Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
GroupAPT38 | APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants. |
| T1027.002 Software Packing |
GroupElderwood | Elderwood has packed malware payloads before delivery to victims. |
| T1027.002 Software Packing |
GroupGALLIUM | GALLIUM packed some payloads using different types of packers, both known and custom. |
| T1027.002 Software Packing |
GroupAPT3 | APT3 has been known to pack their tools. |
| T1027.002 Software Packing |
GroupKimsuky | Kimsuky has packed malware with UPX. |
| T1027.002 Software Packing |
GroupVolt Typhoon | Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine. |
| T1027.002 Software Packing |
GroupPatchwork | A Patchwork payload was packed with UPX. |
| T1027.002 Software Packing |
GroupAPT41 | APT41 uses packers such as Themida to obfuscate malicious files. |
| T1027.002 Software Packing |
GroupTeamTNT | TeamTNT has used UPX and Ezuri packer to pack its binaries. |
| T1027.002 Software Packing |
GroupZIRCONIUM | ZIRCONIUM has used multi-stage packers for exploit code. |
| T1027.002 Software Packing |
GroupRocke | Rocke's miner has created UPX-packed files in the Windows Start Menu Folder. |
| T1027.002 Software Packing |
GroupAPT39 | APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection. |
| T1027.002 Software Packing |
GroupTA2541 | TA2541 has used a .NET packer to obfuscate malicious files. |
| T1027.002 Software Packing |
GroupAoqin Dragon | Aoqin Dragon has used the Themida packer to obfuscate malicious payloads. |
| T1027.002 Software Packing |
GroupThe White Company | The White Company has obfuscated their payloads through packing. |
| T1027.002 Software Packing |
GroupSaint Bear | Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload. |
| T1027.002 Software Packing |
GroupMoustachedBouncer | MoustachedBouncer has used malware plugins packed with Themida. |
| T1027.002 Software Packing |
GroupStorm-0501 | Storm-0501 has used Themida to pack Cobalt Strike payloads. |
| T1027.002 Software Packing |
GroupTA505 | TA505 has used UPX to obscure malicious code. |
| T1027.002 Software Packing |
GroupAPT29 | APT29 used UPX to pack files. |
| T1027.002 Software Packing |
GroupDark Caracal | Dark Caracal has used UPX to pack Bandook. |
| T1027.002 Software Packing |
GroupMedusa Group | Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard. |
| T1027.002 Software Packing |
GroupThreat Group-3390 | Threat Group-3390 has packed malware and tools, including using VMProtect. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.