Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareCuba | Cuba has a packed payload when delivered. |
| T1027.002 Software Packing |
MalwareMongall | Mongall has been packed with Themida. |
| T1027.002 Software Packing |
MalwareLockBit 3.0 | LockBit 3.0 can use code packing to hinder analysis. |
| T1027.002 Software Packing |
MalwareLatrodectus | The Latrodectus payload has been packed for obfuscation. |
| T1027.002 Software Packing |
MalwareSaint Bot | Saint Bot has been packed using a dark market crypter. |
| T1027.002 Software Packing |
MalwareSagerunex | Sagerunex has used VMProtect to pack and obscure itself. |
| T1027.002 Software Packing |
MalwareUroburos | Uroburos uses a custom packer. |
| T1027.002 Software Packing |
MalwareMetamorfo | Metamorfo has used VMProtect to pack and protect files. |
| T1027.002 Software Packing |
MalwareTrojan.Karagany | Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer. |
| T1027.002 Software Packing |
MalwareKONNI | KONNI has been packed for obfuscation. |
| T1027.002 Software Packing |
MalwareRedLine Stealer | RedLine Stealer has used obfuscation tools such as DNGuard and Boxed App to pack their code. |
| T1027.002 Software Packing |
MalwareOopsIE | OopsIE uses the SmartAssembly obfuscator to pack an embedded .Net Framework assembly used for C2. |
| T1027.002 Software Packing |
MalwareSDBbot | SDBbot has used a packed installer file. |
| T1027.002 Software Packing |
MalwareStrelaStealer | StrelaStealer variants have used packers to obfuscate payloads and make analysis more difficult. |
| T1027.002 Software Packing |
MalwareLiteDuke | LiteDuke has been packed with multiple layers of encryption. |
| T1027.002 Software Packing |
MalwareBazar | Bazar has a variant with a packed payload. |
| T1027.002 Software Packing |
MalwareXLoader | XLoader uses various packers, including CyaX, to obfuscate malicious executables. |
| T1027.002 Software Packing |
MalwareZebrocy | Zebrocy's Delphi variant was packed with UPX. |
| T1027.002 Software Packing |
MalwareFinFisher | A FinFisher variant uses a custom packer. |
| T1027.002 Software Packing |
MalwareHotCroissant | HotCroissant has used the open source UPX executable packer. |
| T1027.002 Software Packing |
MalwareValak | Valak has used packed DLL payloads. |
| T1027.002 Software Packing |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has a variant that is packed with UPX. |
| T1027.002 Software Packing |
MalwareDaserf | A version of Daserf uses the MPRESS packer. |
| T1027.002 Software Packing |
MalwareSysUpdate | SysUpdate has been packed with VMProtect. |
| T1027.002 Software Packing |
MalwareClop | Clop has been packed to help avoid detection. |
| T1027.002 Software Packing |
MalwareLokibot | Lokibot has used several packing methods for obfuscation. |
| T1027.002 Software Packing |
MalwareEgregor | Egregor's payloads are custom-packed, archived and encrypted to prevent analysis. |
| T1027.002 Software Packing |
MalwareMelcoz | Melcoz has been packed with VMProtect and Themida. |
| T1027.002 Software Packing |
MalwareTroll Stealer | Troll Stealer has been delivered as a VMProtect-packed binary. |
| T1027.002 Software Packing |
MalwareAstaroth | Astaroth uses a software packer called Pe123\RPolyCryptor. |
| T1027.002 Software Packing |
MalwareQakBot | QakBot can encrypt and pack malicious payloads. |
| T1027.002 Software Packing |
MalwarejRAT | jRAT payloads have been packed. |
| T1027.002 Software Packing |
MalwareDok | Dok is packed with an UPX executable packer. |
| T1027.002 Software Packing |
MalwareH1N1 | H1N1 uses a custom packing algorithm. |
| T1027.002 Software Packing |
ToolCSPY Downloader | CSPY Downloader has been packed with UPX. |
| T1027.002 Software Packing |
ToolDonut | Donut can generate packed code modules. |
| T1027.003 Steganography |
CampaignOperation Spalax | For Operation Spalax, the threat actors used packers that read pixel data from images contained in PE files' resource sections and build the next layer of execution from the data. |
| T1027.003 Steganography |
CampaignOperation Ghost | During Operation Ghost, APT29 used steganography to hide payloads inside valid images. |
| T1027.003 Steganography |
GroupMuddyWater | MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg. |
| T1027.003 Steganography |
GroupAndariel | Andariel has hidden malicious executables within PNG files. |
| T1027.003 Steganography |
GroupAPT37 | APT37 uses steganography to send images to users that are embedded with shellcode. |
| T1027.003 Steganography |
GroupTropic Trooper | Tropic Trooper has used JPG files with encrypted payloads to mask their backdoor routines and evade detection. |
| T1027.003 Steganography |
GroupLeviathan | Leviathan has used steganography to hide stolen data inside other files stored on Github. |
| T1027.003 Steganography |
GroupBRONZE BUTLER | BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads. |
| T1027.003 Steganography |
GroupTA551 | TA551 has hidden encoded data for malware DLLs in a PNG. |
| T1027.003 Steganography |
GroupAPT-C-36 | APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files. |
| T1027.003 Steganography |
GroupEarth Lusca | Earth Lusca has used steganography to hide shellcode in a BMP image file. |
| T1027.003 Steganography |
MalwarePowerDuke | PowerDuke uses steganography to hide backdoors in PNG files, which are also encrypted using the Tiny Encryption Algorithm (TEA). |
| T1027.003 Steganography |
MalwarePikabot | Pikabot loads a set of PNG images stored in the malware's resources section (RCDATA), each with an encrypted section containing portions of the core Pikabot core module. These sections are loaded and decrypted using a bitwise XOR operation with a hardcoded 32 bit key. |
| T1027.003 Steganography |
MalwareAvenger | Avenger can extract backdoor malware from downloaded images. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.