Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64. |
| T1027.013 Encrypted/Encoded File |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda stored installation payloads as encrypted files in hidden folders during RedDelta Modified PlugX Infection Chain Operations. |
| T1027.013 Encrypted/Encoded File |
CampaignRedPenguin | During RedPenguin, UNC3886 generated Base64-encoded files in the FreeBSD shell environment of targeted Juniper devices. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used Base64 to encode files with a custom key. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Spalax | For Operation Spalax, the threat actors used XOR-encrypted payloads. |
| T1027.013 Encrypted/Encoded File |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus encrypts its dynamic library files (.dll) using RC4, and when loaded only decrypts specific portions of the file using the key `3jB(2bsG#@c7`. |
| T1027.013 Encrypted/Encoded File |
CampaignCutting Edge | During Cutting Edge, threat actors used a Base64-encoded Python script to write a patched version of the Ivanti Connect Secure `dsls` binary. |
| T1027.013 Encrypted/Encoded File |
CampaignShadowRay | During ShadowRay, threat actors used Base64-encrypted Python code to evade detection. |
| T1027.013 Encrypted/Encoded File |
CampaignOuter Space | During Outer Space, OilRig deployed VBS droppers with obfuscated strings. |
| T1027.013 Encrypted/Encoded File |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized a Base64-encoded ZIP archive to prevent content analysis. |
| T1027.013 Encrypted/Encoded File |
CampaignAPT41 DUST | APT41 DUST used encrypted payloads decrypted and executed in memory. |
| T1027.013 Encrypted/Encoded File |
CampaignNight Dragon | During Night Dragon, threat actors used a DLL that included an XOR-encoded section. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.