ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.013×

13 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64.

T1027.013
Encrypted/Encoded File
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda stored installation payloads as encrypted files in hidden folders during RedDelta Modified PlugX Infection Chain Operations.

T1027.013
Encrypted/Encoded File
CampaignRedPenguin

During RedPenguin, UNC3886 generated Base64-encoded files in the FreeBSD shell environment of targeted Juniper devices.

T1027.013
Encrypted/Encoded File
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used Base64 to encode files with a custom key.

T1027.013
Encrypted/Encoded File
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded.

T1027.013
Encrypted/Encoded File
CampaignOperation Spalax

For Operation Spalax, the threat actors used XOR-encrypted payloads.

T1027.013
Encrypted/Encoded File
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus encrypts its dynamic library files (.dll) using RC4, and when loaded only decrypts specific portions of the file using the key `3jB(2bsG#@c7`.

T1027.013
Encrypted/Encoded File
CampaignCutting Edge

During Cutting Edge, threat actors used a Base64-encoded Python script to write a patched version of the Ivanti Connect Secure `dsls` binary.

T1027.013
Encrypted/Encoded File
CampaignShadowRay

During ShadowRay, threat actors used Base64-encrypted Python code to evade detection.

T1027.013
Encrypted/Encoded File
CampaignOuter Space

During Outer Space, OilRig deployed VBS droppers with obfuscated strings.

T1027.013
Encrypted/Encoded File
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized a Base64-encoded ZIP archive to prevent content analysis.

T1027.013
Encrypted/Encoded File
CampaignAPT41 DUST

APT41 DUST used encrypted payloads decrypted and executed in memory.

T1027.013
Encrypted/Encoded File
CampaignNight Dragon

During Night Dragon, threat actors used a DLL that included an XOR-encoded section.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.