ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027×

138 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareInnaputRAT

InnaputRAT uses an 8-byte XOR key to obfuscate API names and other strings contained in the payload.

T1027
Obfuscated Files or Information
MalwareGrimAgent

GrimAgent has used Rotate on Right (RoR) and Rotate on Left (RoL) functionality to encrypt strings.

T1027
Obfuscated Files or Information
MalwareLokibot

Lokibot has obfuscated strings with base64 encoding.

T1027
Obfuscated Files or Information
MalwarePoetRAT

PoetRAT has used a custom encryption scheme for communication between scripts.

T1027
Obfuscated Files or Information
MalwareCoinTicker

CoinTicker initially downloads a hidden encoded file.

T1027
Obfuscated Files or Information
MalwareEbury

Ebury has obfuscated its strings with a simple XOR encryption with a static key.

T1027
Obfuscated Files or Information
MalwareMaze

Maze has decrypted strings and other important information during the encryption process. Maze also calls certain functions dynamically to hinder analysis.

T1027
Obfuscated Files or Information
MalwareComRAT

ComRAT has encrypted its virtual file system using AES-256 in XTS mode.

T1027
Obfuscated Files or Information
MalwarePowerStallion

PowerStallion uses a XOR cipher to encrypt command output written to its OneDrive C2 server.

T1027
Obfuscated Files or Information
MalwareShai-Hulud

Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account. Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes.

T1027
Obfuscated Files or Information
MalwareJPIN

A JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer.

T1027
Obfuscated Files or Information
MalwareHTTPBrowser

HTTPBrowser's code may be obfuscated through structured exception handling and return-oriented programming.

T1027
Obfuscated Files or Information
MalwareKillDisk

KillDisk uses VMProtect to make reverse engineering the malware more difficult.

T1027
Obfuscated Files or Information
MalwareAppleJeus

AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components.

T1027
Obfuscated Files or Information
MalwareSoreFang

SoreFang has the ability to encode and RC6 encrypt data sent to C2.

T1027
Obfuscated Files or Information
MalwareIndustroyer

Industroyer uses heavily obfuscated code in its Windows Notepad backdoor.

T1027
Obfuscated Files or Information
MalwareAgent Tesla

Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings.

T1027
Obfuscated Files or Information
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON has encrypted strings with RC4.

T1027
Obfuscated Files or Information
MalwareShadowPad

ShadowPad has encrypted its payload, a virtual file system, and various files.

T1027
Obfuscated Files or Information
MalwareQakBot

QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells.

T1027
Obfuscated Files or Information
MalwareHancitor

Hancitor has used Base64 to encode malicious links.

T1027
Obfuscated Files or Information
MalwarejRAT

jRAT’s Java payload is encrypted with AES. Additionally, backdoor files are encrypted using DES as a stream cipher. Later variants of jRAT also incorporated AV evasion methods such as Java bytecode obfuscation via the commercial Allatori obfuscation tool.

T1027
Obfuscated Files or Information
MalwareDridex

Dridex's strings are obfuscated using RC4.

T1027
Obfuscated Files or Information
MalwareDenis

Denis obfuscates its code and encrypts the API names.

T1027
Obfuscated Files or Information
MalwareComnie

Comnie uses RC4 and Base64 to obfuscate strings.

T1027
Obfuscated Files or Information
MalwareLizar

Lizar has obfuscated the fingerprint of the victim system, the local IP address, and the Fowler-Noll-V 1 (FNV-1) hash of the local IP address using an XOR operation. The data is then sent to the C2 server.

T1027
Obfuscated Files or Information
MalwareH1N1

H1N1 uses multiple techniques to obfuscate strings, including XOR.

T1027
Obfuscated Files or Information
MalwareSLOWPULSE

SLOWPULSE can hide malicious code in the padding regions between legitimate functions in the Pulse Secure `libdsplibs.so` file.

T1027
Obfuscated Files or Information
MalwareADVSTORESHELL

Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory.

T1027
Obfuscated Files or Information
MalwareSmall Sieve

Small Sieve has the ability to use a custom hex byte swapping encoding scheme combined with an obfuscated Base64 function to protect program strings and Telegram credentials.

T1027
Obfuscated Files or Information
ToolShimRatReporter

ShimRatReporter encrypted gathered information with a combination of shifting and XOR using a static key.

T1027
Obfuscated Files or Information
ToolSliver

Sliver obfuscates configuration and other static files using native Go libraries such as `garble` and `gobfuscate` to inhibit configuration analysis and static detection.

T1027
Obfuscated Files or Information
ToolCARROTBALL

CARROTBALL has used a custom base64 alphabet to decode files.

T1027
Obfuscated Files or Information
ToolBrute Ratel C4

Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory.

T1027
Obfuscated Files or Information
ToolRemcos

Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths. Remcos can also employ control flow flattening to hinder analysis.

T1027
Obfuscated Files or Information
ToolOut1

Out1 has the ability to encode data.

T1027
Obfuscated Files or Information
ToolImminent Monitor

Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2.

T1027
Obfuscated Files or Information
ToolMCMD

MCMD can Base64 encode output strings prior to sending to C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.