Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareKazuar | Kazuar is obfuscated using the open source ConfuserEx protector. Kazuar also obfuscates the name of created files/folders/mutexes and encrypts debug messages written to log files using the Rijndael cipher. |
| T1027 Obfuscated Files or Information |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use a custom Base64 alphabet to encode an API decryption key. |
| T1027 Obfuscated Files or Information |
MalwareFatDuke | FatDuke can use base64 encoding, string stacking, and opaque predicates for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareDRATzarus | DRATzarus can be partly encrypted with XOR. |
| T1027 Obfuscated Files or Information |
MalwareSHOTPUT | SHOTPUT is obscured using XOR encoding and appended to a valid GIF file. |
| T1027 Obfuscated Files or Information |
MalwareAvaddon | Avaddon has used encrypted strings. |
| T1027 Obfuscated Files or Information |
MalwareConficker | Conficker has obfuscated its code to prevent its removal from host machines. |
| T1027 Obfuscated Files or Information |
MalwareFlagpro | Flagpro has been delivered within ZIP or RAR password-protected archived files. |
| T1027 Obfuscated Files or Information |
MalwareGreen Lambert | Green Lambert has encrypted strings. |
| T1027 Obfuscated Files or Information |
MalwareISMInjector | ISMInjector is obfuscated with the off-the-shelf SmartAssembly .NET obfuscator created by red-gate.com. |
| T1027 Obfuscated Files or Information |
MalwarePUNCHBUGGY | PUNCHBUGGY has hashed most its code's functions and encrypted payloads with base64 and XOR. |
| T1027 Obfuscated Files or Information |
MalwarePOSHSPY | POSHSPY appends a file signature header (randomly selected from six file types) to encrypted data prior to upload or download. |
| T1027 Obfuscated Files or Information |
MalwareMiniDuke | MiniDuke can use control flow flattening to obscure code. |
| T1027 Obfuscated Files or Information |
MalwareAnchor | Anchor has obfuscated code with stack strings and string encryption. |
| T1027 Obfuscated Files or Information |
MalwareDarkTortilla | DarkTortilla has been obfuscated with the DeepSea .NET and ConfuserEx code obfuscators. |
| T1027 Obfuscated Files or Information |
MalwareROKRAT | ROKRAT can encrypt data prior to exfiltration by using an RSA public key. |
| T1027 Obfuscated Files or Information |
MalwareCORESHELL | CORESHELL obfuscates strings using a custom stream cipher. |
| T1027 Obfuscated Files or Information |
MalwarePlugX | PlugX can use API hashing and modify the names of strings to evade detection. |
| T1027 Obfuscated Files or Information |
MalwareNOOPLDR | NOOPLDR can use control flow flattening to help hide malicious code. |
| T1027 Obfuscated Files or Information |
MalwareLumma Stealer | Lumma Stealer has used SmartAssembly to obfuscate .NET payloads. |
| T1027 Obfuscated Files or Information |
MalwareDustySky | The DustySky dropper uses a function to obfuscate the name of functions and other parts of the malware. |
| T1027 Obfuscated Files or Information |
MalwareEpic | Epic heavily obfuscates its code to make analysis more difficult. |
| T1027 Obfuscated Files or Information |
MalwareCuba | Cuba has used multiple layers of obfuscation to avoid analysis, including its Base64 encoded payload. |
| T1027 Obfuscated Files or Information |
MalwareClambling | The Clambling executable has been obfuscated when dropped on a compromised host. |
| T1027 Obfuscated Files or Information |
MalwareDarkGate | DarkGate uses a hard-coded string as a seed, along with the victim machine hardware identifier and input text, to generate a unique string used as an internal mutex value to evade static detection based on mutexes. |
| T1027 Obfuscated Files or Information |
MalwareSVCReady | SVCReady can encrypt victim data with an RC4 cipher. |
| T1027 Obfuscated Files or Information |
MalwareCarbanak | Carbanak encrypts strings to make analysis more difficult. |
| T1027 Obfuscated Files or Information |
MalwareXTunnel | A version of XTunnel introduced in July 2015 obfuscated the binary using opaque predicates and other techniques in a likely attempt to obfuscate it and bypass security products. |
| T1027 Obfuscated Files or Information |
MalwareHydraq | Hydraq uses basic obfuscation in the form of spaghetti code. |
| T1027 Obfuscated Files or Information |
MalwareSaint Bot | Saint Bot has been obfuscated to help avoid detection. |
| T1027 Obfuscated Files or Information |
MalwareLODEINFO | LODEINFO has used control flow flattening to obfuscate code. |
| T1027 Obfuscated Files or Information |
MalwareBundlore | Bundlore has obfuscated data with base64, AES, RC4, and bz2. |
| T1027 Obfuscated Files or Information |
MalwareFooder | Fooder has stored its embedded payload in encrypted form within the binary, using a hardcoded key modified at runtime to produce the AES decryption key. |
| T1027 Obfuscated Files or Information |
MalwareTrojan.Karagany | Trojan.Karagany can base64 encode and AES-128-CBC encrypt data prior to transmission. |
| T1027 Obfuscated Files or Information |
MalwareShamoon | Shamoon contains base64-encoded strings. |
| T1027 Obfuscated Files or Information |
MalwareBPFDoor | BPFDoor can require a password to activate the backdoor and uses RC4 encryption or static library encryption `libtomcrypt`. |
| T1027 Obfuscated Files or Information |
MalwareOopsIE | OopsIE uses the Confuser protector to obfuscate an embedded .Net Framework assembly used for C2. OopsIE also encodes collected data in hexadecimal format before writing to files on disk and obfuscates strings. |
| T1027 Obfuscated Files or Information |
MalwareStreamEx | StreamEx obfuscates some commands by using statically programmed fragments of strings when starting a DLL. It also uses a one-byte xor against 0x91 to encode configuration data. |
| T1027 Obfuscated Files or Information |
MalwareBoxCaon | BoxCaon used the "StackStrings" obfuscation technique to hide malicious functionalities. |
| T1027 Obfuscated Files or Information |
MalwareNightClub | NightClub can obfuscate strings using the congruential generator `(LCG): staten+1 = (690069 × staten + 1) mod 232`. |
| T1027 Obfuscated Files or Information |
MalwareSDBbot | SDBbot has the ability to XOR the strings for its installer component with a hardcoded 128 byte key. |
| T1027 Obfuscated Files or Information |
MalwareRTM | RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm. |
| T1027 Obfuscated Files or Information |
MalwareSodaMaster | SodaMaster can use "stackstrings" for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareStrelaStealer | StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives. |
| T1027 Obfuscated Files or Information |
MalwareDrovorub | Drovorub has used XOR encrypted payloads in WebSocket client to server messages. |
| T1027 Obfuscated Files or Information |
MalwareKobalos | Kobalos encrypts all strings using RC4 and bundles all functionality into a single function call. |
| T1027 Obfuscated Files or Information |
MalwareRyuk | Ryuk can use anti-disassembly and code transformation obfuscation techniques. |
| T1027 Obfuscated Files or Information |
MalwareFinal1stspy | Final1stspy obfuscates strings with base64 encoding. |
| T1027 Obfuscated Files or Information |
MalwareFinFisher | FinFisher is heavily obfuscated in many ways, including through the use of spaghetti code in its functions in an effort to confuse disassembly programs. It also uses a custom XOR algorithm to obfuscate code. |
| T1027 Obfuscated Files or Information |
MalwareCobalt Strike | Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.