Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.003 Steganography |
MalwarePolyglotDuke | PolyglotDuke can use steganography to hide C2 information in images. |
| T1027.003 Steganography |
MalwareRegDuke | RegDuke can hide data in images, including use of the Least Significant Bit (LSB). |
| T1027.003 Steganography |
MalwareProLock | ProLock can use .jpg and .bmp files to store its payload. |
| T1027.003 Steganography |
MalwareRDAT | RDAT can also embed data within a BMP image prior to exfiltration. |
| T1027.003 Steganography |
MalwareOkrum | Okrum's payload is encrypted and embedded within its loader, or within a legitimate PNG file. |
| T1027.003 Steganography |
MalwareDiavol | Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques. |
| T1027.003 Steganography |
MalwareRaindrop | Raindrop used steganography to locate the start of its encoded payload within legitimate 7-Zip code. |
| T1027.003 Steganography |
MalwareIcedID | IcedID has embedded binaries within RC4 encrypted .png files. |
| T1027.003 Steganography |
MalwareObliqueRAT | ObliqueRAT can hide its payload in BMP images hosted on compromised websites. |
| T1027.003 Steganography |
MalwareBandook | Bandook has used .PNG images within a zip file to build the executable. |
| T1027.003 Steganography |
MalwareLiteDuke | LiteDuke has used image files to hide its loader component. |
| T1027.003 Steganography |
MalwareABK | ABK can extract a malicious Portable Executable (PE) from a photo. |
| T1027.003 Steganography |
MalwareRamsay | Ramsay has PE data embedded within JPEG files contained within Word documents. |
| T1027.003 Steganography |
Malwarebuild_downer | build_downer can extract malware from a downloaded JPEG. |
| T1027.003 Steganography |
MalwareBBK | BBK can extract a malicious Portable Executable (PE) from a photo. |
| T1027.003 Steganography |
ToolInvoke-PSImage | Invoke-PSImage can be used to embed a PowerShell script within the pixels of a PNG file. |
| T1027.003 Steganography |
GroupTeamPCP | TeamPCP has hidden malicious payloads in the frame data of WAV audio files. |
| T1027.004 Compile After Delivery |
GroupMuddyWater | MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code. |
| T1027.004 Compile After Delivery |
GroupGamaredon Group | Gamaredon Group has compiled the source code for a downloader directly on the infected system using the built-in |
| T1027.004 Compile After Delivery |
GroupRocke | Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC). |
| T1027.004 Compile After Delivery |
GroupSea Turtle | Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments. |
| T1027.004 Compile After Delivery |
MalwareDarkWatchman | DarkWatchman has used the |
| T1027.004 Compile After Delivery |
MalwareFoggyWeb | FoggyWeb can compile and execute source code sent to the compromised AD FS server via a specific HTTP POST. |
| T1027.004 Compile After Delivery |
MalwareSamurai | Samurai can compile and execute downloaded modules at runtime. |
| T1027.004 Compile After Delivery |
MalwareCardinal RAT | Cardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code. |
| T1027.004 Compile After Delivery |
MalwarenjRAT | njRAT has used AutoIt to compile the payload and main script into a single executable after delivery. |
| T1027.004 Compile After Delivery |
ToolSliver | Sliver includes functionality to retrieve source code and compile locally prior to execution in victim environments. |
| T1027.005 Indicator Removal from Tools |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles modified files based on the open-source project cryptcat in an apparent attempt to decrease anti-virus detection rates. |
| T1027.005 Indicator Removal from Tools |
CampaignOperation Wocao | During Operation Wocao, threat actors edited variable names within the Impacket suite to avoid automated detection. |
| T1027.005 Indicator Removal from Tools |
GroupGALLIUM | GALLIUM ensured each payload had a unique hash, including by using different types of packers. |
| T1027.005 Indicator Removal from Tools |
GroupAPT3 | APT3 has been known to remove indicators of compromise from tools. |
| T1027.005 Indicator Removal from Tools |
GroupPatchwork | Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes. |
| T1027.005 Indicator Removal from Tools |
GroupUNC3886 | UNC3886 has replaced atomic indicators mentioned in threat intelligence publications, sometimes as quickly as under a week after release. |
| T1027.005 Indicator Removal from Tools |
GroupOilRig | OilRig has tested malware samples to determine AV detection and subsequently modified the samples to ensure AV evasion. |
| T1027.005 Indicator Removal from Tools |
GroupTurla | Based on comparison of Gazer versions, Turla made an effort to obfuscate strings in the malware that could be used as IoCs, including the mutex name and named pipe. |
| T1027.005 Indicator Removal from Tools |
GroupDeep Panda | Deep Panda has updated and modified its malware, resulting in different hash values that evade detection. |
| T1027.005 Indicator Removal from Tools |
MalwareGravityRAT | The author of GravityRAT submitted samples to VirusTotal for testing, showing that the author modified the code to try to hide the DDE object in a different part of the document. |
| T1027.005 Indicator Removal from Tools |
MalwareInvisiMole | InvisiMole has undergone regular technical improvements in an attempt to evade detection. |
| T1027.005 Indicator Removal from Tools |
MalwareCobalt Strike | Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods. |
| T1027.005 Indicator Removal from Tools |
MalwareSUNBURST | SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT. |
| T1027.005 Indicator Removal from Tools |
MalwareDaserf | Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection. |
| T1027.005 Indicator Removal from Tools |
MalwarePenquin | Penquin can remove strings from binaries. |
| T1027.005 Indicator Removal from Tools |
MalwareQakBot | QakBot can make small changes to itself in order to change its checksum and hash value. |
| T1027.005 Indicator Removal from Tools |
MalwareWaterbear | Waterbear can scramble functions not to be executed again with random values. |
| T1027.005 Indicator Removal from Tools |
ToolPowerSploit | PowerSploit's |
| T1027.006 HTML Smuggling |
GroupAPT29 | APT29 has embedded an ISO file within an HTML attachment that contained JavaScript code to initiate malware execution. |
| T1027.006 HTML Smuggling |
MalwareEnvyScout | EnvyScout contains JavaScript code that can extract an encoded blob from its HTML body and write it to disk. |
| T1027.006 HTML Smuggling |
MalwareQakBot | QakBot has been delivered in ZIP files via HTML smuggling. |
| T1027.007 Dynamic API Resolution |
GroupKimsuky | Kimsuky has leveraged dynamic API resolution using custom hashing techniques. |
| T1027.007 Dynamic API Resolution |
GroupMustang Panda | Mustang Panda has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.