Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwarePoetRAT | PoetRAT has `pyminifier` to obfuscate scripts. |
| T1027.010 Command Obfuscation |
MalwarePowerPunch | PowerPunch can use Base64-encoded scripts. |
| T1027.010 Command Obfuscation |
MalwareComRAT | ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts. |
| T1027.010 Command Obfuscation |
MalwareIceApple | IceApple can use Base64 and "junk" JavaScript code to obfuscate information. |
| T1027.010 Command Obfuscation |
MalwareKOCTOPUS | KOCTOPUS has obfuscated scripts with the BatchEncryption tool. |
| T1027.010 Command Obfuscation |
MalwarePOWERSTATS | POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation |
| T1027.010 Command Obfuscation |
MalwareAstaroth | Astaroth has obfuscated and randomized parts of the JScript code it is initiating. |
| T1027.010 Command Obfuscation |
MalwareQakBot | QakBot can use obfuscated and encoded scripts. |
| T1027.010 Command Obfuscation |
MalwareCookieMiner | CookieMiner has used base64 encoding to obfuscate scripts on the system. |
| T1027.010 Command Obfuscation |
MalwareDenis | Denis has encoded its PowerShell commands in Base64. |
| T1027.010 Command Obfuscation |
MalwareLoudMiner | LoudMiner has obfuscated various scripts. |
| T1027.010 Command Obfuscation |
MalwareXORIndex Loader | XORIndex Loader has obfuscated strings using ASCII buffers and TextDecoder. |
| T1027.010 Command Obfuscation |
ToolPowerSploit | PowerSploit contains a collection of ScriptModification modules that compress and encode scripts and payloads. |
| T1027.010 Command Obfuscation |
ToolEmpire | Empire has the ability to obfuscate commands using |
| T1027.011 Fileless Storage |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors stroed payloads in Windows CLFS (Common Log File System) transactional logs. |
| T1027.011 Fileless Storage |
CampaignQuad7 Activity | Quad7 Activity has infected victim network devices by storing artifacts in the |
| T1027.011 Fileless Storage |
GroupAPT32 | APT32's backdoor has stored its configuration in a registry key. |
| T1027.011 Fileless Storage |
GroupTurla | Turla has used the Registry to store encrypted and encoded payloads. |
| T1027.011 Fileless Storage |
MalwarePikabot | Some versions of Pikabot build the final PE payload in memory to avoid writing contents to disk on the executing machine. |
| T1027.011 Fileless Storage |
MalwareRCSession | RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`. |
| T1027.011 Fileless Storage |
MalwareExaramel for Windows | Exaramel for Windows stores the backdoor's configuration in the Registry in XML format. |
| T1027.011 Fileless Storage |
MalwareThreatNeedle | ThreatNeedle can save its configuration data as a RC4-encrypted Registry key under `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`. |
| T1027.011 Fileless Storage |
MalwareNETWIRE | NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`. |
| T1027.011 Fileless Storage |
MalwareTinyTurla | TinyTurla can save its configuration parameters in the Registry. |
| T1027.011 Fileless Storage |
MalwarePolyglotDuke | PolyglotDuke can store encrypted JSON configuration files in the Registry. |
| T1027.011 Fileless Storage |
MalwareRegDuke | RegDuke can store its encryption key in the Registry. |
| T1027.011 Fileless Storage |
MalwareVolgmer | Volgmer stores an encoded configuration file in |
| T1027.011 Fileless Storage |
MalwareDarkWatchman | DarkWatchman can store configuration strings, keylogger, and output of components in the Registry. |
| T1027.011 Fileless Storage |
MalwareChaes | Some versions of Chaes stored its instructions (otherwise in a `instructions.ini` file) in the Registry. |
| T1027.011 Fileless Storage |
MalwareTYPEFRAME | TYPEFRAME can install and store encrypted configuration data under the Registry key |
| T1027.011 Fileless Storage |
MalwareQUADAGENT | QUADAGENT stores a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications within a Registry key (such as `HKCU\Office365DCOMCheck`) in the `HKCU` hive. |
| T1027.011 Fileless Storage |
MalwareUroburos | Uroburos can store configuration information for the kernel driver and kernel driver loader components in an encrypted blob typically found at `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds.` |
| T1027.011 Fileless Storage |
MalwarePipeMon | PipeMon has stored its encrypted payload in the Registry under `HKLM\SOFTWARE\Microsoft\Print\Components\`. |
| T1027.011 Fileless Storage |
MalwareMosquito | Mosquito stores configuration values under the Registry key |
| T1027.011 Fileless Storage |
MalwareGrandoreiro | Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including |
| T1027.011 Fileless Storage |
MalwareSibot | Sibot has installed a second-stage script in the |
| T1027.011 Fileless Storage |
MalwareREvil | REvil can save encryption parameters and system information in the Registry. |
| T1027.011 Fileless Storage |
MalwareValak | Valak has the ability to store information regarding the C2 server and downloads in the Registry key |
| T1027.011 Fileless Storage |
MalwarePillowmint | Pillowmint has stored a compressed payload in the Registry key |
| T1027.011 Fileless Storage |
MalwareSysUpdate | SysUpdate can store its encoded configuration file within |
| T1027.011 Fileless Storage |
MalwareCHOPSTICK | CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry. |
| T1027.011 Fileless Storage |
MalwareComRAT | ComRAT has stored encrypted orchestrator code and payloads in the Registry. |
| T1027.011 Fileless Storage |
MalwareShadowPad | ShadowPad maintains a configuration block and virtual file system in the Registry. |
| T1027.011 Fileless Storage |
MalwareQakBot | QakBot can store its configuration information in a randomly named subkey under |
| T1027.011 Fileless Storage |
MalwareGelsemium | Gelsemium can store its components in the Registry. |
| T1027.012 LNK Icon Smuggling |
GroupKimsuky | Kimsuky has used the LNK icon location to execute malicious scripts. Kimsuky has also padded the LNK target field properties with extra spaces to obscure the script. |
| T1027.012 LNK Icon Smuggling |
GroupGamaredon Group | Gamaredon Group has used LNK files to hide malicious scripts for execution. |
| T1027.012 LNK Icon Smuggling |
GroupMustang Panda | Mustang Panda has utilized LNK files to hide malicious scripts for execution. Mustang Panda has also leveraged LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary. |
| T1027.012 LNK Icon Smuggling |
MalwareTONESHELL | TONESHELL has been initiated using LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.