ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.002×

23 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
GroupAPT38

APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants.

T1027.002
Software Packing
GroupElderwood

Elderwood has packed malware payloads before delivery to victims.

T1027.002
Software Packing
GroupGALLIUM

GALLIUM packed some payloads using different types of packers, both known and custom.

T1027.002
Software Packing
GroupAPT3

APT3 has been known to pack their tools.

T1027.002
Software Packing
GroupKimsuky

Kimsuky has packed malware with UPX.

T1027.002
Software Packing
GroupVolt Typhoon

Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine.

T1027.002
Software Packing
GroupPatchwork

A Patchwork payload was packed with UPX.

T1027.002
Software Packing
GroupAPT41

APT41 uses packers such as Themida to obfuscate malicious files.

T1027.002
Software Packing
GroupTeamTNT

TeamTNT has used UPX and Ezuri packer to pack its binaries.

T1027.002
Software Packing
GroupZIRCONIUM

ZIRCONIUM has used multi-stage packers for exploit code.

T1027.002
Software Packing
GroupRocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1027.002
Software Packing
GroupAPT39

APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection.

T1027.002
Software Packing
GroupTA2541

TA2541 has used a .NET packer to obfuscate malicious files.

T1027.002
Software Packing
GroupAoqin Dragon

Aoqin Dragon has used the Themida packer to obfuscate malicious payloads.

T1027.002
Software Packing
GroupThe White Company

The White Company has obfuscated their payloads through packing.

T1027.002
Software Packing
GroupSaint Bear

Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload.

T1027.002
Software Packing
GroupMoustachedBouncer

MoustachedBouncer has used malware plugins packed with Themida.

T1027.002
Software Packing
GroupStorm-0501

Storm-0501 has used Themida to pack Cobalt Strike payloads.

T1027.002
Software Packing
GroupTA505

TA505 has used UPX to obscure malicious code.

T1027.002
Software Packing
GroupAPT29

APT29 used UPX to pack files.

T1027.002
Software Packing
GroupDark Caracal

Dark Caracal has used UPX to pack Bandook.

T1027.002
Software Packing
GroupMedusa Group

Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard.

T1027.002
Software Packing
GroupThreat Group-3390

Threat Group-3390 has packed malware and tools, including using VMProtect.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.