Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
ToolOut1 | Out1 has the ability to encode data. |
| T1027 Obfuscated Files or Information |
ToolImminent Monitor | Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2. |
| T1027 Obfuscated Files or Information |
ToolMCMD | MCMD can Base64 encode output strings prior to sending to C2. |
| T1027.001 Binary Padding |
GroupKimsuky | Kimsuky has performed padding of PowerShell command line code with over 100 spaces. |
| T1027.001 Binary Padding |
GroupPatchwork | Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes. |
| T1027.001 Binary Padding |
GroupMoafee | Moafee has been known to employ binary padding. |
| T1027.001 Binary Padding |
GroupAkira | Akira has used binary padding to obfuscate payloads. |
| T1027.001 Binary Padding |
GroupHigaisa | Higaisa performed padding with null bytes before calculating its hash. |
| T1027.001 Binary Padding |
GroupLeviathan | Leviathan has inserted garbage characters into code, presumably to avoid anti-virus detection. |
| T1027.001 Binary Padding |
GroupAPT29 | APT29 used large size files to avoid detection by security solutions with hardcoded size limits. |
| T1027.001 Binary Padding |
GroupBRONZE BUTLER | BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection. |
| T1027.001 Binary Padding |
MalwareEmissary | A variant of Emissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan. |
| T1027.001 Binary Padding |
MalwareHeartCrypt | HeartCrypt can add several hundred thousand kilobytes of null padding to payloads before saving onto the file system. |
| T1027.001 Binary Padding |
MalwareTONESHELL | TONESHELL has used randomized padding to obfuscate payloads. |
| T1027.001 Binary Padding |
MalwareEmotet | Emotet inflates malicious files and malware as an evasion technique. |
| T1027.001 Binary Padding |
MalwareSnip3 | Snip3 can obfuscate strings using junk Chinese characters. |
| T1027.001 Binary Padding |
MalwareRifdoor | Rifdoor has added four additional bytes of data upon launching, then saved the changed version as |
| T1027.001 Binary Padding |
MalwareCHIMNEYSWEEP | The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size. |
| T1027.001 Binary Padding |
MalwareLightSpy | LightSpy's configuration file is appended to the end of the binary. For example, the last `0x1d0` bytes of one sample is an AES encrypted configuration file with a static key of `3e2717e8b3873b29`. |
| T1027.001 Binary Padding |
MalwareCostaBricks | CostaBricks has added the entire unobfuscated code of the legitimate open source application Blink to its code. |
| T1027.001 Binary Padding |
MalwareJavali | Javali can use large obfuscated libraries to hinder detection and analysis. |
| T1027.001 Binary Padding |
MalwarePlugX | PlugX has utilized junk code and opaque predicates in payloads to hinder analysis. |
| T1027.001 Binary Padding |
MalwareBisonal | Bisonal has appended random binary data to the end of itself to generate a large binary. |
| T1027.001 Binary Padding |
MalwareLatrodectus | Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file. |
| T1027.001 Binary Padding |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can execute |
| T1027.001 Binary Padding |
MalwareBlack Basta | Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload. |
| T1027.001 Binary Padding |
MalwareGrandoreiro | Grandoreiro has added BMP images to the resources section of its Portable Executable (PE) file increasing each binary to at least 300MB in size. |
| T1027.001 Binary Padding |
MalwareCaminho | Caminho can use junk code for obfuscation. |
| T1027.001 Binary Padding |
MalwareKwampirs | Before writing to disk, Kwampirs inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections. |
| T1027.001 Binary Padding |
MalwareGrimAgent | GrimAgent has the ability to add bytes to change the file hash. |
| T1027.001 Binary Padding |
MalwareGoopy | Goopy has had null characters padded in its malicious DLL payload. |
| T1027.001 Binary Padding |
MalwareQakBot | QakBot can use large file sizes to evade detection. |
| T1027.001 Binary Padding |
MalwareComnie | Comnie appends a total of 64MB of garbage data to a file to deter any security products in place that may be scanning files on disk. |
| T1027.002 Software Packing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection. |
| T1027.002 Software Packing |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors UPX-packed malicous payloads including 4L4MD4R ransomware. |
| T1027.002 Software Packing |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors used UPX to pack some payloads. |
| T1027.002 Software Packing |
CampaignOperation Spalax | For Operation Spalax, the threat actors used a variety of packers, including CyaX, to obfuscate malicious executables. |
| T1027.002 Software Packing |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used UPX to pack a copy of Mimikatz. |
| T1027.002 Software Packing |
CampaignNight Dragon | During Night Dragon, threat actors used software packing in its tools. |
| T1027.002 Software Packing |
CampaignC0017 | During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries. |
| T1027.002 Software Packing |
GroupAPT38 | APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants. |
| T1027.002 Software Packing |
GroupElderwood | Elderwood has packed malware payloads before delivery to victims. |
| T1027.002 Software Packing |
GroupGALLIUM | GALLIUM packed some payloads using different types of packers, both known and custom. |
| T1027.002 Software Packing |
GroupAPT3 | APT3 has been known to pack their tools. |
| T1027.002 Software Packing |
GroupKimsuky | Kimsuky has packed malware with UPX. |
| T1027.002 Software Packing |
GroupVolt Typhoon | Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine. |
| T1027.002 Software Packing |
GroupPatchwork | A Patchwork payload was packed with UPX. |
| T1027.002 Software Packing |
GroupAPT41 | APT41 uses packers such as Themida to obfuscate malicious files. |
| T1027.002 Software Packing |
GroupTeamTNT | TeamTNT has used UPX and Ezuri packer to pack its binaries. |
| T1027.002 Software Packing |
GroupZIRCONIUM | ZIRCONIUM has used multi-stage packers for exploit code. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.