Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
GroupAPT41 | APT41 used VMProtected binaries in multiple intrusions. |
| T1027 Obfuscated Files or Information |
GroupGamaredon Group | Gamaredon Group has delivered self-extracting 7z archive files within malicious document attachments. Additionally, Gamaredon Group has used an obfuscated .drv file. |
| T1027 Obfuscated Files or Information |
GroupGallmaker | Gallmaker obfuscated shellcode used during execution. |
| T1027 Obfuscated Files or Information |
GroupSandworm Team | Sandworm Team has used Base64 encoding within malware variants. |
| T1027 Obfuscated Files or Information |
GroupMustang Panda | Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadAnomali MUSTANG PANDA October 2019Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018Eset PlugX Korplug Mustang Panda March 2022Proofpoint TA416 Europe March 2022Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Sophos PlugX September 2022Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1027 Obfuscated Files or Information |
GroupRocke | Rocke has modified UPX headers after packing files to break unpackers. |
| T1027 Obfuscated Files or Information |
GroupAPT37 | APT37 obfuscates strings and payloads. |
| T1027 Obfuscated Files or Information |
GroupKe3chang | Ke3chang has used Base64-encoded shellcode strings. |
| T1027 Obfuscated Files or Information |
GroupRedCurl | RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files. |
| T1027 Obfuscated Files or Information |
GroupBackdoorDiplomacy | BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect. |
| T1027 Obfuscated Files or Information |
GroupWindshift | Windshift has used string encoding with floating point calculations. |
| T1027 Obfuscated Files or Information |
GroupAPT-C-36 | APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats. |
| T1027 Obfuscated Files or Information |
GroupEarth Lusca | Earth Lusca used Base64 to encode strings. |
| T1027 Obfuscated Files or Information |
GroupBlackOasis | BlackOasis's first stage shellcode contains a NOP sled with alternative instructions that was likely designed to bypass antivirus tools. |
| T1027 Obfuscated Files or Information |
GroupMoonstone Sleet | Moonstone Sleet delivers encrypted payloads in pieces that are then combined together to form a new portable executable (PE) file during installation. |
| T1027 Obfuscated Files or Information |
MalwareTrickBot | TrickBot uses non-descriptive names to hide functionality. |
| T1027 Obfuscated Files or Information |
MalwareEKANS | EKANS uses encoded strings in its process kill list. |
| T1027 Obfuscated Files or Information |
MalwareSynAck | SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering. |
| T1027 Obfuscated Files or Information |
MalwareBumblebee | Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions. |
| T1027 Obfuscated Files or Information |
MalwareBRICKSTORM | BRICKSTORM has utilized Go libraries to include Garble to obfuscate code. |
| T1027 Obfuscated Files or Information |
MalwareAmadey | Amadey has obfuscated strings such as antivirus vendor names, domains, files, and others. |
| T1027 Obfuscated Files or Information |
MalwareOrz | Some Orz strings are base64 encoded, such as the embedded DLL known as MockDll. |
| T1027 Obfuscated Files or Information |
MalwareNOKKI | NOKKI uses Base64 encoding for strings. |
| T1027 Obfuscated Files or Information |
MalwareAvosLocker | AvosLocker has used XOR-encoded strings. |
| T1027 Obfuscated Files or Information |
MalwareCOATHANGER | COATHANGER can store obfuscated configuration information in the last 56 bytes of the file `/date/.bd.key/preload.so`. |
| T1027 Obfuscated Files or Information |
MalwareSardonic | Sardonic can use certain ConfuserEx features for obfuscation and can be encoded in a base64 string. |
| T1027 Obfuscated Files or Information |
MalwareMatryoshka | Matryoshka obfuscates API function names using a substitute cipher combined with Base64 encoding. |
| T1027 Obfuscated Files or Information |
MalwareEcipekac | Ecipekac can use XOR, AES, and DES to encrypt loader shellcode. |
| T1027 Obfuscated Files or Information |
MalwareAppleSeed | AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls. |
| T1027 Obfuscated Files or Information |
MalwareBUSHWALK | BUSHWALK can encrypt the resulting data generated from C2 commands with RC4. |
| T1027 Obfuscated Files or Information |
MalwareNETWIRE | NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names. |
| T1027 Obfuscated Files or Information |
MalwareBOOKWORM | BOOKWORM has been delivered using self-extracting RAR archives. |
| T1027 Obfuscated Files or Information |
MalwareOLDBAIT | OLDBAIT obfuscates internal strings and unpacks them at startup. |
| T1027 Obfuscated Files or Information |
MalwareTEARDROP | TEARDROP created and read from a file with a fake JPG header, and its payload was encrypted with a simple rotating XOR cipher. |
| T1027 Obfuscated Files or Information |
MalwareTurian | Turian can use VMProtect for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareAction RAT | Action RAT's commands, strings, and domains can be Base64 encoded within the payload. |
| T1027 Obfuscated Files or Information |
MalwarePUBLOAD | PUBLOAD has obfuscated DLL names using the ror13AddHash32 algorithm. |
| T1027 Obfuscated Files or Information |
MalwareGootloader | The Gootloader first stage script is obfuscated using random alpha numeric strings. |
| T1027 Obfuscated Files or Information |
MalwarePolyglotDuke | PolyglotDuke can custom encrypt strings. |
| T1027 Obfuscated Files or Information |
MalwareSombRAT | SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data. |
| T1027 Obfuscated Files or Information |
MalwareSnip3 | Snip3 has the ability to obfuscate strings using XOR encryption. |
| T1027 Obfuscated Files or Information |
MalwareRegDuke | RegDuke can use control-flow flattening or the commercially available .NET Reactor for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareInvisiMole | InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format. |
| T1027 Obfuscated Files or Information |
MalwareP.A.S. Webshell | P.A.S. Webshell can use encryption and base64 encoding to hide strings and to enforce access control once deployed. |
| T1027 Obfuscated Files or Information |
MalwareConti | Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls. |
| T1027 Obfuscated Files or Information |
MalwareRaspberry Robin | Raspberry Robin uses mixed-case letters for filenames and commands to evade detection. |
| T1027 Obfuscated Files or Information |
MalwareDiavol | Diavol has Base64 encoded the RSA public key used for encrypting files. |
| T1027 Obfuscated Files or Information |
MalwareSiloscape | Siloscape itself is obfuscated and uses obfuscated API calls. |
| T1027 Obfuscated Files or Information |
MalwareRustyWater | RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function. |
| T1027 Obfuscated Files or Information |
MalwareHTTPTroy | HTTPTroy has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions to hinder analysis and detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.