ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareSUNBURST

SUNBURST obfuscated collected system information using a FNV-1a + XOR algorithm.

T1027
Obfuscated Files or Information
MalwareValak

Valak has the ability to base64 encode and XOR encrypt strings.

T1027
Obfuscated Files or Information
MalwareSamurai

Samurai can encrypt the names of requested APIs.

T1027
Obfuscated Files or Information
MalwarePoisonIvy

PoisonIvy hides any strings related to its own indicators of compromise.

T1027
Obfuscated Files or Information
MalwareNanoCore

NanoCore’s plugins were obfuscated with Eazfuscater.NET 3.3.

T1027
Obfuscated Files or Information
MalwareTajMahal

TajMahal has used an encrypted Virtual File System to store plugins.

T1027
Obfuscated Files or Information
MalwareDaserf

Daserf uses encrypted Windows APIs and also encrypts data using the alternative base64+RC4 or the Caesar cipher.

T1027
Obfuscated Files or Information
MalwareCarbon

Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm.

T1027
Obfuscated Files or Information
MalwarePisloader

Pisloader obfuscates files by splitting strings into smaller sub-strings and including "garbage" strings that are never used. The malware also uses return-oriented programming (ROP) technique and single-byte XOR to obfuscate data.

T1027
Obfuscated Files or Information
MalwareRamsay

Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. Ramsay can also embed information within document footers.

T1027
Obfuscated Files or Information
MalwarePillowmint

Pillowmint has obfuscated the AES key used for encryption.

T1027
Obfuscated Files or Information
MalwareSUNSPOT

SUNSPOT encrypted log entries it collected with the stream cipher RC4 using a hard-coded key. It also uses AES128-CBC encrypted blobs for SUNBURST source code and data extracted from the SolarWinds Orion <MsBuild.exe</code> process.

T1027
Obfuscated Files or Information
MalwareANELLDR

ANELLDR code implements anti-analysis techniques including control flow flattening and Mixed Boolean Arithmetic (MBA).

T1027
Obfuscated Files or Information
MalwareBoomBox

BoomBox can encrypt data using AES prior to exfiltration.

T1027
Obfuscated Files or Information
MalwarePUNCHTRACK

PUNCHTRACK is loaded and executed by a highly obfuscated launcher.

T1027
Obfuscated Files or Information
MalwareInnaputRAT

InnaputRAT uses an 8-byte XOR key to obfuscate API names and other strings contained in the payload.

T1027
Obfuscated Files or Information
MalwareGrimAgent

GrimAgent has used Rotate on Right (RoR) and Rotate on Left (RoL) functionality to encrypt strings.

T1027
Obfuscated Files or Information
MalwareLokibot

Lokibot has obfuscated strings with base64 encoding.

T1027
Obfuscated Files or Information
MalwarePoetRAT

PoetRAT has used a custom encryption scheme for communication between scripts.

T1027
Obfuscated Files or Information
MalwareCoinTicker

CoinTicker initially downloads a hidden encoded file.

T1027
Obfuscated Files or Information
MalwareEbury

Ebury has obfuscated its strings with a simple XOR encryption with a static key.

T1027
Obfuscated Files or Information
MalwareMaze

Maze has decrypted strings and other important information during the encryption process. Maze also calls certain functions dynamically to hinder analysis.

T1027
Obfuscated Files or Information
MalwareComRAT

ComRAT has encrypted its virtual file system using AES-256 in XTS mode.

T1027
Obfuscated Files or Information
MalwarePowerStallion

PowerStallion uses a XOR cipher to encrypt command output written to its OneDrive C2 server.

T1027
Obfuscated Files or Information
MalwareShai-Hulud

Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account. Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes.

T1027
Obfuscated Files or Information
MalwareJPIN

A JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer.

T1027
Obfuscated Files or Information
MalwareHTTPBrowser

HTTPBrowser's code may be obfuscated through structured exception handling and return-oriented programming.

T1027
Obfuscated Files or Information
MalwareKillDisk

KillDisk uses VMProtect to make reverse engineering the malware more difficult.

T1027
Obfuscated Files or Information
MalwareAppleJeus

AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components.

T1027
Obfuscated Files or Information
MalwareSoreFang

SoreFang has the ability to encode and RC6 encrypt data sent to C2.

T1027
Obfuscated Files or Information
MalwareIndustroyer

Industroyer uses heavily obfuscated code in its Windows Notepad backdoor.

T1027
Obfuscated Files or Information
MalwareAgent Tesla

Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings.

T1027
Obfuscated Files or Information
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON has encrypted strings with RC4.

T1027
Obfuscated Files or Information
MalwareShadowPad

ShadowPad has encrypted its payload, a virtual file system, and various files.

T1027
Obfuscated Files or Information
MalwareQakBot

QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells.

T1027
Obfuscated Files or Information
MalwareHancitor

Hancitor has used Base64 to encode malicious links.

T1027
Obfuscated Files or Information
MalwarejRAT

jRAT’s Java payload is encrypted with AES. Additionally, backdoor files are encrypted using DES as a stream cipher. Later variants of jRAT also incorporated AV evasion methods such as Java bytecode obfuscation via the commercial Allatori obfuscation tool.

T1027
Obfuscated Files or Information
MalwareDridex

Dridex's strings are obfuscated using RC4.

T1027
Obfuscated Files or Information
MalwareDenis

Denis obfuscates its code and encrypts the API names.

T1027
Obfuscated Files or Information
MalwareComnie

Comnie uses RC4 and Base64 to obfuscate strings.

T1027
Obfuscated Files or Information
MalwareLizar

Lizar has obfuscated the fingerprint of the victim system, the local IP address, and the Fowler-Noll-V 1 (FNV-1) hash of the local IP address using an XOR operation. The data is then sent to the C2 server.

T1027
Obfuscated Files or Information
MalwareH1N1

H1N1 uses multiple techniques to obfuscate strings, including XOR.

T1027
Obfuscated Files or Information
MalwareSLOWPULSE

SLOWPULSE can hide malicious code in the padding regions between legitimate functions in the Pulse Secure `libdsplibs.so` file.

T1027
Obfuscated Files or Information
MalwareADVSTORESHELL

Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory.

T1027
Obfuscated Files or Information
MalwareSmall Sieve

Small Sieve has the ability to use a custom hex byte swapping encoding scheme combined with an obfuscated Base64 function to protect program strings and Telegram credentials.

T1027
Obfuscated Files or Information
ToolShimRatReporter

ShimRatReporter encrypted gathered information with a combination of shifting and XOR using a static key.

T1027
Obfuscated Files or Information
ToolSliver

Sliver obfuscates configuration and other static files using native Go libraries such as `garble` and `gobfuscate` to inhibit configuration analysis and static detection.

T1027
Obfuscated Files or Information
ToolCARROTBALL

CARROTBALL has used a custom base64 alphabet to decode files.

T1027
Obfuscated Files or Information
ToolBrute Ratel C4

Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory.

T1027
Obfuscated Files or Information
ToolRemcos

Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths. Remcos can also employ control flow flattening to hinder analysis.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.