Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.015 Compression |
GroupTA2541 | TA2541 has used compressed and char-encoded scripts in operations. |
| T1027.015 Compression |
GroupHigaisa | Higaisa used Base64 encoded compressed payloads. |
| T1027.015 Compression |
GroupLeviathan | Leviathan has obfuscated code using gzip compression. |
| T1027.015 Compression |
GroupMofang | Mofang has compressed the ShimRat executable within malicious email attachments. |
| T1027.015 Compression |
GroupMolerats | Molerats has delivered compressed executables within ZIP files to victims. |
| T1027.015 Compression |
GroupVOID MANTICORE | VOID MANTICORE has compressed their payloads by leveraging zip files. |
| T1027.015 Compression |
GroupWIRTE | WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation. |
| T1027.015 Compression |
GroupThreat Group-3390 | Threat Group-3390 malware is compressed with LZNT1 compression. |
| T1027.015 Compression |
MalwareNinja | Ninja has compressed its data with the LZSS algorithm. |
| T1027.015 Compression |
MalwareRCSession | RCSession can compress and obfuscate its strings to evade detection on a compromised host. |
| T1027.015 Compression |
MalwareWindTail | WindTail can be delivered as a compressed, encrypted, and encoded payload. |
| T1027.015 Compression |
MalwareThreatNeedle | ThreatNeedle has been compressed and obfuscated. |
| T1027.015 Compression |
MalwarePony | Pony attachments have been delivered via compressed archive files. |
| T1027.015 Compression |
MalwareBADHATCH | BADHATCH can be compressed with the ApLib algorithm. |
| T1027.015 Compression |
MalwarePUBLOAD | PUBLOAD has been delivered as compressed files within ZIP files to victims. |
| T1027.015 Compression |
MalwareShimRat | ShimRat has been delivered as a package that includes compressed DLL and shellcode payloads within a .dat file. |
| T1027.015 Compression |
MalwareSocGholish | The SocGholish JavaScript payload has been delivered within a compressed ZIP archive. |
| T1027.015 Compression |
MalwareLine Runner | Line Runner uses a ZIP payload that is automatically extracted with its contents, a LUA script, executed for initial execution via CVE-2024-20359. |
| T1027.015 Compression |
MalwareDarkWatchman | DarkWatchman has been delivered as compressed RAR payloads in ZIP files to victims. |
| T1027.015 Compression |
MalwareLODEINFO | LODEINFO components have been compressed with zip for delivery. |
| T1027.015 Compression |
MalwareKerrdown | Kerrdown can encrypt, encode, and compress multiple layers of shellcode. |
| T1027.015 Compression |
MalwareRTM | RTM has been delivered to targets as various archive files including ZIP, 7-ZIP, and RAR. |
| T1027.015 Compression |
MalwareStrelaStealer | StrelaStealer has been delivered via JScript files in a ZIP archive. |
| T1027.015 Compression |
MalwareHermeticWiper | HermeticWiper can compress 32-bit and 64-bit driver files with the Lempel-Ziv algorithm. |
| T1027.015 Compression |
MalwarePandora | Pandora has the ability to compress stings with QuickLZ. |
| T1027.015 Compression |
MalwareSUNBURST | SUNBURST strings were compressed and encoded in Base64. |
| T1027.015 Compression |
MalwareSamurai | Samurai can deliver its final payload as a compressed, encrypted and base64-encoded blob. |
| T1027.015 Compression |
MalwarePillowmint | Pillowmint has been compressed and stored within a registry key. |
| T1027.015 Compression |
MalwareWinnti for Windows | Winnti for Windows has the ability to encrypt and compress its payload. |
| T1027.015 Compression |
MalwareHancitor | Hancitor has delivered compressed payloads in ZIP files to victims. |
| T1027.015 Compression |
MalwareGelsemium | Gelsemium has the ability to compress its components. |
| T1027.015 Compression |
ToolPcShare | PcShare has been compressed with LZW algorithm. |
| T1027.015 Compression |
ToolDonut | Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules. |
| T1027.016 Junk Code Insertion |
GroupKimsuky | Kimsuky has obfuscated code by filling scripts with junk code and concatenating strings to hamper analysis and detection. |
| T1027.016 Junk Code Insertion |
GroupAPT32 | APT32 includes garbage code to mislead anti-malware software and researchers. |
| T1027.016 Junk Code Insertion |
GroupGamaredon Group | Gamaredon Group has obfuscated .NET executables by inserting junk code. |
| T1027.016 Junk Code Insertion |
GroupFIN7 | FIN7 has used random junk code to obfuscate malware code. |
| T1027.016 Junk Code Insertion |
GroupMustang Panda | Mustang Panda has used junk code within their DLL files to hinder analysis. |
| T1027.016 Junk Code Insertion |
GroupAPT-C-36 | APT-C-36 has used junk characters to obfuscate malicious scripts. |
| T1027.016 Junk Code Insertion |
Malwareyty | yty contains junk code in its binary, likely to confuse malware analysts. |
| T1027.016 Junk Code Insertion |
MalwarePony | Pony obfuscates memory flow by adding junk instructions when executing to make analysis more difficult. |
| T1027.016 Junk Code Insertion |
MalwareWastedLocker | WastedLocker contains junk code to increase its entropy and hide the actual code. |
| T1027.016 Junk Code Insertion |
MalwareZeroT | ZeroT has obfuscated DLLs and functions using dummy API calls inserted between real instructions. |
| T1027.016 Junk Code Insertion |
MalwareSamSam | SamSam has used garbage code to pad some of its malware components. |
| T1027.016 Junk Code Insertion |
MalwareFatDuke | FatDuke has been packed with junk code and strings. |
| T1027.016 Junk Code Insertion |
MalwareCORESHELL | CORESHELL contains unused machine instructions in a likely attempt to hinder analysis. |
| T1027.016 Junk Code Insertion |
MalwareNOOPLDR | NOOPLDR can insert junk code to obfuscate malicious payloads. |
| T1027.016 Junk Code Insertion |
MalwarePureCrypter | PureCrypter can insert junk code to avoid detection. |
| T1027.016 Junk Code Insertion |
MalwareXTunnel | A version of XTunnel introduced in July 2015 inserted junk code into the binary in a likely attempt to obfuscate it and bypass security products. |
| T1027.016 Junk Code Insertion |
MalwareLODEINFO | LODEINFO has inserted junk code to obstruct code analysis. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.