Real-world descriptions of how a group, tool or campaign used a technique.
301 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
MalwareLucifer | Lucifer can decrypt its C2 address upon execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGLASSTOKEN | GLASSTOKEN has the ability to decode hexadecimal and Base64 C2 requests. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBOOSTWRITE | BOOSTWRITE has used a a 32-byte long multi-XOR key to decode data inside its payload. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRising Sun | Rising Sun has decrypted itself using a single-byte XOR scheme. Additionally, Rising Sun can decrypt its configuration data at runtime. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareShimRat | ShimRat has decompressed its core DLL using shellcode once an impersonated antivirus component was running on a system. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareChrommme | Chrommme can decrypt its encrypted internal code. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAvaddon | Avaddon has decrypted encrypted strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGreen Lambert | Green Lambert can use multiple custom routines to decrypt strings prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareISMInjector | ISMInjector uses the |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePUNCHBUGGY | PUNCHBUGGY has used PowerShell to decode base64-encoded assembly. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGoldMax | GoldMax has decoded and decrypted the configuration file when executed. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCostaBricks | CostaBricks has the ability to use bytecode to decrypt embedded payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLIGHTWIRE | LIGHTWIRE can RC4 decrypt and Base64 decode C2 commands. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHyperBro | HyperBro can unpack and decrypt its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePteranodon | Pteranodon can decrypt encrypted data strings prior to using them. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDarkTortilla | DarkTortilla can decrypt its payload and associated configuration elements using the Rijndael cipher. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareROKRAT | ROKRAT can decrypt strings using the victim's hostname as the key. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSplatDropper | SplatDropper has decoded XOR encrypted payload. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBabuk | Babuk has the ability to unpack itself into memory using XOR. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareExbyte | Exbyte decodes and decrypts data stored in the configuration file with a key provided on the command line during execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDarkWatchman | DarkWatchman has the ability to self-extract as a RAR archive. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDyre | Dyre decrypts resources needed for targeting the victim. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLunarLoader | LunarLoader can deobfuscate files containing the next stages in the infection chain. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBBSRAT | BBSRAT uses Expand to decompress a CAB file into executable content. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePlugX | PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBisonal | Bisonal has decoded strings in the malware using XOR and RC4. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNOOPLDR | NOOPLDR can decrypt its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLumma Stealer | Lumma Stealer has used Base64-encoded content during execution, decoded via PowerShell. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLightNeuron | LightNeuron has used AES and XOR to decrypt configuration files and commands. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKEYPLUG | KEYPLUG can decode its configuration file to determine C2 protocols. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareClambling | Clambling can deobfuscate its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePureCrypter | PureCrypter can decrypt downloaded resources and parse internal files to determine its settings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDarkGate | DarkGate installation includes binary code stored in a file located in a hidden directory, such as |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMongall | Mongall has the ability to decrypt its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLockBit 3.0 | The LockBit 3.0 payload is decrypted at runtime. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFoggyWeb | FoggyWeb can be decrypted in memory using a Lightweight Encryption Algorithm (LEA)-128 key and decoded using a XOR key. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNetwalker | Netwalker's PowerShell script can decode and decrypt multiple layers of obfuscation, leading to the Netwalker DLL being loaded into memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTSCookie | TSCookie has the ability to decrypt, load, and execute a DLL and its resources. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLatrodectus | Latrodectus has the ability to deobfuscate encrypted strings. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSaint Bot | Saint Bot can deobfuscate strings and files for execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareChaes | Chaes has decrypted an AES encrypted binary file to trigger the download of other files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCharmPower | CharmPower can decrypt downloaded modules prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMuddyViper | MuddyViper has decrypted the embedded HackBrowserData tool prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTYPEFRAME | One TYPEFRAME variant decrypts an archive using an RC4 key, then decompresses and installs the decrypted malicious DLL module. Another variant decodes the embedded file by XORing it with the value "0x35". |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBundlore | Bundlore has used |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFooder | Fooder has decrypted payloads using the WinCrypt API and the AES key. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMori | Mori can resolve networking APIs from strings that are ADD-encrypted. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareQUADAGENT | QUADAGENT uses AES and a preshared key to decrypt the custom Base64 routine used to encode strings and scripts. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSagerunex | Sagerunex uses a custom decryption routine to unpack itself during installation. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLP-Notes | LP-Notes has decrypted strings with lengths ranging from 15 to 19 characters using the same decryption key for each string. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.