Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
GroupRocke | Rocke's miner has created UPX-packed files in the Windows Start Menu Folder. |
| T1027.002 Software Packing |
GroupAPT39 | APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection. |
| T1027.002 Software Packing |
GroupTA2541 | TA2541 has used a .NET packer to obfuscate malicious files. |
| T1027.002 Software Packing |
GroupAoqin Dragon | Aoqin Dragon has used the Themida packer to obfuscate malicious payloads. |
| T1027.002 Software Packing |
GroupThe White Company | The White Company has obfuscated their payloads through packing. |
| T1027.002 Software Packing |
GroupSaint Bear | Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload. |
| T1027.002 Software Packing |
GroupMoustachedBouncer | MoustachedBouncer has used malware plugins packed with Themida. |
| T1027.002 Software Packing |
GroupStorm-0501 | Storm-0501 has used Themida to pack Cobalt Strike payloads. |
| T1027.002 Software Packing |
GroupTA505 | TA505 has used UPX to obscure malicious code. |
| T1027.002 Software Packing |
GroupAPT29 | APT29 used UPX to pack files. |
| T1027.002 Software Packing |
GroupDark Caracal | Dark Caracal has used UPX to pack Bandook. |
| T1027.002 Software Packing |
GroupMedusa Group | Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard. |
| T1027.002 Software Packing |
GroupThreat Group-3390 | Threat Group-3390 has packed malware and tools, including using VMProtect. |
| T1027.002 Software Packing |
MalwareTrickBot | TrickBot leverages a custom packer to obfuscate its functionality. |
| T1027.002 Software Packing |
MalwareBLINDINGCAN | BLINDINGCAN has been packed with the UPX packer. |
| T1027.002 Software Packing |
MalwareSpark | Spark has been packed with Enigma Protector to obfuscate its contents. |
| T1027.002 Software Packing |
MalwareTorisma | Torisma has been packed with Iz4 compression. |
| T1027.002 Software Packing |
Malwareyty | yty packs a plugin with UPX. |
| T1027.002 Software Packing |
MalwareCOATHANGER | The first stage of COATHANGER is delivered as a packed file. |
| T1027.002 Software Packing |
MalwareMisdat | Misdat was typically packed using UPX. |
| T1027.002 Software Packing |
MalwareHeartCrypt | HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection. |
| T1027.002 Software Packing |
MalwareAppleSeed | AppleSeed has used UPX packers for its payload DLL. |
| T1027.002 Software Packing |
MalwareNETWIRE | NETWIRE has used .NET packer tools to evade detection. |
| T1027.002 Software Packing |
MalwareGreyEnergy | GreyEnergy is packed for obfuscation. |
| T1027.002 Software Packing |
MalwareEmotet | Emotet has used custom packers to protect its payloads. |
| T1027.002 Software Packing |
MalwareTomiris | Tomiris has been packed with UPX. |
| T1027.002 Software Packing |
MalwareMachete | Machete has been packed with NSIS. |
| T1027.002 Software Packing |
MalwareSquirrelwaffle | Squirrelwaffle has been packed with a custom packer to hide payloads. |
| T1027.002 Software Packing |
MalwareHildegard | Hildegard has packed ELF files into other binaries. |
| T1027.002 Software Packing |
MalwareFYAnti | FYAnti has used ConfuserEx to pack its .NET module. |
| T1027.002 Software Packing |
MalwareZeroT | Some ZeroT DLL files have been packed with UPX. |
| T1027.002 Software Packing |
MalwareRaspberry Robin | Raspberry Robin contains multiple payloads that are packed for defense evasion purposes and unpacked on runtime. |
| T1027.002 Software Packing |
MalwareRaindrop | Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm. |
| T1027.002 Software Packing |
MalwareIcedID | IcedID has packed and encrypted its loader module. |
| T1027.002 Software Packing |
MalwareVERMIN | VERMIN is initially packed. |
| T1027.002 Software Packing |
MalwareDarkComet | DarkComet has the option to compress its payload using UPX or MPRESS. |
| T1027.002 Software Packing |
MalwareFatDuke | FatDuke has been regularly repacked by its operators to create large binaries and evade detection. |
| T1027.002 Software Packing |
MalwareLucifer | Lucifer has used UPX packed binaries. |
| T1027.002 Software Packing |
MalwareDRATzarus | DRATzarus's dropper can be packed with UPX. |
| T1027.002 Software Packing |
MalwareShimRat | ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack. |
| T1027.002 Software Packing |
MalwareChina Chopper | China Chopper's client component is packed with UPX. |
| T1027.002 Software Packing |
MalwareGoldMax | GoldMax has been packed for obfuscation. |
| T1027.002 Software Packing |
MalwareCostaBricks | CostaBricks can implement a custom-built virtual machine mechanism to obfuscate its code. |
| T1027.002 Software Packing |
MalwareHyperBro | HyperBro has the ability to pack its payload. |
| T1027.002 Software Packing |
MalwareAnchor | Anchor has come with a packed payload. |
| T1027.002 Software Packing |
MalwareBabuk | Versions of Babuk have been packed. |
| T1027.002 Software Packing |
MalwareDyre | Dyre has been delivered with encrypted resources and must be unpacked for execution. |
| T1027.002 Software Packing |
MalwareBisonal | Bisonal has used the MPRESS packer and similar tools for obfuscation. |
| T1027.002 Software Packing |
MalwareS-Type | Some S-Type samples have been packed with UPX. |
| T1027.002 Software Packing |
MalwareSeaDuke | SeaDuke has been packed with the UPX packer. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.