ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupKimsuky

Kimsuky has encoded malicious PowerShell scripts using Base64.

T1027.010
Command Obfuscation
GroupPatchwork

Patchwork has obfuscated a script with Crypto Obfuscator.

T1027.010
Command Obfuscation
GroupAPT32

APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell.

T1027.010
Command Obfuscation
GroupMuddyWater

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.

T1027.010
Command Obfuscation
GroupFIN6

FIN6 has used encoded PowerShell commands.

T1027.010
Command Obfuscation
GroupGamaredon Group

Gamaredon Group has used obfuscated or encrypted scripts.

T1027.010
Command Obfuscation
GroupLeafminer

Leafminer obfuscated scripts that were used on victim machines.

T1027.010
Command Obfuscation
GroupFIN7

FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands.

T1027.010
Command Obfuscation
GroupSandworm Team

Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor.

T1027.010
Command Obfuscation
GroupSidewinder

Sidewinder has used base64 encoding for scripts.

T1027.010
Command Obfuscation
GroupContagious Interview

Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions.

T1027.010
Command Obfuscation
GroupAquatic Panda

Aquatic Panda has encoded PowerShell commands in Base64.

T1027.010
Command Obfuscation
GroupTurla

Turla has used encryption (including salted 3DES via PowerSploit's Out-EncryptedScript.ps1), random variable names, and base64 encoding to obfuscate PowerShell commands and payloads.

T1027.010
Command Obfuscation
GroupTA505

TA505 has used base64 encoded PowerShell commands.

T1027.010
Command Obfuscation
GroupChimera

Chimera has encoded PowerShell commands.

T1027.010
Command Obfuscation
GroupMedusa Group

Medusa Group has obfuscated PowerShell scripts with Base64 encoding. Medusa Group has also obfuscated the code of dropped kernel drivers using a software known as Safengine Shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code.

T1027.010
Command Obfuscation
GroupTA551

TA551 has used obfuscated variable names in a JavaScript configuration file.

T1027.010
Command Obfuscation
GroupLazyScripter

LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques.

T1027.010
Command Obfuscation
GroupFox Kitten

Fox Kitten has base64 encoded scripts to avoid detection.

T1027.010
Command Obfuscation
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has executed base64 encoded PowerShell scripts on compromised hosts.

T1027.010
Command Obfuscation
GroupSilence

Silence has used environment variable string substitution for obfuscation.

T1027.010
Command Obfuscation
GroupCobalt Group

Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4.

T1027.010
Command Obfuscation
GroupWizard Spider

Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands.

T1027.010
Command Obfuscation
GroupPlay

Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.

T1027.010
Command Obfuscation
GroupHEXANE

HEXANE has used Base64-encoded scripts.

T1027.010
Command Obfuscation
GroupWIRTE

WIRTE has XOR encrypted command line strings to conceal malware execution chains.

T1027.010
Command Obfuscation
GroupMagic Hound

Magic Hound has used base64-encoded commands.

T1027.010
Command Obfuscation
GroupFIN8

FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads.

T1027.010
Command Obfuscation
GroupAPT19

APT19 used Base64 to obfuscate executed commands.

T1027.010
Command Obfuscation
MalwareIronWind

IronWind has used Base64 encoding and XOR encryption with the key “53” to obfuscate command strings.

T1027.010
Command Obfuscation
MalwareSardonic

Sardonic PowerShell scripts can be encrypted with RC4 and compressed using Gzip.

T1027.010
Command Obfuscation
MalwareUrsnif

Ursnif droppers execute base64 encoded PowerShell commands.

T1027.010
Command Obfuscation
MalwareTsundere Botnet

Tsundere Botnet’s MSI installer has Base64-encoded command execution.

T1027.010
Command Obfuscation
MalwareZeus Panda

Zeus Panda obfuscates the macro commands in its initial payload.

T1027.010
Command Obfuscation
MalwareHavoc

Havoc has utilized XOR encryption with the key “01-01-1900” to obfuscate command strings.

T1027.010
Command Obfuscation
MalwareCARROTBAT

CARROTBAT has the ability to execute obfuscated commands on the infected host.

T1027.010
Command Obfuscation
MalwareEmotet

Emotet has obfuscated macros within malicious documents to hide the URLs hosting the malware, CMD.exe arguments, and PowerShell scripts.

T1027.010
Command Obfuscation
MalwareBADHATCH

BADHATCH malicious PowerShell commands can be encoded with base64.

T1027.010
Command Obfuscation
MalwareMachete

Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis.

T1027.010
Command Obfuscation
MalwareFruitFly

FruitFly executes and stores obfuscated Perl scripts.

T1027.010
Command Obfuscation
MalwareDarkWatchman

DarkWatchman has used Base64 to encode PowerShell commands.

T1027.010
Command Obfuscation
MalwareSHARPSTATS

SHARPSTATS has used base64 encoding and XOR to obfuscate PowerShell scripts.

T1027.010
Command Obfuscation
MalwareNetwalker

Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables.

T1027.010
Command Obfuscation
MalwareQUADAGENT

QUADAGENT was likely obfuscated using `Invoke-Obfuscation`.

T1027.010
Command Obfuscation
MalwareRedLine Stealer

RedLine Stealer has obfuscated scripts within text files used in execution.

T1027.010
Command Obfuscation
MalwareRogueRobin

The PowerShell script with the RogueRobin payload was obfuscated using the COMPRESS technique in `Invoke-Obfuscation`.

T1027.010
Command Obfuscation
MalwareSQLRat

SQLRat has used a character insertion obfuscation technique, making the script appear to contain Chinese characters.

T1027.010
Command Obfuscation
MalwareSibot

Sibot has obfuscated scripts used in execution.

T1027.010
Command Obfuscation
MalwareBackConfig

BackConfig has used compressed and decimal encoded VBS scripts.

T1027.010
Command Obfuscation
MalwarePHASEJAM

PHASEJAM has encoded commands with Base64.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.