ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareBoxCaon

BoxCaon used the "StackStrings" obfuscation technique to hide malicious functionalities.

T1027
Obfuscated Files or Information
MalwareNightClub

NightClub can obfuscate strings using the congruential generator `(LCG): staten+1 = (690069 × staten + 1) mod 232`.

T1027
Obfuscated Files or Information
MalwareSDBbot

SDBbot has the ability to XOR the strings for its installer component with a hardcoded 128 byte key.

T1027
Obfuscated Files or Information
MalwareRTM

RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm.

T1027
Obfuscated Files or Information
MalwareSodaMaster

SodaMaster can use "stackstrings" for obfuscation.

T1027
Obfuscated Files or Information
MalwareStrelaStealer

StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives.

T1027
Obfuscated Files or Information
MalwareDrovorub

Drovorub has used XOR encrypted payloads in WebSocket client to server messages.

T1027
Obfuscated Files or Information
MalwareKobalos

Kobalos encrypts all strings using RC4 and bundles all functionality into a single function call.

T1027
Obfuscated Files or Information
MalwareRyuk

Ryuk can use anti-disassembly and code transformation obfuscation techniques.

T1027
Obfuscated Files or Information
MalwareFinal1stspy

Final1stspy obfuscates strings with base64 encoding.

T1027
Obfuscated Files or Information
MalwareFinFisher

FinFisher is heavily obfuscated in many ways, including through the use of spaghetti code in its functions in an effort to confuse disassembly programs. It also uses a custom XOR algorithm to obfuscate code.

T1027
Obfuscated Files or Information
MalwareCobalt Strike

Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata.

T1027
Obfuscated Files or Information
MalwareSUNBURST

SUNBURST obfuscated collected system information using a FNV-1a + XOR algorithm.

T1027
Obfuscated Files or Information
MalwareValak

Valak has the ability to base64 encode and XOR encrypt strings.

T1027
Obfuscated Files or Information
MalwareSamurai

Samurai can encrypt the names of requested APIs.

T1027
Obfuscated Files or Information
MalwarePoisonIvy

PoisonIvy hides any strings related to its own indicators of compromise.

T1027
Obfuscated Files or Information
MalwareNanoCore

NanoCore’s plugins were obfuscated with Eazfuscater.NET 3.3.

T1027
Obfuscated Files or Information
MalwareTajMahal

TajMahal has used an encrypted Virtual File System to store plugins.

T1027
Obfuscated Files or Information
MalwareDaserf

Daserf uses encrypted Windows APIs and also encrypts data using the alternative base64+RC4 or the Caesar cipher.

T1027
Obfuscated Files or Information
MalwareCarbon

Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm.

T1027
Obfuscated Files or Information
MalwarePisloader

Pisloader obfuscates files by splitting strings into smaller sub-strings and including "garbage" strings that are never used. The malware also uses return-oriented programming (ROP) technique and single-byte XOR to obfuscate data.

T1027
Obfuscated Files or Information
MalwareRamsay

Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. Ramsay can also embed information within document footers.

T1027
Obfuscated Files or Information
MalwarePillowmint

Pillowmint has obfuscated the AES key used for encryption.

T1027
Obfuscated Files or Information
MalwareSUNSPOT

SUNSPOT encrypted log entries it collected with the stream cipher RC4 using a hard-coded key. It also uses AES128-CBC encrypted blobs for SUNBURST source code and data extracted from the SolarWinds Orion <MsBuild.exe</code> process.

T1027
Obfuscated Files or Information
MalwareANELLDR

ANELLDR code implements anti-analysis techniques including control flow flattening and Mixed Boolean Arithmetic (MBA).

T1027
Obfuscated Files or Information
MalwareBoomBox

BoomBox can encrypt data using AES prior to exfiltration.

T1027
Obfuscated Files or Information
MalwarePUNCHTRACK

PUNCHTRACK is loaded and executed by a highly obfuscated launcher.

T1027
Obfuscated Files or Information
MalwareInnaputRAT

InnaputRAT uses an 8-byte XOR key to obfuscate API names and other strings contained in the payload.

T1027
Obfuscated Files or Information
MalwareGrimAgent

GrimAgent has used Rotate on Right (RoR) and Rotate on Left (RoL) functionality to encrypt strings.

T1027
Obfuscated Files or Information
MalwareLokibot

Lokibot has obfuscated strings with base64 encoding.

T1027
Obfuscated Files or Information
MalwarePoetRAT

PoetRAT has used a custom encryption scheme for communication between scripts.

T1027
Obfuscated Files or Information
MalwareCoinTicker

CoinTicker initially downloads a hidden encoded file.

T1027
Obfuscated Files or Information
MalwareEbury

Ebury has obfuscated its strings with a simple XOR encryption with a static key.

T1027
Obfuscated Files or Information
MalwareMaze

Maze has decrypted strings and other important information during the encryption process. Maze also calls certain functions dynamically to hinder analysis.

T1027
Obfuscated Files or Information
MalwareComRAT

ComRAT has encrypted its virtual file system using AES-256 in XTS mode.

T1027
Obfuscated Files or Information
MalwarePowerStallion

PowerStallion uses a XOR cipher to encrypt command output written to its OneDrive C2 server.

T1027
Obfuscated Files or Information
MalwareShai-Hulud

Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account. Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes.

T1027
Obfuscated Files or Information
MalwareJPIN

A JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer.

T1027
Obfuscated Files or Information
MalwareHTTPBrowser

HTTPBrowser's code may be obfuscated through structured exception handling and return-oriented programming.

T1027
Obfuscated Files or Information
MalwareKillDisk

KillDisk uses VMProtect to make reverse engineering the malware more difficult.

T1027
Obfuscated Files or Information
MalwareAppleJeus

AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components.

T1027
Obfuscated Files or Information
MalwareSoreFang

SoreFang has the ability to encode and RC6 encrypt data sent to C2.

T1027
Obfuscated Files or Information
MalwareIndustroyer

Industroyer uses heavily obfuscated code in its Windows Notepad backdoor.

T1027
Obfuscated Files or Information
MalwareAgent Tesla

Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings.

T1027
Obfuscated Files or Information
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON has encrypted strings with RC4.

T1027
Obfuscated Files or Information
MalwareShadowPad

ShadowPad has encrypted its payload, a virtual file system, and various files.

T1027
Obfuscated Files or Information
MalwareQakBot

QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells.

T1027
Obfuscated Files or Information
MalwareHancitor

Hancitor has used Base64 to encode malicious links.

T1027
Obfuscated Files or Information
MalwarejRAT

jRAT’s Java payload is encrypted with AES. Additionally, backdoor files are encrypted using DES as a stream cipher. Later variants of jRAT also incorporated AV evasion methods such as Java bytecode obfuscation via the commercial Allatori obfuscation tool.

T1027
Obfuscated Files or Information
MalwareDridex

Dridex's strings are obfuscated using RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.