ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareKwampirs

Kwampirs downloads additional files that are base64-encoded and encrypted with another cipher.

T1027.013
Encrypted/Encoded File
MalwareDEADEYE

DEADEYE has encrypted its payload.

T1027.013
Encrypted/Encoded File
MalwareMango

Mango contains a series of base64 encoded substrings.

T1027.013
Encrypted/Encoded File
MalwareKessel

Kessel's configuration is hardcoded and RC4 encrypted within the binary.

T1027.013
Encrypted/Encoded File
MalwarePHASEJAM

PHASEJAM has launched a webshell using the `MIME::Base64` module that encoded and decoded Base64 commands.

T1027.013
Encrypted/Encoded File
MalwareYAHOYAH

YAHOYAH encrypts its configuration file using a simple algorithm.

T1027.013
Encrypted/Encoded File
MalwareStealBit

StealBit stores obfuscated DLL file names in its executable.

T1027.013
Encrypted/Encoded File
MalwareFELIXROOT

FELIXROOT encrypts strings in the backdoor using a custom XOR algorithm.

T1027.013
Encrypted/Encoded File
MalwarePenquin

Penquin has encrypted strings in the binary for obfuscation.

T1027.013
Encrypted/Encoded File
MalwareSPAWNCHIMERA

SPAWNCHIMERA has encoded a private key with XOR. SPAWNCHIMERA has also encrypted data to be extracted using AES encryption.

T1027.013
Encrypted/Encoded File
MalwareWinnti for Windows

Winnti for Windows has the ability to encrypt and compress its payload.

T1027.013
Encrypted/Encoded File
MalwarenjRAT

njRAT has included a base64 encoded executable.

T1027.013
Encrypted/Encoded File
MalwaremetaMain

metaMain's module file has been encrypted via XOR.

T1027.013
Encrypted/Encoded File
MalwareHeyoka Backdoor

Heyoka Backdoor can encrypt its payload.

T1027.013
Encrypted/Encoded File
MalwareLunarWeb

The LunarWeb install files have been encrypted with AES-256.

T1027.013
Encrypted/Encoded File
MalwareXCSSET

Older XCSSET variants use `xxd` to encode modules. Later versions pass an `xxd` or `base64` encoded blob through multiple decoding stages to reconstruct the module name, AppleScript, or shell command. For example, the initial network request uses three layers of hex decoding before executing a curl command in a shell.

T1027.013
Encrypted/Encoded File
MalwareQilin

Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings.

T1027.013
Encrypted/Encoded File
MalwareSTARWHALE

STARWHALE has been obfuscated with hex-encoded strings.

T1027.013
Encrypted/Encoded File
MalwareCozyCar

The payload of CozyCar is encrypted with simple XOR with a rotating key. The CozyCar configuration file has been encrypted with RC4 keys.

T1027.013
Encrypted/Encoded File
MalwareKevin

Kevin has Base64-encoded its configuration file.

T1027.013
Encrypted/Encoded File
MalwareDRYHOOK

DRYHOOK has encrypted stolen credentials strings within a file using both Base64 and RC4 with a hard-coded key.

T1027.013
Encrypted/Encoded File
MalwareRemexi

Remexi obfuscates its configuration data with XOR.

T1027.013
Encrypted/Encoded File
MalwareAstaroth

Astaroth has used an XOR-based algorithm to encrypt payloads twice with different keys.

T1027.013
Encrypted/Encoded File
MalwareDOWNIISSA

DOWNIISSA code is base64 encoded and XOR encrypted.

T1027.013
Encrypted/Encoded File
MalwareHelminth

The Helminth config file is encrypted with RC4.

T1027.013
Encrypted/Encoded File
MalwareDEADWOOD

DEADWOOD contains an embedded, AES-encrypted resource named METADATA that contains configuration information for follow-on execution.

T1027.013
Encrypted/Encoded File
MalwareWaterbear

Waterbear has used RC4 encrypted shellcode and encrypted functions.

T1027.013
Encrypted/Encoded File
MalwareFIVEHANDS

The FIVEHANDS payload is encrypted with AES-128.

T1027.013
Encrypted/Encoded File
MalwareLoudMiner

LoudMiner has encrypted DMG files.

T1027.013
Encrypted/Encoded File
MalwareBitPaymer

BitPaymer has used RC4-encrypted strings and string hashes to avoid identifiable strings within the binary.

T1027.013
Encrypted/Encoded File
MalwareZox

Zox has been encoded with Base64.

T1027.013
Encrypted/Encoded File
MalwareHiddenWasp

HiddenWasp encrypts its configuration and payload.

T1027.013
Encrypted/Encoded File
MalwareXORIndex Loader

XORIndex Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis.

T1027.013
Encrypted/Encoded File
MalwareHermeticWizard

HermeticWizard has the ability to encrypt PE files with a reverse XOR loop.

T1027.013
Encrypted/Encoded File
ToolSliver

Sliver can encrypt strings at compile time.

T1027.013
Encrypted/Encoded File
ToolDCRAT

The DCRAT configuration file is encrypted using AES-256.

T1027.013
Encrypted/Encoded File
ToolPcShare

PcShare has been encrypted with XOR using different 32-long Base16 strings.

T1027.013
Encrypted/Encoded File
ToolRemcos

Remcos can use string encryption to hinder analysis.

T1027.013
Encrypted/Encoded File
ToolDonut

Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules.

T1027.013
Encrypted/Encoded File
ToolIronNetInjector

IronNetInjector can obfuscate variable names, encrypt strings, as well as base64 encode and Rijndael encrypt payloads.

T1027.013
Encrypted/Encoded File
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has used multi-stage payloads with double Base64-encoded scripts to evade static analysis.

T1027.013
Encrypted/Encoded File
MalwareMini Shai-Hulud

Mini Shai-Hulud has used a hybrid AES-256-GCM and RSA OAEP-SHA256 encryption to archive gathered data. Mini Shai-Hulud has also utilized custom MD5-keystream XOR cipher to encrypt data. Mini Shai-Hulud has also been deployed via an obfuscated script using Bun JavaScript runtime.

T1027.014
Polymorphic Code
MalwareBendyBear

BendyBear changes its runtime footprint during code execution to evade signature-based defenses.

T1027.015
Compression
MalwareNinja

Ninja has compressed its data with the LZSS algorithm.

T1027.015
Compression
MalwareRCSession

RCSession can compress and obfuscate its strings to evade detection on a compromised host.

T1027.015
Compression
MalwareWindTail

WindTail can be delivered as a compressed, encrypted, and encoded payload.

T1027.015
Compression
MalwareThreatNeedle

ThreatNeedle has been compressed and obfuscated.

T1027.015
Compression
MalwarePony

Pony attachments have been delivered via compressed archive files.

T1027.015
Compression
MalwareBADHATCH

BADHATCH can be compressed with the ApLib algorithm.

T1027.015
Compression
MalwarePUBLOAD

PUBLOAD has been delivered as compressed files within ZIP files to victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.