ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
GroupRocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1027.002
Software Packing
GroupAPT39

APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection.

T1027.002
Software Packing
GroupTA2541

TA2541 has used a .NET packer to obfuscate malicious files.

T1027.002
Software Packing
GroupAoqin Dragon

Aoqin Dragon has used the Themida packer to obfuscate malicious payloads.

T1027.002
Software Packing
GroupThe White Company

The White Company has obfuscated their payloads through packing.

T1027.002
Software Packing
GroupSaint Bear

Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload.

T1027.002
Software Packing
GroupMoustachedBouncer

MoustachedBouncer has used malware plugins packed with Themida.

T1027.002
Software Packing
GroupStorm-0501

Storm-0501 has used Themida to pack Cobalt Strike payloads.

T1027.002
Software Packing
GroupTA505

TA505 has used UPX to obscure malicious code.

T1027.002
Software Packing
GroupAPT29

APT29 used UPX to pack files.

T1027.002
Software Packing
GroupDark Caracal

Dark Caracal has used UPX to pack Bandook.

T1027.002
Software Packing
GroupMedusa Group

Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard.

T1027.002
Software Packing
GroupThreat Group-3390

Threat Group-3390 has packed malware and tools, including using VMProtect.

T1027.002
Software Packing
MalwareTrickBot

TrickBot leverages a custom packer to obfuscate its functionality.

T1027.002
Software Packing
MalwareBLINDINGCAN

BLINDINGCAN has been packed with the UPX packer.

T1027.002
Software Packing
MalwareSpark

Spark has been packed with Enigma Protector to obfuscate its contents.

T1027.002
Software Packing
MalwareTorisma

Torisma has been packed with Iz4 compression.

T1027.002
Software Packing
Malwareyty

yty packs a plugin with UPX.

T1027.002
Software Packing
MalwareCOATHANGER

The first stage of COATHANGER is delivered as a packed file.

T1027.002
Software Packing
MalwareMisdat

Misdat was typically packed using UPX.

T1027.002
Software Packing
MalwareHeartCrypt

HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection.

T1027.002
Software Packing
MalwareAppleSeed

AppleSeed has used UPX packers for its payload DLL.

T1027.002
Software Packing
MalwareNETWIRE

NETWIRE has used .NET packer tools to evade detection.

T1027.002
Software Packing
MalwareGreyEnergy

GreyEnergy is packed for obfuscation.

T1027.002
Software Packing
MalwareEmotet

Emotet has used custom packers to protect its payloads.

T1027.002
Software Packing
MalwareTomiris

Tomiris has been packed with UPX.

T1027.002
Software Packing
MalwareMachete

Machete has been packed with NSIS.

T1027.002
Software Packing
MalwareSquirrelwaffle

Squirrelwaffle has been packed with a custom packer to hide payloads.

T1027.002
Software Packing
MalwareHildegard

Hildegard has packed ELF files into other binaries.

T1027.002
Software Packing
MalwareFYAnti

FYAnti has used ConfuserEx to pack its .NET module.

T1027.002
Software Packing
MalwareZeroT

Some ZeroT DLL files have been packed with UPX.

T1027.002
Software Packing
MalwareRaspberry Robin

Raspberry Robin contains multiple payloads that are packed for defense evasion purposes and unpacked on runtime.

T1027.002
Software Packing
MalwareRaindrop

Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm.

T1027.002
Software Packing
MalwareIcedID

IcedID has packed and encrypted its loader module.

T1027.002
Software Packing
MalwareVERMIN

VERMIN is initially packed.

T1027.002
Software Packing
MalwareDarkComet

DarkComet has the option to compress its payload using UPX or MPRESS.

T1027.002
Software Packing
MalwareFatDuke

FatDuke has been regularly repacked by its operators to create large binaries and evade detection.

T1027.002
Software Packing
MalwareLucifer

Lucifer has used UPX packed binaries.

T1027.002
Software Packing
MalwareDRATzarus

DRATzarus's dropper can be packed with UPX.

T1027.002
Software Packing
MalwareShimRat

ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack.

T1027.002
Software Packing
MalwareChina Chopper

China Chopper's client component is packed with UPX.

T1027.002
Software Packing
MalwareGoldMax

GoldMax has been packed for obfuscation.

T1027.002
Software Packing
MalwareCostaBricks

CostaBricks can implement a custom-built virtual machine mechanism to obfuscate its code.

T1027.002
Software Packing
MalwareHyperBro

HyperBro has the ability to pack its payload.

T1027.002
Software Packing
MalwareAnchor

Anchor has come with a packed payload.

T1027.002
Software Packing
MalwareBabuk

Versions of Babuk have been packed.

T1027.002
Software Packing
MalwareDyre

Dyre has been delivered with encrypted resources and must be unpacked for execution.

T1027.002
Software Packing
MalwareBisonal

Bisonal has used the MPRESS packer and similar tools for obfuscation.

T1027.002
Software Packing
MalwareS-Type

Some S-Type samples have been packed with UPX.

T1027.002
Software Packing
MalwareSeaDuke

SeaDuke has been packed with the UPX packer.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.