Real-world descriptions of how a group, tool or campaign used a technique.
195 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareMore_eggs | More_eggs's payload has been encrypted with a key that has the hostname and processor family information appended to the end. |
| T1027.013 Encrypted/Encoded File |
MalwareSysUpdate | SysUpdate can encrypt and encode its configuration file. |
| T1027.013 Encrypted/Encoded File |
MalwareANELLDR | ANELLDR can update its encryption key to AES-256-CBC and re-encrypt its payload, overwriting the original payload file with the newly encrypted data. |
| T1027.013 Encrypted/Encoded File |
MalwareKwampirs | Kwampirs downloads additional files that are base64-encoded and encrypted with another cipher. |
| T1027.013 Encrypted/Encoded File |
MalwareDEADEYE | DEADEYE has encrypted its payload. |
| T1027.013 Encrypted/Encoded File |
MalwareMango | Mango contains a series of base64 encoded substrings. |
| T1027.013 Encrypted/Encoded File |
MalwareKessel | Kessel's configuration is hardcoded and RC4 encrypted within the binary. |
| T1027.013 Encrypted/Encoded File |
MalwarePHASEJAM | PHASEJAM has launched a webshell using the `MIME::Base64` module that encoded and decoded Base64 commands. |
| T1027.013 Encrypted/Encoded File |
MalwareYAHOYAH | YAHOYAH encrypts its configuration file using a simple algorithm. |
| T1027.013 Encrypted/Encoded File |
MalwareStealBit | StealBit stores obfuscated DLL file names in its executable. |
| T1027.013 Encrypted/Encoded File |
MalwareFELIXROOT | FELIXROOT encrypts strings in the backdoor using a custom XOR algorithm. |
| T1027.013 Encrypted/Encoded File |
MalwarePenquin | Penquin has encrypted strings in the binary for obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has encoded a private key with XOR. SPAWNCHIMERA has also encrypted data to be extracted using AES encryption. |
| T1027.013 Encrypted/Encoded File |
MalwareWinnti for Windows | Winnti for Windows has the ability to encrypt and compress its payload. |
| T1027.013 Encrypted/Encoded File |
MalwarenjRAT | njRAT has included a base64 encoded executable. |
| T1027.013 Encrypted/Encoded File |
MalwaremetaMain | metaMain's module file has been encrypted via XOR. |
| T1027.013 Encrypted/Encoded File |
MalwareHeyoka Backdoor | Heyoka Backdoor can encrypt its payload. |
| T1027.013 Encrypted/Encoded File |
MalwareLunarWeb | The LunarWeb install files have been encrypted with AES-256. |
| T1027.013 Encrypted/Encoded File |
MalwareXCSSET | Older XCSSET variants use `xxd` to encode modules. Later versions pass an `xxd` or `base64` encoded blob through multiple decoding stages to reconstruct the module name, AppleScript, or shell command. For example, the initial network request uses three layers of hex decoding before executing a curl command in a shell. |
| T1027.013 Encrypted/Encoded File |
MalwareQilin | Qilin can employ several code obfuscation methods, including renaming functions, altering control flows, and encrypting strings. |
| T1027.013 Encrypted/Encoded File |
MalwareSTARWHALE | STARWHALE has been obfuscated with hex-encoded strings. |
| T1027.013 Encrypted/Encoded File |
MalwareCozyCar | The payload of CozyCar is encrypted with simple XOR with a rotating key. The CozyCar configuration file has been encrypted with RC4 keys. |
| T1027.013 Encrypted/Encoded File |
MalwareKevin | Kevin has Base64-encoded its configuration file. |
| T1027.013 Encrypted/Encoded File |
MalwareDRYHOOK | DRYHOOK has encrypted stolen credentials strings within a file using both Base64 and RC4 with a hard-coded key. |
| T1027.013 Encrypted/Encoded File |
MalwareRemexi | Remexi obfuscates its configuration data with XOR. |
| T1027.013 Encrypted/Encoded File |
MalwareAstaroth | Astaroth has used an XOR-based algorithm to encrypt payloads twice with different keys. |
| T1027.013 Encrypted/Encoded File |
MalwareDOWNIISSA | DOWNIISSA code is base64 encoded and XOR encrypted. |
| T1027.013 Encrypted/Encoded File |
MalwareHelminth | The Helminth config file is encrypted with RC4. |
| T1027.013 Encrypted/Encoded File |
MalwareDEADWOOD | DEADWOOD contains an embedded, AES-encrypted resource named |
| T1027.013 Encrypted/Encoded File |
MalwareWaterbear | Waterbear has used RC4 encrypted shellcode and encrypted functions. |
| T1027.013 Encrypted/Encoded File |
MalwareFIVEHANDS | The FIVEHANDS payload is encrypted with AES-128. |
| T1027.013 Encrypted/Encoded File |
MalwareLoudMiner | LoudMiner has encrypted DMG files. |
| T1027.013 Encrypted/Encoded File |
MalwareBitPaymer | BitPaymer has used RC4-encrypted strings and string hashes to avoid identifiable strings within the binary. |
| T1027.013 Encrypted/Encoded File |
MalwareZox | Zox has been encoded with Base64. |
| T1027.013 Encrypted/Encoded File |
MalwareHiddenWasp | HiddenWasp encrypts its configuration and payload. |
| T1027.013 Encrypted/Encoded File |
MalwareXORIndex Loader | XORIndex Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis. |
| T1027.013 Encrypted/Encoded File |
MalwareHermeticWizard | HermeticWizard has the ability to encrypt PE files with a reverse XOR loop. |
| T1027.013 Encrypted/Encoded File |
ToolSliver | Sliver can encrypt strings at compile time. |
| T1027.013 Encrypted/Encoded File |
ToolDCRAT | The DCRAT configuration file is encrypted using AES-256. |
| T1027.013 Encrypted/Encoded File |
ToolPcShare | PcShare has been encrypted with XOR using different 32-long Base16 strings. |
| T1027.013 Encrypted/Encoded File |
ToolRemcos | Remcos can use string encryption to hinder analysis. |
| T1027.013 Encrypted/Encoded File |
ToolDonut | Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules. |
| T1027.013 Encrypted/Encoded File |
ToolIronNetInjector | IronNetInjector can obfuscate variable names, encrypt strings, as well as base64 encode and Rijndael encrypt payloads. |
| T1027.013 Encrypted/Encoded File |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has used multi-stage payloads with double Base64-encoded scripts to evade static analysis. |
| T1027.013 Encrypted/Encoded File |
MalwareMini Shai-Hulud | Mini Shai-Hulud has used a hybrid AES-256-GCM and RSA OAEP-SHA256 encryption to archive gathered data. Mini Shai-Hulud has also utilized custom MD5-keystream XOR cipher to encrypt data. Mini Shai-Hulud has also been deployed via an obfuscated script using Bun JavaScript runtime. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.