Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareEgregor | Egregor's payloads are custom-packed, archived and encrypted to prevent analysis. |
| T1027.002 Software Packing |
MalwareMelcoz | Melcoz has been packed with VMProtect and Themida. |
| T1027.002 Software Packing |
MalwareTroll Stealer | Troll Stealer has been delivered as a VMProtect-packed binary. |
| T1027.002 Software Packing |
MalwareAstaroth | Astaroth uses a software packer called Pe123\RPolyCryptor. |
| T1027.002 Software Packing |
MalwareQakBot | QakBot can encrypt and pack malicious payloads. |
| T1027.002 Software Packing |
MalwarejRAT | jRAT payloads have been packed. |
| T1027.002 Software Packing |
MalwareDok | Dok is packed with an UPX executable packer. |
| T1027.002 Software Packing |
MalwareH1N1 | H1N1 uses a custom packing algorithm. |
| T1027.002 Software Packing |
ToolCSPY Downloader | CSPY Downloader has been packed with UPX. |
| T1027.002 Software Packing |
ToolDonut | Donut can generate packed code modules. |
| T1027.003 Steganography |
MalwarePowerDuke | PowerDuke uses steganography to hide backdoors in PNG files, which are also encrypted using the Tiny Encryption Algorithm (TEA). |
| T1027.003 Steganography |
MalwarePikabot | Pikabot loads a set of PNG images stored in the malware's resources section (RCDATA), each with an encrypted section containing portions of the core Pikabot core module. These sections are loaded and decrypted using a bitwise XOR operation with a hardcoded 32 bit key. |
| T1027.003 Steganography |
MalwareAvenger | Avenger can extract backdoor malware from downloaded images. |
| T1027.003 Steganography |
MalwarePolyglotDuke | PolyglotDuke can use steganography to hide C2 information in images. |
| T1027.003 Steganography |
MalwareRegDuke | RegDuke can hide data in images, including use of the Least Significant Bit (LSB). |
| T1027.003 Steganography |
MalwareProLock | ProLock can use .jpg and .bmp files to store its payload. |
| T1027.003 Steganography |
MalwareRDAT | RDAT can also embed data within a BMP image prior to exfiltration. |
| T1027.003 Steganography |
MalwareOkrum | Okrum's payload is encrypted and embedded within its loader, or within a legitimate PNG file. |
| T1027.003 Steganography |
MalwareDiavol | Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques. |
| T1027.003 Steganography |
MalwareRaindrop | Raindrop used steganography to locate the start of its encoded payload within legitimate 7-Zip code. |
| T1027.003 Steganography |
MalwareIcedID | IcedID has embedded binaries within RC4 encrypted .png files. |
| T1027.003 Steganography |
MalwareObliqueRAT | ObliqueRAT can hide its payload in BMP images hosted on compromised websites. |
| T1027.003 Steganography |
MalwareBandook | Bandook has used .PNG images within a zip file to build the executable. |
| T1027.003 Steganography |
MalwareLiteDuke | LiteDuke has used image files to hide its loader component. |
| T1027.003 Steganography |
MalwareABK | ABK can extract a malicious Portable Executable (PE) from a photo. |
| T1027.003 Steganography |
MalwareRamsay | Ramsay has PE data embedded within JPEG files contained within Word documents. |
| T1027.003 Steganography |
Malwarebuild_downer | build_downer can extract malware from a downloaded JPEG. |
| T1027.003 Steganography |
MalwareBBK | BBK can extract a malicious Portable Executable (PE) from a photo. |
| T1027.003 Steganography |
ToolInvoke-PSImage | Invoke-PSImage can be used to embed a PowerShell script within the pixels of a PNG file. |
| T1027.004 Compile After Delivery |
MalwareDarkWatchman | DarkWatchman has used the |
| T1027.004 Compile After Delivery |
MalwareFoggyWeb | FoggyWeb can compile and execute source code sent to the compromised AD FS server via a specific HTTP POST. |
| T1027.004 Compile After Delivery |
MalwareSamurai | Samurai can compile and execute downloaded modules at runtime. |
| T1027.004 Compile After Delivery |
MalwareCardinal RAT | Cardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code. |
| T1027.004 Compile After Delivery |
MalwarenjRAT | njRAT has used AutoIt to compile the payload and main script into a single executable after delivery. |
| T1027.004 Compile After Delivery |
ToolSliver | Sliver includes functionality to retrieve source code and compile locally prior to execution in victim environments. |
| T1027.005 Indicator Removal from Tools |
MalwareGravityRAT | The author of GravityRAT submitted samples to VirusTotal for testing, showing that the author modified the code to try to hide the DDE object in a different part of the document. |
| T1027.005 Indicator Removal from Tools |
MalwareInvisiMole | InvisiMole has undergone regular technical improvements in an attempt to evade detection. |
| T1027.005 Indicator Removal from Tools |
MalwareCobalt Strike | Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods. |
| T1027.005 Indicator Removal from Tools |
MalwareSUNBURST | SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT. |
| T1027.005 Indicator Removal from Tools |
MalwareDaserf | Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection. |
| T1027.005 Indicator Removal from Tools |
MalwarePenquin | Penquin can remove strings from binaries. |
| T1027.005 Indicator Removal from Tools |
MalwareQakBot | QakBot can make small changes to itself in order to change its checksum and hash value. |
| T1027.005 Indicator Removal from Tools |
MalwareWaterbear | Waterbear can scramble functions not to be executed again with random values. |
| T1027.005 Indicator Removal from Tools |
ToolPowerSploit | PowerSploit's |
| T1027.006 HTML Smuggling |
MalwareEnvyScout | EnvyScout contains JavaScript code that can extract an encoded blob from its HTML body and write it to disk. |
| T1027.006 HTML Smuggling |
MalwareQakBot | QakBot has been delivered in ZIP files via HTML smuggling. |
| T1027.007 Dynamic API Resolution |
MalwareAvosLocker | AvosLocker has used obfuscated API calls that are retrieved by their checksums. |
| T1027.007 Dynamic API Resolution |
MalwareTONESHELL | TONESHELL has utilized a modified DJB2 algorithm to resolve APIs. |
| T1027.007 Dynamic API Resolution |
MalwareCANONSTAGER | CANONSTAGER has utilized custom API hashing to obfuscate the Windows APIs being used. |
| T1027.007 Dynamic API Resolution |
MalwareCLAIMLOADER | CLAIMLOADER has utilized XOR-encrypted API names and native APIs of `LdrLoadDll()` and `LderGetProcedureAddress()` to resolve imports dynamically. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.