ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareEgregor

Egregor's payloads are custom-packed, archived and encrypted to prevent analysis.

T1027.002
Software Packing
MalwareMelcoz

Melcoz has been packed with VMProtect and Themida.

T1027.002
Software Packing
MalwareTroll Stealer

Troll Stealer has been delivered as a VMProtect-packed binary.

T1027.002
Software Packing
MalwareAstaroth

Astaroth uses a software packer called Pe123\RPolyCryptor.

T1027.002
Software Packing
MalwareQakBot

QakBot can encrypt and pack malicious payloads.

T1027.002
Software Packing
MalwarejRAT

jRAT payloads have been packed.

T1027.002
Software Packing
MalwareDok

Dok is packed with an UPX executable packer.

T1027.002
Software Packing
MalwareH1N1

H1N1 uses a custom packing algorithm.

T1027.002
Software Packing
ToolCSPY Downloader

CSPY Downloader has been packed with UPX.

T1027.002
Software Packing
ToolDonut

Donut can generate packed code modules.

T1027.003
Steganography
MalwarePowerDuke

PowerDuke uses steganography to hide backdoors in PNG files, which are also encrypted using the Tiny Encryption Algorithm (TEA).

T1027.003
Steganography
MalwarePikabot

Pikabot loads a set of PNG images stored in the malware's resources section (RCDATA), each with an encrypted section containing portions of the core Pikabot core module. These sections are loaded and decrypted using a bitwise XOR operation with a hardcoded 32 bit key.

T1027.003
Steganography
MalwareAvenger

Avenger can extract backdoor malware from downloaded images.

T1027.003
Steganography
MalwarePolyglotDuke

PolyglotDuke can use steganography to hide C2 information in images.

T1027.003
Steganography
MalwareRegDuke

RegDuke can hide data in images, including use of the Least Significant Bit (LSB).

T1027.003
Steganography
MalwareProLock

ProLock can use .jpg and .bmp files to store its payload.

T1027.003
Steganography
MalwareRDAT

RDAT can also embed data within a BMP image prior to exfiltration.

T1027.003
Steganography
MalwareOkrum

Okrum's payload is encrypted and embedded within its loader, or within a legitimate PNG file.

T1027.003
Steganography
MalwareDiavol

Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques.

T1027.003
Steganography
MalwareRaindrop

Raindrop used steganography to locate the start of its encoded payload within legitimate 7-Zip code.

T1027.003
Steganography
MalwareIcedID

IcedID has embedded binaries within RC4 encrypted .png files.

T1027.003
Steganography
MalwareObliqueRAT

ObliqueRAT can hide its payload in BMP images hosted on compromised websites.

T1027.003
Steganography
MalwareBandook

Bandook has used .PNG images within a zip file to build the executable.

T1027.003
Steganography
MalwareLiteDuke

LiteDuke has used image files to hide its loader component.

T1027.003
Steganography
MalwareABK

ABK can extract a malicious Portable Executable (PE) from a photo.

T1027.003
Steganography
MalwareRamsay

Ramsay has PE data embedded within JPEG files contained within Word documents.

T1027.003
Steganography
Malwarebuild_downer

build_downer can extract malware from a downloaded JPEG.

T1027.003
Steganography
MalwareBBK

BBK can extract a malicious Portable Executable (PE) from a photo.

T1027.003
Steganography
ToolInvoke-PSImage

Invoke-PSImage can be used to embed a PowerShell script within the pixels of a PNG file.

T1027.004
Compile After Delivery
MalwareDarkWatchman

DarkWatchman has used the csc.exe tool to compile a C# executable.

T1027.004
Compile After Delivery
MalwareFoggyWeb

FoggyWeb can compile and execute source code sent to the compromised AD FS server via a specific HTTP POST.

T1027.004
Compile After Delivery
MalwareSamurai

Samurai can compile and execute downloaded modules at runtime.

T1027.004
Compile After Delivery
MalwareCardinal RAT

Cardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code.

T1027.004
Compile After Delivery
MalwarenjRAT

njRAT has used AutoIt to compile the payload and main script into a single executable after delivery.

T1027.004
Compile After Delivery
ToolSliver

Sliver includes functionality to retrieve source code and compile locally prior to execution in victim environments.

T1027.005
Indicator Removal from Tools
MalwareGravityRAT

The author of GravityRAT submitted samples to VirusTotal for testing, showing that the author modified the code to try to hide the DDE object in a different part of the document.

T1027.005
Indicator Removal from Tools
MalwareInvisiMole

InvisiMole has undergone regular technical improvements in an attempt to evade detection.

T1027.005
Indicator Removal from Tools
MalwareCobalt Strike

Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods.

T1027.005
Indicator Removal from Tools
MalwareSUNBURST

SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT.

T1027.005
Indicator Removal from Tools
MalwareDaserf

Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection.

T1027.005
Indicator Removal from Tools
MalwarePenquin

Penquin can remove strings from binaries.

T1027.005
Indicator Removal from Tools
MalwareQakBot

QakBot can make small changes to itself in order to change its checksum and hash value.

T1027.005
Indicator Removal from Tools
MalwareWaterbear

Waterbear can scramble functions not to be executed again with random values.

T1027.005
Indicator Removal from Tools
ToolPowerSploit

PowerSploit's Find-AVSignature AntivirusBypass module can be used to locate single byte anti-virus signatures.

T1027.006
HTML Smuggling
MalwareEnvyScout

EnvyScout contains JavaScript code that can extract an encoded blob from its HTML body and write it to disk.

T1027.006
HTML Smuggling
MalwareQakBot

QakBot has been delivered in ZIP files via HTML smuggling.

T1027.007
Dynamic API Resolution
MalwareAvosLocker

AvosLocker has used obfuscated API calls that are retrieved by their checksums.

T1027.007
Dynamic API Resolution
MalwareTONESHELL

TONESHELL has utilized a modified DJB2 algorithm to resolve APIs.

T1027.007
Dynamic API Resolution
MalwareCANONSTAGER

CANONSTAGER has utilized custom API hashing to obfuscate the Windows APIs being used.

T1027.007
Dynamic API Resolution
MalwareCLAIMLOADER

CLAIMLOADER has utilized XOR-encrypted API names and native APIs of `LdrLoadDll()` and `LderGetProcedureAddress()` to resolve imports dynamically.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.