Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.015 Compression |
MalwareShimRat | ShimRat has been delivered as a package that includes compressed DLL and shellcode payloads within a .dat file. |
| T1027.015 Compression |
MalwareSocGholish | The SocGholish JavaScript payload has been delivered within a compressed ZIP archive. |
| T1027.015 Compression |
MalwareLine Runner | Line Runner uses a ZIP payload that is automatically extracted with its contents, a LUA script, executed for initial execution via CVE-2024-20359. |
| T1027.015 Compression |
MalwareDarkWatchman | DarkWatchman has been delivered as compressed RAR payloads in ZIP files to victims. |
| T1027.015 Compression |
MalwareLODEINFO | LODEINFO components have been compressed with zip for delivery. |
| T1027.015 Compression |
MalwareKerrdown | Kerrdown can encrypt, encode, and compress multiple layers of shellcode. |
| T1027.015 Compression |
MalwareRTM | RTM has been delivered to targets as various archive files including ZIP, 7-ZIP, and RAR. |
| T1027.015 Compression |
MalwareStrelaStealer | StrelaStealer has been delivered via JScript files in a ZIP archive. |
| T1027.015 Compression |
MalwareHermeticWiper | HermeticWiper can compress 32-bit and 64-bit driver files with the Lempel-Ziv algorithm. |
| T1027.015 Compression |
MalwarePandora | Pandora has the ability to compress stings with QuickLZ. |
| T1027.015 Compression |
MalwareSUNBURST | SUNBURST strings were compressed and encoded in Base64. |
| T1027.015 Compression |
MalwareSamurai | Samurai can deliver its final payload as a compressed, encrypted and base64-encoded blob. |
| T1027.015 Compression |
MalwarePillowmint | Pillowmint has been compressed and stored within a registry key. |
| T1027.015 Compression |
MalwareWinnti for Windows | Winnti for Windows has the ability to encrypt and compress its payload. |
| T1027.015 Compression |
MalwareHancitor | Hancitor has delivered compressed payloads in ZIP files to victims. |
| T1027.015 Compression |
MalwareGelsemium | Gelsemium has the ability to compress its components. |
| T1027.015 Compression |
ToolPcShare | PcShare has been compressed with LZW algorithm. |
| T1027.015 Compression |
ToolDonut | Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules. |
| T1027.016 Junk Code Insertion |
Malwareyty | yty contains junk code in its binary, likely to confuse malware analysts. |
| T1027.016 Junk Code Insertion |
MalwarePony | Pony obfuscates memory flow by adding junk instructions when executing to make analysis more difficult. |
| T1027.016 Junk Code Insertion |
MalwareWastedLocker | WastedLocker contains junk code to increase its entropy and hide the actual code. |
| T1027.016 Junk Code Insertion |
MalwareZeroT | ZeroT has obfuscated DLLs and functions using dummy API calls inserted between real instructions. |
| T1027.016 Junk Code Insertion |
MalwareSamSam | SamSam has used garbage code to pad some of its malware components. |
| T1027.016 Junk Code Insertion |
MalwareFatDuke | FatDuke has been packed with junk code and strings. |
| T1027.016 Junk Code Insertion |
MalwareCORESHELL | CORESHELL contains unused machine instructions in a likely attempt to hinder analysis. |
| T1027.016 Junk Code Insertion |
MalwareNOOPLDR | NOOPLDR can insert junk code to obfuscate malicious payloads. |
| T1027.016 Junk Code Insertion |
MalwarePureCrypter | PureCrypter can insert junk code to avoid detection. |
| T1027.016 Junk Code Insertion |
MalwareXTunnel | A version of XTunnel introduced in July 2015 inserted junk code into the binary in a likely attempt to obfuscate it and bypass security products. |
| T1027.016 Junk Code Insertion |
MalwareLODEINFO | LODEINFO has inserted junk code to obstruct code analysis. |
| T1027.016 Junk Code Insertion |
MalwareStrelaStealer | StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes. |
| T1027.016 Junk Code Insertion |
MalwareFinFisher | FinFisher contains junk code in its functions in an effort to confuse disassembly programs. |
| T1027.016 Junk Code Insertion |
MalwareANELLDR | ANELLDR can use junk code for payload obfuscation. |
| T1027.016 Junk Code Insertion |
MalwareMaze | Maze has inserted large blocks of junk code, including some components to decrypt strings and other important information for later in the encryption process. |
| T1027.016 Junk Code Insertion |
MalwarePOWERSTATS | POWERSTATS has used useless code blocks to counter analysis. |
| T1027.016 Junk Code Insertion |
MalwareGoopy | Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis. |
| T1027.016 Junk Code Insertion |
MalwareGelsemium | Gelsemium can use junk code to hide functions and evade detection. |
| T1027.018 Invisible Unicode |
MalwareGlassWorm | GlassWorm has utilized invisible Unicode Private Use Area (PUA) characters to obfuscate its malicious code so that it does not render in code editors. |
| T1029 Scheduled Transfer |
MalwareNinja | Ninja can configure its agent to work only in specific time frames. |
| T1029 Scheduled Transfer |
MalwareTinyTurla | TinyTurla contacts its C2 based on a scheduled timing set in its configuration. |
| T1029 Scheduled Transfer |
MalwareMachete | Machete sends stolen data to the C2 server every 10 minutes. |
| T1029 Scheduled Transfer |
MalwareKazuar | Kazuar can sleep for a specific time and be set to communicate at specific intervals. |
| T1029 Scheduled Transfer |
MalwareShimRat | ShimRat can sleep when instructed to do so by the C2. |
| T1029 Scheduled Transfer |
MalwareChrommme | Chrommme can set itself to sleep before requesting a new command from C2. |
| T1029 Scheduled Transfer |
MalwareFlagpro | Flagpro has the ability to wait for a specified time interval between communicating with and executing commands from C2. |
| T1029 Scheduled Transfer |
MalwareLightNeuron | LightNeuron can be configured to exfiltrate data during nighttime or working hours. |
| T1029 Scheduled Transfer |
MalwareShark | Shark can pause C2 communications for a specified time. |
| T1029 Scheduled Transfer |
MalwareCobalt Strike | Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval. |
| T1029 Scheduled Transfer |
MalwareComRAT | ComRAT has been programmed to sleep outside local business hours (9 to 5, Monday to Friday). |
| T1029 Scheduled Transfer |
MalwareDipsind | Dipsind can be configured to only run during normal working hours, which would make its communications harder to distinguish from normal traffic. |
| T1029 Scheduled Transfer |
MalwarePOWERSTATS | POWERSTATS can sleep for a given number of seconds. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.