ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareCuba

Cuba has a packed payload when delivered.

T1027.002
Software Packing
MalwareMongall

Mongall has been packed with Themida.

T1027.002
Software Packing
MalwareLockBit 3.0

LockBit 3.0 can use code packing to hinder analysis.

T1027.002
Software Packing
MalwareLatrodectus

The Latrodectus payload has been packed for obfuscation.

T1027.002
Software Packing
MalwareSaint Bot

Saint Bot has been packed using a dark market crypter.

T1027.002
Software Packing
MalwareSagerunex

Sagerunex has used VMProtect to pack and obscure itself.

T1027.002
Software Packing
MalwareUroburos

Uroburos uses a custom packer.

T1027.002
Software Packing
MalwareMetamorfo

Metamorfo has used VMProtect to pack and protect files.

T1027.002
Software Packing
MalwareTrojan.Karagany

Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer.

T1027.002
Software Packing
MalwareKONNI

KONNI has been packed for obfuscation.

T1027.002
Software Packing
MalwareRedLine Stealer

RedLine Stealer has used obfuscation tools such as DNGuard and Boxed App to pack their code.

T1027.002
Software Packing
MalwareOopsIE

OopsIE uses the SmartAssembly obfuscator to pack an embedded .Net Framework assembly used for C2.

T1027.002
Software Packing
MalwareSDBbot

SDBbot has used a packed installer file.

T1027.002
Software Packing
MalwareStrelaStealer

StrelaStealer variants have used packers to obfuscate payloads and make analysis more difficult.

T1027.002
Software Packing
MalwareLiteDuke

LiteDuke has been packed with multiple layers of encryption.

T1027.002
Software Packing
MalwareBazar

Bazar has a variant with a packed payload.

T1027.002
Software Packing
MalwareXLoader

XLoader uses various packers, including CyaX, to obfuscate malicious executables.

T1027.002
Software Packing
MalwareZebrocy

Zebrocy's Delphi variant was packed with UPX.

T1027.002
Software Packing
MalwareFinFisher

A FinFisher variant uses a custom packer.

T1027.002
Software Packing
MalwareHotCroissant

HotCroissant has used the open source UPX executable packer.

T1027.002
Software Packing
MalwareValak

Valak has used packed DLL payloads.

T1027.002
Software Packing
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a variant that is packed with UPX.

T1027.002
Software Packing
MalwareDaserf

A version of Daserf uses the MPRESS packer.

T1027.002
Software Packing
MalwareSysUpdate

SysUpdate has been packed with VMProtect.

T1027.002
Software Packing
MalwareClop

Clop has been packed to help avoid detection.

T1027.002
Software Packing
MalwareLokibot

Lokibot has used several packing methods for obfuscation.

T1027.002
Software Packing
MalwareEgregor

Egregor's payloads are custom-packed, archived and encrypted to prevent analysis.

T1027.002
Software Packing
MalwareMelcoz

Melcoz has been packed with VMProtect and Themida.

T1027.002
Software Packing
MalwareTroll Stealer

Troll Stealer has been delivered as a VMProtect-packed binary.

T1027.002
Software Packing
MalwareAstaroth

Astaroth uses a software packer called Pe123\RPolyCryptor.

T1027.002
Software Packing
MalwareQakBot

QakBot can encrypt and pack malicious payloads.

T1027.002
Software Packing
MalwarejRAT

jRAT payloads have been packed.

T1027.002
Software Packing
MalwareDok

Dok is packed with an UPX executable packer.

T1027.002
Software Packing
MalwareH1N1

H1N1 uses a custom packing algorithm.

T1027.002
Software Packing
ToolCSPY Downloader

CSPY Downloader has been packed with UPX.

T1027.002
Software Packing
ToolDonut

Donut can generate packed code modules.

T1027.003
Steganography
CampaignOperation Spalax

For Operation Spalax, the threat actors used packers that read pixel data from images contained in PE files' resource sections and build the next layer of execution from the data.

T1027.003
Steganography
CampaignOperation Ghost

During Operation Ghost, APT29 used steganography to hide payloads inside valid images.

T1027.003
Steganography
GroupMuddyWater

MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg.

T1027.003
Steganography
GroupAndariel

Andariel has hidden malicious executables within PNG files.

T1027.003
Steganography
GroupAPT37

APT37 uses steganography to send images to users that are embedded with shellcode.

T1027.003
Steganography
GroupTropic Trooper

Tropic Trooper has used JPG files with encrypted payloads to mask their backdoor routines and evade detection.

T1027.003
Steganography
GroupLeviathan

Leviathan has used steganography to hide stolen data inside other files stored on Github.

T1027.003
Steganography
GroupBRONZE BUTLER

BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads.

T1027.003
Steganography
GroupTA551

TA551 has hidden encoded data for malware DLLs in a PNG.

T1027.003
Steganography
GroupAPT-C-36

APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files.

T1027.003
Steganography
GroupEarth Lusca

Earth Lusca has used steganography to hide shellcode in a BMP image file.

T1027.003
Steganography
MalwarePowerDuke

PowerDuke uses steganography to hide backdoors in PNG files, which are also encrypted using the Tiny Encryption Algorithm (TEA).

T1027.003
Steganography
MalwarePikabot

Pikabot loads a set of PNG images stored in the malware's resources section (RCDATA), each with an encrypted section containing portions of the core Pikabot core module. These sections are loaded and decrypted using a bitwise XOR operation with a hardcoded 32 bit key.

T1027.003
Steganography
MalwareAvenger

Avenger can extract backdoor malware from downloaded images.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.