Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.005 VNC |
GroupGamaredon Group | Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts. |
| T1021.005 VNC |
GroupFIN7 | FIN7 has used TightVNC to control compromised hosts. |
| T1021.005 VNC |
GroupFox Kitten | Fox Kitten has installed TightVNC server and client on compromised servers and endpoints for lateral movement. |
| T1021.006 Windows Remote Management |
GroupStorm-0501 | Storm-0501 has utilized the post-exploitation tool known as Evil-WinRM that uses PowerShell over Windows Remote Management (WinRM) for remote code execution. |
| T1021.006 Windows Remote Management |
GroupChimera | Chimera has used WinRM for lateral movement. |
| T1021.006 Windows Remote Management |
GroupWizard Spider | Wizard Spider has used Window Remote Management to move laterally through a victim network. |
| T1021.006 Windows Remote Management |
GroupThreat Group-3390 | Threat Group-3390 has used WinRM to enable remote execution. |
| T1021.006 Windows Remote Management |
GroupFIN13 | FIN13 has leveraged `WMI` to move laterally within a compromised network via application servers and SQL servers. |
| T1021.007 Cloud Services |
GroupScattered Spider | Scattered Spider has also leveraged pre-existing AWS EC2 instances for lateral movement and data collection purposes. |
| T1021.007 Cloud Services |
GroupStorm-0501 | Storm-0501 has used compromised Entra Connect Sync Server to move laterally within the victim environment. |
| T1021.007 Cloud Services |
GroupAPT29 | APT29 has leveraged compromised high-privileged on-premises accounts synced to Office 365 to move laterally into a cloud environment, including through the use of Azure AD PowerShell. |
| T1025 Data from Removable Media |
GroupGamaredon Group | A Gamaredon Group file stealer has the capability to steal data from newly connected logical volumes on a system, including USB drives. |
| T1025 Data from Removable Media |
GroupOilRig | OilRig has used Wireshark’s usbcapcmd utility to capture USB traffic. |
| T1025 Data from Removable Media |
GroupTurla | Turla RPC backdoors can collect files from USB thumb drives. |
| T1025 Data from Removable Media |
GroupAPT28 | An APT28 backdoor may collect the entire contents of an inserted USB device. |
| T1027 Obfuscated Files or Information |
GroupGALLIUM | GALLIUM used a modified version of HTRAN in which they obfuscated strings such as debug messages in an apparent attempt to evade detection. |
| T1027 Obfuscated Files or Information |
GroupAPT3 | APT3 obfuscates files or information to help evade defensive measures. |
| T1027 Obfuscated Files or Information |
GroupKimsuky | Kimsuky has obfuscated binary strings including the use of XOR encryption and Base64 encoding. Kimsuky has also modified the first byte of DLL implants targeting victims to prevent recognition of the executable file format. Kimsuky has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions that complicate static analysis. |
| T1027 Obfuscated Files or Information |
GroupAPT41 | APT41 used VMProtected binaries in multiple intrusions. |
| T1027 Obfuscated Files or Information |
GroupGamaredon Group | Gamaredon Group has delivered self-extracting 7z archive files within malicious document attachments. Additionally, Gamaredon Group has used an obfuscated .drv file. |
| T1027 Obfuscated Files or Information |
GroupGallmaker | Gallmaker obfuscated shellcode used during execution. |
| T1027 Obfuscated Files or Information |
GroupSandworm Team | Sandworm Team has used Base64 encoding within malware variants. |
| T1027 Obfuscated Files or Information |
GroupMustang Panda | Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadAnomali MUSTANG PANDA October 2019Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018Eset PlugX Korplug Mustang Panda March 2022Proofpoint TA416 Europe March 2022Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Sophos PlugX September 2022Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1027 Obfuscated Files or Information |
GroupRocke | Rocke has modified UPX headers after packing files to break unpackers. |
| T1027 Obfuscated Files or Information |
GroupAPT37 | APT37 obfuscates strings and payloads. |
| T1027 Obfuscated Files or Information |
GroupKe3chang | Ke3chang has used Base64-encoded shellcode strings. |
| T1027 Obfuscated Files or Information |
GroupRedCurl | RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files. |
| T1027 Obfuscated Files or Information |
GroupBackdoorDiplomacy | BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect. |
| T1027 Obfuscated Files or Information |
GroupWindshift | Windshift has used string encoding with floating point calculations. |
| T1027 Obfuscated Files or Information |
GroupAPT-C-36 | APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats. |
| T1027 Obfuscated Files or Information |
GroupEarth Lusca | Earth Lusca used Base64 to encode strings. |
| T1027 Obfuscated Files or Information |
GroupBlackOasis | BlackOasis's first stage shellcode contains a NOP sled with alternative instructions that was likely designed to bypass antivirus tools. |
| T1027 Obfuscated Files or Information |
GroupMoonstone Sleet | Moonstone Sleet delivers encrypted payloads in pieces that are then combined together to form a new portable executable (PE) file during installation. |
| T1027.001 Binary Padding |
GroupKimsuky | Kimsuky has performed padding of PowerShell command line code with over 100 spaces. |
| T1027.001 Binary Padding |
GroupPatchwork | Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes. |
| T1027.001 Binary Padding |
GroupMoafee | Moafee has been known to employ binary padding. |
| T1027.001 Binary Padding |
GroupAkira | Akira has used binary padding to obfuscate payloads. |
| T1027.001 Binary Padding |
GroupHigaisa | Higaisa performed padding with null bytes before calculating its hash. |
| T1027.001 Binary Padding |
GroupLeviathan | Leviathan has inserted garbage characters into code, presumably to avoid anti-virus detection. |
| T1027.001 Binary Padding |
GroupAPT29 | APT29 used large size files to avoid detection by security solutions with hardcoded size limits. |
| T1027.001 Binary Padding |
GroupBRONZE BUTLER | BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection. |
| T1027.002 Software Packing |
GroupAPT38 | APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants. |
| T1027.002 Software Packing |
GroupElderwood | Elderwood has packed malware payloads before delivery to victims. |
| T1027.002 Software Packing |
GroupGALLIUM | GALLIUM packed some payloads using different types of packers, both known and custom. |
| T1027.002 Software Packing |
GroupAPT3 | APT3 has been known to pack their tools. |
| T1027.002 Software Packing |
GroupKimsuky | Kimsuky has packed malware with UPX. |
| T1027.002 Software Packing |
GroupVolt Typhoon | Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine. |
| T1027.002 Software Packing |
GroupPatchwork | A Patchwork payload was packed with UPX. |
| T1027.002 Software Packing |
GroupAPT41 | APT41 uses packers such as Themida to obfuscate malicious files. |
| T1027.002 Software Packing |
GroupTeamTNT | TeamTNT has used UPX and Ezuri packer to pack its binaries. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.