Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
GroupGALLIUM | GALLIUM used a modified version of HTRAN in which they obfuscated strings such as debug messages in an apparent attempt to evade detection. |
| T1027 Obfuscated Files or Information |
GroupAPT3 | APT3 obfuscates files or information to help evade defensive measures. |
| T1027 Obfuscated Files or Information |
GroupKimsuky | Kimsuky has obfuscated binary strings including the use of XOR encryption and Base64 encoding. Kimsuky has also modified the first byte of DLL implants targeting victims to prevent recognition of the executable file format. Kimsuky has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions that complicate static analysis. |
| T1027 Obfuscated Files or Information |
GroupAPT41 | APT41 used VMProtected binaries in multiple intrusions. |
| T1027 Obfuscated Files or Information |
GroupGamaredon Group | Gamaredon Group has delivered self-extracting 7z archive files within malicious document attachments. Additionally, Gamaredon Group has used an obfuscated .drv file. |
| T1027 Obfuscated Files or Information |
GroupGallmaker | Gallmaker obfuscated shellcode used during execution. |
| T1027 Obfuscated Files or Information |
GroupSandworm Team | Sandworm Team has used Base64 encoding within malware variants. |
| T1027 Obfuscated Files or Information |
GroupMustang Panda | Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadAnomali MUSTANG PANDA October 2019Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018Eset PlugX Korplug Mustang Panda March 2022Proofpoint TA416 Europe March 2022Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Sophos PlugX September 2022Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1027 Obfuscated Files or Information |
GroupRocke | Rocke has modified UPX headers after packing files to break unpackers. |
| T1027 Obfuscated Files or Information |
GroupAPT37 | APT37 obfuscates strings and payloads. |
| T1027 Obfuscated Files or Information |
GroupKe3chang | Ke3chang has used Base64-encoded shellcode strings. |
| T1027 Obfuscated Files or Information |
GroupRedCurl | RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files. |
| T1027 Obfuscated Files or Information |
GroupBackdoorDiplomacy | BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect. |
| T1027 Obfuscated Files or Information |
GroupWindshift | Windshift has used string encoding with floating point calculations. |
| T1027 Obfuscated Files or Information |
GroupAPT-C-36 | APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats. |
| T1027 Obfuscated Files or Information |
GroupEarth Lusca | Earth Lusca used Base64 to encode strings. |
| T1027 Obfuscated Files or Information |
GroupBlackOasis | BlackOasis's first stage shellcode contains a NOP sled with alternative instructions that was likely designed to bypass antivirus tools. |
| T1027 Obfuscated Files or Information |
GroupMoonstone Sleet | Moonstone Sleet delivers encrypted payloads in pieces that are then combined together to form a new portable executable (PE) file during installation. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.