Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.007 Dynamic API Resolution |
GroupLazarus Group | Lazarus Group has used a custom hashing method to resolve APIs used in shellcode. |
| T1027.007 Dynamic API Resolution |
MalwareAvosLocker | AvosLocker has used obfuscated API calls that are retrieved by their checksums. |
| T1027.007 Dynamic API Resolution |
MalwareTONESHELL | TONESHELL has utilized a modified DJB2 algorithm to resolve APIs. |
| T1027.007 Dynamic API Resolution |
MalwareCANONSTAGER | CANONSTAGER has utilized custom API hashing to obfuscate the Windows APIs being used. |
| T1027.007 Dynamic API Resolution |
MalwareCLAIMLOADER | CLAIMLOADER has utilized XOR-encrypted API names and native APIs of `LdrLoadDll()` and `LderGetProcedureAddress()` to resolve imports dynamically. |
| T1027.007 Dynamic API Resolution |
MalwareHTTPTroy | HTTPTroy has utilized dynamic API resolution by reconstructing API calls during runtime using combinations of arithmetic and logical operations to complicate static analysis. |
| T1027.007 Dynamic API Resolution |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use `LoadLibrary` and `GetProcAddress` to resolve Windows API function strings at run time. |
| T1027.007 Dynamic API Resolution |
MalwarePteranodon | Pteranodon can use a dynamic Windows hashing algorithm to map API components. |
| T1027.007 Dynamic API Resolution |
MalwareSplatDropper | SplatDropper has leveraged hashed Windows API calls using a seed value of "131313". |
| T1027.007 Dynamic API Resolution |
MalwarePlugX | PlugX has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API. |
| T1027.007 Dynamic API Resolution |
MalwareLatrodectus | Latrodectus can resolve Windows APIs dynamically by hash. |
| T1027.007 Dynamic API Resolution |
MalwareLODEINFO | LODEINFO can use a hashing algorithm to dynamically resolve API function addresses. |
| T1027.007 Dynamic API Resolution |
MalwareLP-Notes | LP-Notes has dynamically resolved API functions during the C runtime startup. |
| T1027.007 Dynamic API Resolution |
MalwareBazar | Bazar can hash then resolve API calls at runtime. |
| T1027.007 Dynamic API Resolution |
MalwareHiddenFace | HiddenFace can dynamically resolve Windows APIs. |
| T1027.007 Dynamic API Resolution |
MalwareSamurai | Samurai can encrypt API name strings with an XOR-based algorithm. |
| T1027.007 Dynamic API Resolution |
MalwareRaccoon Stealer | Raccoon Stealer dynamically links key WinApi functions during execution. |
| T1027.007 Dynamic API Resolution |
ToolBrute Ratel C4 | Brute Ratel C4 can call and dynamically resolve hashed APIs. |
| T1027.008 Stripped Payloads |
MalwaremacOS.OSAMiner | macOS.OSAMiner has used run-only Applescripts, a compiled and stripped version of AppleScript, to remove human readable indicators to evade detection. |
| T1027.008 Stripped Payloads |
MalwareCuckoo Stealer | Cuckoo Stealer is a stripped binary payload. |
| T1027.009 Embedded Payloads |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus uses embedded .dll as apart of a chained delivery mechanism to invoke the COM class factory. |
| T1027.009 Embedded Payloads |
CampaignC0021 | For C0021, the threat actors embedded a base64-encoded payload within a LNK file. |
| T1027.009 Embedded Payloads |
GroupTA577 | TA577 has used LNK files to execute embedded DLLs. |
| T1027.009 Embedded Payloads |
GroupLazarus Group | Lazarus Group has distributed malicious payloads embedded in PNG files. |
| T1027.009 Embedded Payloads |
GroupMoonstone Sleet | Moonstone Sleet embedded payloads in trojanized software for follow-on execution. |
| T1027.009 Embedded Payloads |
MalwarePikabot | Pikabot further decrypts information embedded via steganography using AES-CBC with the same 32 bit key as initial XOR operations combined with the first 16 bytes of the encrypted data as an initialization vector. Other Pikabot variants include encrypted, chunked sections of the stage 2 payload in the initial loader |
| T1027.009 Embedded Payloads |
MalwaremacOS.OSAMiner | macOS.OSAMiner has embedded Stripped Payloads within another run-only Stripped Payloads. |
| T1027.009 Embedded Payloads |
MalwareEmotet | Emotet has dropped an embedded executable at `%Temp%\setup.exe`. Additionally, Emotet may embed entire code into other files. |
| T1027.009 Embedded Payloads |
MalwareDUSTTRAP | DUSTTRAP contains additional embedded DLLs and configuration files that are loaded into memory during execution. |
| T1027.009 Embedded Payloads |
MalwareBADHATCH | BADHATCH has an embedded second stage DLL payload within the first stage of the malware. |
| T1027.009 Embedded Payloads |
MalwareDUSTPAN | DUSTPAN decrypts and executes an embedded payload. |
| T1027.009 Embedded Payloads |
MalwareMoneybird | Moneybird contains a configuration blob embedded in the malware itself. |
| T1027.009 Embedded Payloads |
MalwareIcedID | IcedID has embedded malicious functionality in a legitimate DLL file. |
| T1027.009 Embedded Payloads |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can extract RC4 encrypted embedded payloads for privilege escalation. |
| T1027.009 Embedded Payloads |
MalwareMultiLayer Wiper | MultiLayer Wiper contains two binaries in its resources section, MultiList and MultiWip. MultiLayer Wiper drops and executes each of these items when run, then deletes them after execution. |
| T1027.009 Embedded Payloads |
MalwareNetwalker | Netwalker's DLL has been embedded within the PowerShell script in hex format. |
| T1027.009 Embedded Payloads |
MalwareSMOKEDHAM | The SMOKEDHAM source code is embedded in the dropper as an encrypted string. |
| T1027.009 Embedded Payloads |
MalwareUroburos | The Uroburos Queue file contains embedded executable files along with key material, communication channels, and modes of operation. |
| T1027.009 Embedded Payloads |
MalwareDEADEYE | The DEADEYE.EMBED variant of DEADEYE has the ability to embed payloads inside of a compiled binary. |
| T1027.009 Embedded Payloads |
MalwareComRAT | ComRAT has embedded a XOR encrypted communications module inside the orchestrator module. |
| T1027.009 Embedded Payloads |
MalwareDEADWOOD | DEADWOOD contains an embedded, AES-encrypted payload labeled |
| T1027.009 Embedded Payloads |
MalwareDtrack | Dtrack has used a dropper that embeds an encrypted payload as extra data. |
| T1027.009 Embedded Payloads |
ToolInvoke-PSImage | Invoke-PSImage can be used to embed payload data within a new image file. |
| T1027.009 Embedded Payloads |
MalwareCanisterWorm | CanisterWorm has used embedded second stage Base64-encoded payloads. |
| T1027.010 Command Obfuscation |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
CampaignFrankenstein | During Frankenstein, the threat actors ran encoded commands from the command line. |
| T1027.010 Command Obfuscation |
CampaignC0018 | During C0018, the threat actors used Base64 to encode their PowerShell scripts. |
| T1027.010 Command Obfuscation |
CampaignC0021 | During C0021, the threat actors used encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors executed an encoded VBScript file. |
| T1027.010 Command Obfuscation |
CampaignOperation Wocao | During Operation Wocao, threat actors executed PowerShell commands which were encoded or compressed using Base64, zlib, and XOR. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.