ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.013×

195 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareMore_eggs

More_eggs's payload has been encrypted with a key that has the hostname and processor family information appended to the end.

T1027.013
Encrypted/Encoded File
MalwareSysUpdate

SysUpdate can encrypt and encode its configuration file.

T1027.013
Encrypted/Encoded File
MalwareANELLDR

ANELLDR can update its encryption key to AES-256-CBC and re-encrypt its payload, overwriting the original payload file with the newly encrypted data.

T1027.013
Encrypted/Encoded File
MalwareKwampirs

Kwampirs downloads additional files that are base64-encoded and encrypted with another cipher.

T1027.013
Encrypted/Encoded File
MalwareDEADEYE

DEADEYE has encrypted its payload.

T1027.013
Encrypted/Encoded File
MalwareMango

Mango contains a series of base64 encoded substrings.

T1027.013
Encrypted/Encoded File
MalwareKessel

Kessel's configuration is hardcoded and RC4 encrypted within the binary.

T1027.013
Encrypted/Encoded File
MalwarePHASEJAM

PHASEJAM has launched a webshell using the `MIME::Base64` module that encoded and decoded Base64 commands.

T1027.013
Encrypted/Encoded File
MalwareYAHOYAH

YAHOYAH encrypts its configuration file using a simple algorithm.

T1027.013
Encrypted/Encoded File
MalwareStealBit

StealBit stores obfuscated DLL file names in its executable.

T1027.013
Encrypted/Encoded File
MalwareFELIXROOT

FELIXROOT encrypts strings in the backdoor using a custom XOR algorithm.

T1027.013
Encrypted/Encoded File
MalwarePenquin

Penquin has encrypted strings in the binary for obfuscation.

T1027.013
Encrypted/Encoded File
MalwareSPAWNCHIMERA

SPAWNCHIMERA has encoded a private key with XOR. SPAWNCHIMERA has also encrypted data to be extracted using AES encryption.

T1027.013
Encrypted/Encoded File
MalwareWinnti for Windows

Winnti for Windows has the ability to encrypt and compress its payload.

T1027.013
Encrypted/Encoded File
MalwarenjRAT

njRAT has included a base64 encoded executable.

T1027.013
Encrypted/Encoded File
MalwaremetaMain

metaMain's module file has been encrypted via XOR.

T1027.013
Encrypted/Encoded File
MalwareHeyoka Backdoor

Heyoka Backdoor can encrypt its payload.

T1027.013
Encrypted/Encoded File
MalwareLunarWeb

The LunarWeb install files have been encrypted with AES-256.

T1027.013
Encrypted/Encoded File
MalwareXCSSET

Older XCSSET variants use `xxd` to encode modules. Later versions pass an `xxd` or `base64` encoded blob through multiple decoding stages to reconstruct the module name, AppleScript, or shell command. For example, the initial network request uses three layers of hex decoding before executing a curl command in a shell.

T1027.013
Encrypted/Encoded File
MalwareQilin

Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings.

T1027.013
Encrypted/Encoded File
MalwareSTARWHALE

STARWHALE has been obfuscated with hex-encoded strings.

T1027.013
Encrypted/Encoded File
MalwareCozyCar

The payload of CozyCar is encrypted with simple XOR with a rotating key. The CozyCar configuration file has been encrypted with RC4 keys.

T1027.013
Encrypted/Encoded File
MalwareKevin

Kevin has Base64-encoded its configuration file.

T1027.013
Encrypted/Encoded File
MalwareDRYHOOK

DRYHOOK has encrypted stolen credentials strings within a file using both Base64 and RC4 with a hard-coded key.

T1027.013
Encrypted/Encoded File
MalwareRemexi

Remexi obfuscates its configuration data with XOR.

T1027.013
Encrypted/Encoded File
MalwareAstaroth

Astaroth has used an XOR-based algorithm to encrypt payloads twice with different keys.

T1027.013
Encrypted/Encoded File
MalwareDOWNIISSA

DOWNIISSA code is base64 encoded and XOR encrypted.

T1027.013
Encrypted/Encoded File
MalwareHelminth

The Helminth config file is encrypted with RC4.

T1027.013
Encrypted/Encoded File
MalwareDEADWOOD

DEADWOOD contains an embedded, AES-encrypted resource named METADATA that contains configuration information for follow-on execution.

T1027.013
Encrypted/Encoded File
MalwareWaterbear

Waterbear has used RC4 encrypted shellcode and encrypted functions.

T1027.013
Encrypted/Encoded File
MalwareFIVEHANDS

The FIVEHANDS payload is encrypted with AES-128.

T1027.013
Encrypted/Encoded File
MalwareLoudMiner

LoudMiner has encrypted DMG files.

T1027.013
Encrypted/Encoded File
MalwareBitPaymer

BitPaymer has used RC4-encrypted strings and string hashes to avoid identifiable strings within the binary.

T1027.013
Encrypted/Encoded File
MalwareZox

Zox has been encoded with Base64.

T1027.013
Encrypted/Encoded File
MalwareHiddenWasp

HiddenWasp encrypts its configuration and payload.

T1027.013
Encrypted/Encoded File
MalwareXORIndex Loader

XORIndex Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis.

T1027.013
Encrypted/Encoded File
MalwareHermeticWizard

HermeticWizard has the ability to encrypt PE files with a reverse XOR loop.

T1027.013
Encrypted/Encoded File
ToolSliver

Sliver can encrypt strings at compile time.

T1027.013
Encrypted/Encoded File
ToolDCRAT

The DCRAT configuration file is encrypted using AES-256.

T1027.013
Encrypted/Encoded File
ToolPcShare

PcShare has been encrypted with XOR using different 32-long Base16 strings.

T1027.013
Encrypted/Encoded File
ToolRemcos

Remcos can use string encryption to hinder analysis.

T1027.013
Encrypted/Encoded File
ToolDonut

Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules.

T1027.013
Encrypted/Encoded File
ToolIronNetInjector

IronNetInjector can obfuscate variable names, encrypt strings, as well as base64 encode and Rijndael encrypt payloads.

T1027.013
Encrypted/Encoded File
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has used multi-stage payloads with double Base64-encoded scripts to evade static analysis.

T1027.013
Encrypted/Encoded File
MalwareMini Shai-Hulud

Mini Shai-Hulud has used a hybrid AES-256-GCM and RSA OAEP-SHA256 encryption to archive gathered data. Mini Shai-Hulud has also utilized custom MD5-keystream XOR cipher to encrypt data. Mini Shai-Hulud has also been deployed via an obfuscated script using Bun JavaScript runtime.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.