Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwarePolyglotDuke | PolyglotDuke can custom encrypt strings. |
| T1027 Obfuscated Files or Information |
MalwareSombRAT | SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data. |
| T1027 Obfuscated Files or Information |
MalwareSnip3 | Snip3 has the ability to obfuscate strings using XOR encryption. |
| T1027 Obfuscated Files or Information |
MalwareRegDuke | RegDuke can use control-flow flattening or the commercially available .NET Reactor for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareInvisiMole | InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format. |
| T1027 Obfuscated Files or Information |
MalwareP.A.S. Webshell | P.A.S. Webshell can use encryption and base64 encoding to hide strings and to enforce access control once deployed. |
| T1027 Obfuscated Files or Information |
MalwareConti | Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls. |
| T1027 Obfuscated Files or Information |
MalwareRaspberry Robin | Raspberry Robin uses mixed-case letters for filenames and commands to evade detection. |
| T1027 Obfuscated Files or Information |
MalwareDiavol | Diavol has Base64 encoded the RSA public key used for encrypting files. |
| T1027 Obfuscated Files or Information |
MalwareSiloscape | Siloscape itself is obfuscated and uses obfuscated API calls. |
| T1027 Obfuscated Files or Information |
MalwareRustyWater | RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function. |
| T1027 Obfuscated Files or Information |
MalwareHTTPTroy | HTTPTroy has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions to hinder analysis and detection. |
| T1027 Obfuscated Files or Information |
MalwareKazuar | Kazuar is obfuscated using the open source ConfuserEx protector. Kazuar also obfuscates the name of created files/folders/mutexes and encrypts debug messages written to log files using the Rijndael cipher. |
| T1027 Obfuscated Files or Information |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use a custom Base64 alphabet to encode an API decryption key. |
| T1027 Obfuscated Files or Information |
MalwareFatDuke | FatDuke can use base64 encoding, string stacking, and opaque predicates for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareDRATzarus | DRATzarus can be partly encrypted with XOR. |
| T1027 Obfuscated Files or Information |
MalwareSHOTPUT | SHOTPUT is obscured using XOR encoding and appended to a valid GIF file. |
| T1027 Obfuscated Files or Information |
MalwareAvaddon | Avaddon has used encrypted strings. |
| T1027 Obfuscated Files or Information |
MalwareConficker | Conficker has obfuscated its code to prevent its removal from host machines. |
| T1027 Obfuscated Files or Information |
MalwareFlagpro | Flagpro has been delivered within ZIP or RAR password-protected archived files. |
| T1027 Obfuscated Files or Information |
MalwareGreen Lambert | Green Lambert has encrypted strings. |
| T1027 Obfuscated Files or Information |
MalwareISMInjector | ISMInjector is obfuscated with the off-the-shelf SmartAssembly .NET obfuscator created by red-gate.com. |
| T1027 Obfuscated Files or Information |
MalwarePUNCHBUGGY | PUNCHBUGGY has hashed most its code's functions and encrypted payloads with base64 and XOR. |
| T1027 Obfuscated Files or Information |
MalwarePOSHSPY | POSHSPY appends a file signature header (randomly selected from six file types) to encrypted data prior to upload or download. |
| T1027 Obfuscated Files or Information |
MalwareMiniDuke | MiniDuke can use control flow flattening to obscure code. |
| T1027 Obfuscated Files or Information |
MalwareAnchor | Anchor has obfuscated code with stack strings and string encryption. |
| T1027 Obfuscated Files or Information |
MalwareDarkTortilla | DarkTortilla has been obfuscated with the DeepSea .NET and ConfuserEx code obfuscators. |
| T1027 Obfuscated Files or Information |
MalwareROKRAT | ROKRAT can encrypt data prior to exfiltration by using an RSA public key. |
| T1027 Obfuscated Files or Information |
MalwareCORESHELL | CORESHELL obfuscates strings using a custom stream cipher. |
| T1027 Obfuscated Files or Information |
MalwarePlugX | PlugX can use API hashing and modify the names of strings to evade detection. |
| T1027 Obfuscated Files or Information |
MalwareNOOPLDR | NOOPLDR can use control flow flattening to help hide malicious code. |
| T1027 Obfuscated Files or Information |
MalwareLumma Stealer | Lumma Stealer has used SmartAssembly to obfuscate .NET payloads. |
| T1027 Obfuscated Files or Information |
MalwareDustySky | The DustySky dropper uses a function to obfuscate the name of functions and other parts of the malware. |
| T1027 Obfuscated Files or Information |
MalwareEpic | Epic heavily obfuscates its code to make analysis more difficult. |
| T1027 Obfuscated Files or Information |
MalwareCuba | Cuba has used multiple layers of obfuscation to avoid analysis, including its Base64 encoded payload. |
| T1027 Obfuscated Files or Information |
MalwareClambling | The Clambling executable has been obfuscated when dropped on a compromised host. |
| T1027 Obfuscated Files or Information |
MalwareDarkGate | DarkGate uses a hard-coded string as a seed, along with the victim machine hardware identifier and input text, to generate a unique string used as an internal mutex value to evade static detection based on mutexes. |
| T1027 Obfuscated Files or Information |
MalwareSVCReady | SVCReady can encrypt victim data with an RC4 cipher. |
| T1027 Obfuscated Files or Information |
MalwareCarbanak | Carbanak encrypts strings to make analysis more difficult. |
| T1027 Obfuscated Files or Information |
MalwareXTunnel | A version of XTunnel introduced in July 2015 obfuscated the binary using opaque predicates and other techniques in a likely attempt to obfuscate it and bypass security products. |
| T1027 Obfuscated Files or Information |
MalwareHydraq | Hydraq uses basic obfuscation in the form of spaghetti code. |
| T1027 Obfuscated Files or Information |
MalwareSaint Bot | Saint Bot has been obfuscated to help avoid detection. |
| T1027 Obfuscated Files or Information |
MalwareLODEINFO | LODEINFO has used control flow flattening to obfuscate code. |
| T1027 Obfuscated Files or Information |
MalwareBundlore | Bundlore has obfuscated data with base64, AES, RC4, and bz2. |
| T1027 Obfuscated Files or Information |
MalwareFooder | Fooder has stored its embedded payload in encrypted form within the binary, using a hardcoded key modified at runtime to produce the AES decryption key. |
| T1027 Obfuscated Files or Information |
MalwareTrojan.Karagany | Trojan.Karagany can base64 encode and AES-128-CBC encrypt data prior to transmission. |
| T1027 Obfuscated Files or Information |
MalwareShamoon | Shamoon contains base64-encoded strings. |
| T1027 Obfuscated Files or Information |
MalwareBPFDoor | BPFDoor can require a password to activate the backdoor and uses RC4 encryption or static library encryption `libtomcrypt`. |
| T1027 Obfuscated Files or Information |
MalwareOopsIE | OopsIE uses the Confuser protector to obfuscate an embedded .Net Framework assembly used for C2. OopsIE also encodes collected data in hexadecimal format before writing to files on disk and obfuscates strings. |
| T1027 Obfuscated Files or Information |
MalwareStreamEx | StreamEx obfuscates some commands by using statically programmed fragments of strings when starting a DLL. It also uses a one-byte xor against 0x91 to encode configuration data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.