Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupKimsuky | Kimsuky has encoded malicious PowerShell scripts using Base64. |
| T1027.010 Command Obfuscation |
GroupPatchwork | Patchwork has obfuscated a script with Crypto Obfuscator. |
| T1027.010 Command Obfuscation |
GroupAPT32 | APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell. |
| T1027.010 Command Obfuscation |
GroupMuddyWater | MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupFIN6 | FIN6 has used encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupGamaredon Group | Gamaredon Group has used obfuscated or encrypted scripts. |
| T1027.010 Command Obfuscation |
GroupLeafminer | Leafminer obfuscated scripts that were used on victim machines. |
| T1027.010 Command Obfuscation |
GroupFIN7 | FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands. |
| T1027.010 Command Obfuscation |
GroupSandworm Team | Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor. |
| T1027.010 Command Obfuscation |
GroupSidewinder | Sidewinder has used base64 encoding for scripts. |
| T1027.010 Command Obfuscation |
GroupContagious Interview | Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions. |
| T1027.010 Command Obfuscation |
GroupAquatic Panda | Aquatic Panda has encoded PowerShell commands in Base64. |
| T1027.010 Command Obfuscation |
GroupTurla | Turla has used encryption (including salted 3DES via PowerSploit's |
| T1027.010 Command Obfuscation |
GroupTA505 | TA505 has used base64 encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupChimera | Chimera has encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupMedusa Group | Medusa Group has obfuscated PowerShell scripts with Base64 encoding. Medusa Group has also obfuscated the code of dropped kernel drivers using a software known as Safengine Shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code. |
| T1027.010 Command Obfuscation |
GroupTA551 | TA551 has used obfuscated variable names in a JavaScript configuration file. |
| T1027.010 Command Obfuscation |
GroupLazyScripter | LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques. |
| T1027.010 Command Obfuscation |
GroupFox Kitten | Fox Kitten has base64 encoded scripts to avoid detection. |
| T1027.010 Command Obfuscation |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has executed base64 encoded PowerShell scripts on compromised hosts. |
| T1027.010 Command Obfuscation |
GroupSilence | Silence has used environment variable string substitution for obfuscation. |
| T1027.010 Command Obfuscation |
GroupCobalt Group | Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4. |
| T1027.010 Command Obfuscation |
GroupWizard Spider | Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupPlay | Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts. |
| T1027.010 Command Obfuscation |
GroupHEXANE | HEXANE has used Base64-encoded scripts. |
| T1027.010 Command Obfuscation |
GroupWIRTE | WIRTE has XOR encrypted command line strings to conceal malware execution chains. |
| T1027.010 Command Obfuscation |
GroupMagic Hound | Magic Hound has used base64-encoded commands. |
| T1027.010 Command Obfuscation |
GroupFIN8 | FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads. |
| T1027.010 Command Obfuscation |
GroupAPT19 | APT19 used Base64 to obfuscate executed commands. |
| T1027.010 Command Obfuscation |
MalwareIronWind | IronWind has used Base64 encoding and XOR encryption with the key “53” to obfuscate command strings. |
| T1027.010 Command Obfuscation |
MalwareSardonic | Sardonic PowerShell scripts can be encrypted with RC4 and compressed using Gzip. |
| T1027.010 Command Obfuscation |
MalwareUrsnif | Ursnif droppers execute base64 encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
MalwareTsundere Botnet | Tsundere Botnet’s MSI installer has Base64-encoded command execution. |
| T1027.010 Command Obfuscation |
MalwareZeus Panda | Zeus Panda obfuscates the macro commands in its initial payload. |
| T1027.010 Command Obfuscation |
MalwareHavoc | Havoc has utilized XOR encryption with the key “01-01-1900” to obfuscate command strings. |
| T1027.010 Command Obfuscation |
MalwareCARROTBAT | CARROTBAT has the ability to execute obfuscated commands on the infected host. |
| T1027.010 Command Obfuscation |
MalwareEmotet | Emotet has obfuscated macros within malicious documents to hide the URLs hosting the malware, CMD.exe arguments, and PowerShell scripts. |
| T1027.010 Command Obfuscation |
MalwareBADHATCH | BADHATCH malicious PowerShell commands can be encoded with base64. |
| T1027.010 Command Obfuscation |
MalwareMachete | Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis. |
| T1027.010 Command Obfuscation |
MalwareFruitFly | FruitFly executes and stores obfuscated Perl scripts. |
| T1027.010 Command Obfuscation |
MalwareDarkWatchman | DarkWatchman has used Base64 to encode PowerShell commands. |
| T1027.010 Command Obfuscation |
MalwareSHARPSTATS | SHARPSTATS has used base64 encoding and XOR to obfuscate PowerShell scripts. |
| T1027.010 Command Obfuscation |
MalwareNetwalker | Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables. |
| T1027.010 Command Obfuscation |
MalwareQUADAGENT | QUADAGENT was likely obfuscated using `Invoke-Obfuscation`. |
| T1027.010 Command Obfuscation |
MalwareRedLine Stealer | RedLine Stealer has obfuscated scripts within text files used in execution. |
| T1027.010 Command Obfuscation |
MalwareRogueRobin | The PowerShell script with the RogueRobin payload was obfuscated using the COMPRESS technique in `Invoke-Obfuscation`. |
| T1027.010 Command Obfuscation |
MalwareSQLRat | SQLRat has used a character insertion obfuscation technique, making the script appear to contain Chinese characters. |
| T1027.010 Command Obfuscation |
MalwareSibot | Sibot has obfuscated scripts used in execution. |
| T1027.010 Command Obfuscation |
MalwareBackConfig | BackConfig has used compressed and decimal encoded VBS scripts. |
| T1027.010 Command Obfuscation |
MalwarePHASEJAM | PHASEJAM has encoded commands with Base64. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.