Real-world descriptions of how a group, tool or campaign used a technique.
138 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareInnaputRAT | InnaputRAT uses an 8-byte XOR key to obfuscate API names and other strings contained in the payload. |
| T1027 Obfuscated Files or Information |
MalwareGrimAgent | GrimAgent has used Rotate on Right (RoR) and Rotate on Left (RoL) functionality to encrypt strings. |
| T1027 Obfuscated Files or Information |
MalwareLokibot | Lokibot has obfuscated strings with base64 encoding. |
| T1027 Obfuscated Files or Information |
MalwarePoetRAT | PoetRAT has used a custom encryption scheme for communication between scripts. |
| T1027 Obfuscated Files or Information |
MalwareCoinTicker | CoinTicker initially downloads a hidden encoded file. |
| T1027 Obfuscated Files or Information |
MalwareEbury | Ebury has obfuscated its strings with a simple XOR encryption with a static key. |
| T1027 Obfuscated Files or Information |
MalwareMaze | Maze has decrypted strings and other important information during the encryption process. Maze also calls certain functions dynamically to hinder analysis. |
| T1027 Obfuscated Files or Information |
MalwareComRAT | ComRAT has encrypted its virtual file system using AES-256 in XTS mode. |
| T1027 Obfuscated Files or Information |
MalwarePowerStallion | PowerStallion uses a XOR cipher to encrypt command output written to its OneDrive C2 server. |
| T1027 Obfuscated Files or Information |
MalwareShai-Hulud | Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account. Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes. |
| T1027 Obfuscated Files or Information |
MalwareJPIN | A JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer. |
| T1027 Obfuscated Files or Information |
MalwareHTTPBrowser | HTTPBrowser's code may be obfuscated through structured exception handling and return-oriented programming. |
| T1027 Obfuscated Files or Information |
MalwareKillDisk | KillDisk uses VMProtect to make reverse engineering the malware more difficult. |
| T1027 Obfuscated Files or Information |
MalwareAppleJeus | AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components. |
| T1027 Obfuscated Files or Information |
MalwareSoreFang | SoreFang has the ability to encode and RC6 encrypt data sent to C2. |
| T1027 Obfuscated Files or Information |
MalwareIndustroyer | Industroyer uses heavily obfuscated code in its Windows Notepad backdoor. |
| T1027 Obfuscated Files or Information |
MalwareAgent Tesla | Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings. |
| T1027 Obfuscated Files or Information |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON has encrypted strings with RC4. |
| T1027 Obfuscated Files or Information |
MalwareShadowPad | ShadowPad has encrypted its payload, a virtual file system, and various files. |
| T1027 Obfuscated Files or Information |
MalwareQakBot | QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells. |
| T1027 Obfuscated Files or Information |
MalwareHancitor | Hancitor has used Base64 to encode malicious links. |
| T1027 Obfuscated Files or Information |
MalwarejRAT | jRAT’s Java payload is encrypted with AES. Additionally, backdoor files are encrypted using DES as a stream cipher. Later variants of jRAT also incorporated AV evasion methods such as Java bytecode obfuscation via the commercial Allatori obfuscation tool. |
| T1027 Obfuscated Files or Information |
MalwareDridex | Dridex's strings are obfuscated using RC4. |
| T1027 Obfuscated Files or Information |
MalwareDenis | Denis obfuscates its code and encrypts the API names. |
| T1027 Obfuscated Files or Information |
MalwareComnie | Comnie uses RC4 and Base64 to obfuscate strings. |
| T1027 Obfuscated Files or Information |
MalwareLizar | Lizar has obfuscated the fingerprint of the victim system, the local IP address, and the Fowler-Noll-V 1 (FNV-1) hash of the local IP address using an XOR operation. The data is then sent to the C2 server. |
| T1027 Obfuscated Files or Information |
MalwareH1N1 | H1N1 uses multiple techniques to obfuscate strings, including XOR. |
| T1027 Obfuscated Files or Information |
MalwareSLOWPULSE | SLOWPULSE can hide malicious code in the padding regions between legitimate functions in the Pulse Secure `libdsplibs.so` file. |
| T1027 Obfuscated Files or Information |
MalwareADVSTORESHELL | Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory. |
| T1027 Obfuscated Files or Information |
MalwareSmall Sieve | Small Sieve has the ability to use a custom hex byte swapping encoding scheme combined with an obfuscated Base64 function to protect program strings and Telegram credentials. |
| T1027 Obfuscated Files or Information |
ToolShimRatReporter | ShimRatReporter encrypted gathered information with a combination of shifting and XOR using a static key. |
| T1027 Obfuscated Files or Information |
ToolSliver | Sliver obfuscates configuration and other static files using native Go libraries such as `garble` and `gobfuscate` to inhibit configuration analysis and static detection. |
| T1027 Obfuscated Files or Information |
ToolCARROTBALL | CARROTBALL has used a custom base64 alphabet to decode files. |
| T1027 Obfuscated Files or Information |
ToolBrute Ratel C4 | Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory. |
| T1027 Obfuscated Files or Information |
ToolRemcos | Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths. Remcos can also employ control flow flattening to hinder analysis. |
| T1027 Obfuscated Files or Information |
ToolOut1 | Out1 has the ability to encode data. |
| T1027 Obfuscated Files or Information |
ToolImminent Monitor | Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2. |
| T1027 Obfuscated Files or Information |
ToolMCMD | MCMD can Base64 encode output strings prior to sending to C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.