrypted/Encoded File |
MalwareBeaverTail | BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1027.013 Encrypted/Encoded File |
MalwareSplatDropper | SplatDropper has also utilized XOR encrypted payload. |
| T1027.013 Encrypted/Encoded File |
MalwarePlugX | PlugX has leveraged XOR encryption with the key of 123456789. |
| T1027.013 Encrypted/Encoded File |
MalwareReaver | Reaver encrypts some of its files with XOR. |
| T1027.013 Encrypted/Encoded File |
MalwareBisonal | Bisonal's DLL file and non-malicious decoy file are encrypted with RC4 and some function name strings are obfuscated. |
| T1027.013 Encrypted/Encoded File |
MalwareNOOPLDR | The NOOPLDR payload is encrypted with AES256-CBC. |
| T1027.013 Encrypted/Encoded File |
MalwareLumma Stealer | Lumma Stealer has used AES-encrypted payloads contained within PowerShell scripts. |
| T1027.013 Encrypted/Encoded File |
MalwareRemsec | Some data in Remsec is encrypted using RC5 in CBC mode, AES-CBC with a hardcoded key, RC4, or Salsa20. Some data is also base64-encoded. |
| T1027.013 Encrypted/Encoded File |
MalwareLightNeuron | LightNeuron encrypts its configuration files with AES-256. |
| T1027.013 Encrypted/Encoded File |
MalwareKEYPLUG | KEYPLUG can use a hardcoded one-byte XOR encoded configuration file. |
| T1027.013 Encrypted/Encoded File |
MalwarePureCrypter | PureCrypter has used SmartAssembly and NET-Reactor for string encryption and control flow obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareDarkGate | DarkGate drops an encrypted PE file, pe.bin, and decrypts it during installation. DarkGate also uses custom base64 encoding schemas in later variations to obfuscate payloads. |
| T1027.013 Encrypted/Encoded File |
MalwareNanHaiShu | NanHaiShu encodes files in Base64. |
| T1027.013 Encrypted/Encoded File |
MalwareLockBit 3.0 | The LockBit 3.0 payload includes an encrypted main component. |
| T1027.013 Encrypted/Encoded File |
MalwareFoggyWeb | FoggyWeb has been XOR-encoded. |
| T1027.013 Encrypted/Encoded File |
MalwareHOMEFRY | Some strings in HOMEFRY are obfuscated with XOR x56. |
| T1027.013 Encrypted/Encoded File |
MalwareElise | Elise encrypts several of its files, including configuration files. |
| T1027.013 Encrypted/Encoded File |
MalwareGazer | Gazer logs its actions into files that are encrypted with 3DES. It also uses RSA to encrypt resources. |
| T1027.013 Encrypted/Encoded File |
MalwareLatrodectus | Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings. |
| T1027.013 Encrypted/Encoded File |
MalwareLODEINFO | The LODEINFO loader module contains XOR-encrypted shellcode. |
| T1027.013 Encrypted/Encoded File |
MalwareTYPEFRAME | APIs and strings in some TYPEFRAME variants are RC4 encrypted. Another variant is encoded with XOR. |
| T1027.013 Encrypted/Encoded File |
MalwareSagerunex | Sagerunex can be passed a reference to an XOR-encrypted configuration file at runtime. |
| T1027.013 Encrypted/Encoded File |
MalwareLP-Notes | LP-Notes has used a custom addition-based function and a string stacking function for string encryption. |
| T1027.013 Encrypted/Encoded File |
MalwareBendyBear | BendyBear has encrypted payloads using RC4 and XOR. |
| T1027.013 Encrypted/Encoded File |
MalwareGlassWorm | GlassWorm has leveraged AES-256-CBC encryption to obfuscate its malicious JavaScript payload. GlassWorm has also utilized Base64 encoding to obfuscate the C2 details stored in the Solana memo field. |
| T1027.013 Encrypted/Encoded File |
MalwareUroburos | Uroburos can use AES and CAST-128 encryption to obfuscate resources. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.