ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1027.015
Compression
GroupTA2541

TA2541 has used compressed and char-encoded scripts in operations.

T1027.015
Compression
GroupHigaisa

Higaisa used Base64 encoded compressed payloads.

T1027.015
Compression
GroupLeviathan

Leviathan has obfuscated code using gzip compression.

T1027.015
Compression
GroupMofang

Mofang has compressed the ShimRat executable within malicious email attachments.

T1027.015
Compression
GroupMolerats

Molerats has delivered compressed executables within ZIP files to victims.

T1027.015
Compression
GroupVOID MANTICORE

VOID MANTICORE has compressed their payloads by leveraging zip files.

T1027.015
Compression
GroupWIRTE

WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation.

T1027.015
Compression
GroupThreat Group-3390

Threat Group-3390 malware is compressed with LZNT1 compression.

T1027.015
Compression
MalwareNinja

Ninja has compressed its data with the LZSS algorithm.

T1027.015
Compression
MalwareRCSession

RCSession can compress and obfuscate its strings to evade detection on a compromised host.

T1027.015
Compression
MalwareWindTail

WindTail can be delivered as a compressed, encrypted, and encoded payload.

T1027.015
Compression
MalwareThreatNeedle

ThreatNeedle has been compressed and obfuscated.

T1027.015
Compression
MalwarePony

Pony attachments have been delivered via compressed archive files.

T1027.015
Compression
MalwareBADHATCH

BADHATCH can be compressed with the ApLib algorithm.

T1027.015
Compression
MalwarePUBLOAD

PUBLOAD has been delivered as compressed files within ZIP files to victims.

T1027.015
Compression
MalwareShimRat

ShimRat has been delivered as a package that includes compressed DLL and shellcode payloads within a .dat file.

T1027.015
Compression
MalwareSocGholish

The SocGholish JavaScript payload has been delivered within a compressed ZIP archive.

T1027.015
Compression
MalwareLine Runner

Line Runner uses a ZIP payload that is automatically extracted with its contents, a LUA script, executed for initial execution via CVE-2024-20359.

T1027.015
Compression
MalwareDarkWatchman

DarkWatchman has been delivered as compressed RAR payloads in ZIP files to victims.

T1027.015
Compression
MalwareLODEINFO

LODEINFO components have been compressed with zip for delivery.

T1027.015
Compression
MalwareKerrdown

Kerrdown can encrypt, encode, and compress multiple layers of shellcode.

T1027.015
Compression
MalwareRTM

RTM has been delivered to targets as various archive files including ZIP, 7-ZIP, and RAR.

T1027.015
Compression
MalwareStrelaStealer

StrelaStealer has been delivered via JScript files in a ZIP archive.

T1027.015
Compression
MalwareHermeticWiper

HermeticWiper can compress 32-bit and 64-bit driver files with the Lempel-Ziv algorithm.

T1027.015
Compression
MalwarePandora

Pandora has the ability to compress stings with QuickLZ.

T1027.015
Compression
MalwareSUNBURST

SUNBURST strings were compressed and encoded in Base64.

T1027.015
Compression
MalwareSamurai

Samurai can deliver its final payload as a compressed, encrypted and base64-encoded blob.

T1027.015
Compression
MalwarePillowmint

Pillowmint has been compressed and stored within a registry key.

T1027.015
Compression
MalwareWinnti for Windows

Winnti for Windows has the ability to encrypt and compress its payload.

T1027.015
Compression
MalwareHancitor

Hancitor has delivered compressed payloads in ZIP files to victims.

T1027.015
Compression
MalwareGelsemium

Gelsemium has the ability to compress its components.

T1027.015
Compression
ToolPcShare

PcShare has been compressed with LZW algorithm.

T1027.015
Compression
ToolDonut

Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules.

T1027.016
Junk Code Insertion
GroupKimsuky

Kimsuky has obfuscated code by filling scripts with junk code and concatenating strings to hamper analysis and detection.

T1027.016
Junk Code Insertion
GroupAPT32

APT32 includes garbage code to mislead anti-malware software and researchers.

T1027.016
Junk Code Insertion
GroupGamaredon Group

Gamaredon Group has obfuscated .NET executables by inserting junk code.

T1027.016
Junk Code Insertion
GroupFIN7

FIN7 has used random junk code to obfuscate malware code.

T1027.016
Junk Code Insertion
GroupMustang Panda

Mustang Panda has used junk code within their DLL files to hinder analysis.

T1027.016
Junk Code Insertion
GroupAPT-C-36

APT-C-36 has used junk characters to obfuscate malicious scripts.

T1027.016
Junk Code Insertion
Malwareyty

yty contains junk code in its binary, likely to confuse malware analysts.

T1027.016
Junk Code Insertion
MalwarePony

Pony obfuscates memory flow by adding junk instructions when executing to make analysis more difficult.

T1027.016
Junk Code Insertion
MalwareWastedLocker

WastedLocker contains junk code to increase its entropy and hide the actual code.

T1027.016
Junk Code Insertion
MalwareZeroT

ZeroT has obfuscated DLLs and functions using dummy API calls inserted between real instructions.

T1027.016
Junk Code Insertion
MalwareSamSam

SamSam has used garbage code to pad some of its malware components.

T1027.016
Junk Code Insertion
MalwareFatDuke

FatDuke has been packed with junk code and strings.

T1027.016
Junk Code Insertion
MalwareCORESHELL

CORESHELL contains unused machine instructions in a likely attempt to hinder analysis.

T1027.016
Junk Code Insertion
MalwareNOOPLDR

NOOPLDR can insert junk code to obfuscate malicious payloads.

T1027.016
Junk Code Insertion
MalwarePureCrypter

PureCrypter can insert junk code to avoid detection.

T1027.016
Junk Code Insertion
MalwareXTunnel

A version of XTunnel introduced in July 2015 inserted junk code into the binary in a likely attempt to obfuscate it and bypass security products.

T1027.016
Junk Code Insertion
MalwareLODEINFO

LODEINFO has inserted junk code to obstruct code analysis.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.