ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupAPT41

APT41 used VMProtected binaries in multiple intrusions.

T1027
Obfuscated Files or Information
GroupGamaredon Group

Gamaredon Group has delivered self-extracting 7z archive files within malicious document attachments. Additionally, Gamaredon Group has used an obfuscated .drv file.

T1027
Obfuscated Files or Information
GroupGallmaker

Gallmaker obfuscated shellcode used during execution.

T1027
Obfuscated Files or Information
GroupSandworm Team

Sandworm Team has used Base64 encoding within malware variants.

T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1027
Obfuscated Files or Information
GroupRocke

Rocke has modified UPX headers after packing files to break unpackers.

T1027
Obfuscated Files or Information
GroupAPT37

APT37 obfuscates strings and payloads.

T1027
Obfuscated Files or Information
GroupKe3chang

Ke3chang has used Base64-encoded shellcode strings.

T1027
Obfuscated Files or Information
GroupRedCurl

RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files.

T1027
Obfuscated Files or Information
GroupBackdoorDiplomacy

BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect.

T1027
Obfuscated Files or Information
GroupWindshift

Windshift has used string encoding with floating point calculations.

T1027
Obfuscated Files or Information
GroupAPT-C-36

APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats.

T1027
Obfuscated Files or Information
GroupEarth Lusca

Earth Lusca used Base64 to encode strings.

T1027
Obfuscated Files or Information
GroupBlackOasis

BlackOasis's first stage shellcode contains a NOP sled with alternative instructions that was likely designed to bypass antivirus tools.

T1027
Obfuscated Files or Information
GroupMoonstone Sleet

Moonstone Sleet delivers encrypted payloads in pieces that are then combined together to form a new portable executable (PE) file during installation.

T1027
Obfuscated Files or Information
MalwareTrickBot

TrickBot uses non-descriptive names to hide functionality.

T1027
Obfuscated Files or Information
MalwareEKANS

EKANS uses encoded strings in its process kill list.

T1027
Obfuscated Files or Information
MalwareSynAck

SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering.

T1027
Obfuscated Files or Information
MalwareBumblebee

Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions.

T1027
Obfuscated Files or Information
MalwareBRICKSTORM

BRICKSTORM has utilized Go libraries to include Garble to obfuscate code.

T1027
Obfuscated Files or Information
MalwareAmadey

Amadey has obfuscated strings such as antivirus vendor names, domains, files, and others.

T1027
Obfuscated Files or Information
MalwareOrz

Some Orz strings are base64 encoded, such as the embedded DLL known as MockDll.

T1027
Obfuscated Files or Information
MalwareNOKKI

NOKKI uses Base64 encoding for strings.

T1027
Obfuscated Files or Information
MalwareAvosLocker

AvosLocker has used XOR-encoded strings.

T1027
Obfuscated Files or Information
MalwareCOATHANGER

COATHANGER can store obfuscated configuration information in the last 56 bytes of the file `/date/.bd.key/preload.so`.

T1027
Obfuscated Files or Information
MalwareSardonic

Sardonic can use certain ConfuserEx features for obfuscation and can be encoded in a base64 string.

T1027
Obfuscated Files or Information
MalwareMatryoshka

Matryoshka obfuscates API function names using a substitute cipher combined with Base64 encoding.

T1027
Obfuscated Files or Information
MalwareEcipekac

Ecipekac can use XOR, AES, and DES to encrypt loader shellcode.

T1027
Obfuscated Files or Information
MalwareAppleSeed

AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls.

T1027
Obfuscated Files or Information
MalwareBUSHWALK

BUSHWALK can encrypt the resulting data generated from C2 commands with RC4.

T1027
Obfuscated Files or Information
MalwareNETWIRE

NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names.

T1027
Obfuscated Files or Information
MalwareBOOKWORM

BOOKWORM has been delivered using self-extracting RAR archives.

T1027
Obfuscated Files or Information
MalwareOLDBAIT

OLDBAIT obfuscates internal strings and unpacks them at startup.

T1027
Obfuscated Files or Information
MalwareTEARDROP

TEARDROP created and read from a file with a fake JPG header, and its payload was encrypted with a simple rotating XOR cipher.

T1027
Obfuscated Files or Information
MalwareTurian

Turian can use VMProtect for obfuscation.

T1027
Obfuscated Files or Information
MalwareAction RAT

Action RAT's commands, strings, and domains can be Base64 encoded within the payload.

T1027
Obfuscated Files or Information
MalwarePUBLOAD

PUBLOAD has obfuscated DLL names using the ror13AddHash32 algorithm.

T1027
Obfuscated Files or Information
MalwareGootloader

The Gootloader first stage script is obfuscated using random alpha numeric strings.

T1027
Obfuscated Files or Information
MalwarePolyglotDuke

PolyglotDuke can custom encrypt strings.

T1027
Obfuscated Files or Information
MalwareSombRAT

SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data.

T1027
Obfuscated Files or Information
MalwareSnip3

Snip3 has the ability to obfuscate strings using XOR encryption.

T1027
Obfuscated Files or Information
MalwareRegDuke

RegDuke can use control-flow flattening or the commercially available .NET Reactor for obfuscation.

T1027
Obfuscated Files or Information
MalwareInvisiMole

InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format.

T1027
Obfuscated Files or Information
MalwareP.A.S. Webshell

P.A.S. Webshell can use encryption and base64 encoding to hide strings and to enforce access control once deployed.

T1027
Obfuscated Files or Information
MalwareConti

Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls.

T1027
Obfuscated Files or Information
MalwareRaspberry Robin

Raspberry Robin uses mixed-case letters for filenames and commands to evade detection.

T1027
Obfuscated Files or Information
MalwareDiavol

Diavol has Base64 encoded the RSA public key used for encrypting files.

T1027
Obfuscated Files or Information
MalwareSiloscape

Siloscape itself is obfuscated and uses obfuscated API calls.

T1027
Obfuscated Files or Information
MalwareRustyWater

RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function.

T1027
Obfuscated Files or Information
MalwareHTTPTroy

HTTPTroy has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions to hinder analysis and detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.