Real-world descriptions of how a group, tool or campaign used a technique.
195 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareMetamorfo | Metamorfo has encrypted payloads and strings. |
| T1027.013 Encrypted/Encoded File |
MalwareEmbargo | Embargo has encrypted both MDeployer and MS4 Killer payloads with RC4. |
| T1027.013 Encrypted/Encoded File |
MalwarePipeMon | PipeMon modules are stored encrypted on disk. |
| T1027.013 Encrypted/Encoded File |
MalwareMagicRAT | MagicRAT stores base64 encoded command and contorl URLs in a configuraiton file, with each URL prefixed with the value `LR02DPt22R`. |
| T1027.013 Encrypted/Encoded File |
MalwareTINYTYPHON | TINYTYPHON has used XOR with 0x90 to obfuscate its configuration file. |
| T1027.013 Encrypted/Encoded File |
MalwareKONNI | KONNI is heavily obfuscated and includes encrypted configuration files. |
| T1027.013 Encrypted/Encoded File |
MalwareWinnti for Linux | Winnti for Linux can encode its configuration file with single-byte XOR encoding. |
| T1027.013 Encrypted/Encoded File |
MalwareRAPIDPULSE | RAPIDPULSE has the ability to RC4 encrypt and base64 encode decrypted files on compromised servers prior to writing them to stdout. |
| T1027.013 Encrypted/Encoded File |
MalwareJHUHUGIT | Many strings in JHUHUGIT are obfuscated with a XOR algorithm. |
| T1027.013 Encrypted/Encoded File |
MalwareBLUELIGHT | BLUELIGHT has a XOR-encoded payload. |
| T1027.013 Encrypted/Encoded File |
MalwareKGH_SPY | KGH_SPY has used encrypted strings in its installer. |
| T1027.013 Encrypted/Encoded File |
MalwareMicropsia | Micropsia obfuscates the configuration with a custom Base64 and XOR. |
| T1027.013 Encrypted/Encoded File |
MalwareKerrdown | Kerrdown can encrypt, encode, and compress multiple layers of shellcode. |
| T1027.013 Encrypted/Encoded File |
MalwareRedLine Stealer | RedLine Stealer has encrypted and encoded configuration data with Base64 and XOR functions. |
| T1027.013 Encrypted/Encoded File |
MalwareStoneDrill | StoneDrill has obfuscated its module with an alphabet-based table or XOR encryption. |
| T1027.013 Encrypted/Encoded File |
MalwareAttor | Strings in Attor's components are encrypted with a XOR cipher, using a hardcoded key and the configuration data, log files and plugins are encrypted using a hybrid encryption scheme of Blowfish-OFB combined with RSA. |
| T1027.013 Encrypted/Encoded File |
MalwareMosquito | Mosquito’s installer is obfuscated with a custom crypter to obfuscate the installer. |
| T1027.013 Encrypted/Encoded File |
MalwareBlackByte Ransomware | BlackByte Ransomware is distributed as an encrypted payload. |
| T1027.013 Encrypted/Encoded File |
MalwarePHPsert | PHPsert can use multiple obfuscation techniques including XOR encoding, hexadecimal character representation, string concatenation, and randomized variable names. |
| T1027.013 Encrypted/Encoded File |
MalwareStrelaStealer | StrelaStealer uses XOR-encoded strings to obfuscate items. |
| T1027.013 Encrypted/Encoded File |
MalwareGrandoreiro | The Grandoreiro payload has been delivered encrypted with a custom XOR-based algorithm and also as a base64-encoded ZIP file. |
| T1027.013 Encrypted/Encoded File |
MalwareSakula | Sakula uses single-byte XOR obfuscation to obfuscate many of its files. |
| T1027.013 Encrypted/Encoded File |
MalwareZxxZ | ZxxZ has been encoded to avoid detection from static analysis tools. |
| T1027.013 Encrypted/Encoded File |
MalwareCaminho | Caminho can use code flattening for payload obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareShark | Shark can use encrypted and encoded files for C2 configuration. |
| T1027.013 Encrypted/Encoded File |
MalwareBazar | Bazar has used XOR, RSA2, and RC4 encrypted files. |
| T1027.013 Encrypted/Encoded File |
MalwareXLoader | XLoader features encrypted functions using the RC4 algorithm and bytecode operations. |
| T1027.013 Encrypted/Encoded File |
MalwareHiddenFace | HiddenFace has encrypted its payload with AES. |
| T1027.013 Encrypted/Encoded File |
MalwareCorKLOG | CorKLOG has encrypted collected contents using RC4. CorKLOG has also utilized XOR encrypted strings. |
| T1027.013 Encrypted/Encoded File |
MalwareKapeka | Kapeka utilizes AES-256 (CBC mode), XOR, and RSA-2048 encryption schemas for various configuration and other objects. |
| T1027.013 Encrypted/Encoded File |
MalwareSpeakUp | SpeakUp encodes its second-stage payload with Base64. |
| T1027.013 Encrypted/Encoded File |
MalwareLunarMail | LunarMail has used RC4 and AES to encrypt strings and its exfiltration configuration respectively. |
| T1027.013 Encrypted/Encoded File |
MalwareHotCroissant | HotCroissant has encrypted strings with single-byte XOR and base64 encoded RC4. |
| T1027.013 Encrypted/Encoded File |
MalwareREvil | REvil has used encrypted strings and configuration files. |
| T1027.013 Encrypted/Encoded File |
MalwareMilan | Milan can encode files containing information about the targeted system. |
| T1027.013 Encrypted/Encoded File |
MalwareUSBStealer | Most strings in USBStealer are encrypted using 3DES and XOR and reversed. |
| T1027.013 Encrypted/Encoded File |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D encrypts its strings in RSA256 and encodes them in a custom base64 scheme and XOR. |
| T1027.013 Encrypted/Encoded File |
MalwareTaidoor | Taidoor can use encrypted string blocks for obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareSUPERNOVA | SUPERNOVA contained Base64-encoded strings. |
| T1027.013 Encrypted/Encoded File |
MalwareSeasalt | Seasalt obfuscates configuration data. |
| T1027.013 Encrypted/Encoded File |
MalwareRaccoon Stealer | Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection. |
| T1027.013 Encrypted/Encoded File |
MalwareIPsec Helper | IPsec Helper contains an embedded XML configuration file with an encrypted list of command and control servers. These are written to an external configuration file during execution. |
| T1027.013 Encrypted/Encoded File |
MalwareCardinal RAT | Cardinal RAT encodes many of its artifacts and is encrypted (AES-128) when downloaded. |
| T1027.013 Encrypted/Encoded File |
MalwareDanBot | DanBot can Base64 encode its payload. |
| T1027.013 Encrypted/Encoded File |
MalwareGoldenSpy | GoldenSpy's uninstaller has base64-encoded its variables. |
| T1027.013 Encrypted/Encoded File |
MalwareAshTag | The AshTag AshenOrchestrator component payload as been Base64 encoded and embedded with HTML content from the C2 server. |
| T1027.013 Encrypted/Encoded File |
MalwareCarberp | Carberp has used XOR-based encryption to mask C2 server locations within the trojan. |
| T1027.013 Encrypted/Encoded File |
MalwareFunnyDream | FunnyDream can Base64 encode its C2 address stored in a template binary with the `xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_-` or |
| T1027.013 Encrypted/Encoded File |
MalwareROADSWEEP | The ROADSWEEP binary contains RC4 encrypted embedded scripts. |
| T1027.013 Encrypted/Encoded File |
MalwareMOPSLED | MOPSLED can encrypt configuration files with a custom ChaCha20 algorithm. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.