Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.003 Steganography |
GroupMuddyWater | MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg. |
| T1027.003 Steganography |
GroupAndariel | Andariel has hidden malicious executables within PNG files. |
| T1027.003 Steganography |
GroupAPT37 | APT37 uses steganography to send images to users that are embedded with shellcode. |
| T1027.003 Steganography |
GroupTropic Trooper | Tropic Trooper has used JPG files with encrypted payloads to mask their backdoor routines and evade detection. |
| T1027.003 Steganography |
GroupLeviathan | Leviathan has used steganography to hide stolen data inside other files stored on Github. |
| T1027.003 Steganography |
GroupBRONZE BUTLER | BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads. |
| T1027.003 Steganography |
GroupTA551 | TA551 has hidden encoded data for malware DLLs in a PNG. |
| T1027.003 Steganography |
GroupAPT-C-36 | APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files. |
| T1027.003 Steganography |
GroupEarth Lusca | Earth Lusca has used steganography to hide shellcode in a BMP image file. |
| T1027.003 Steganography |
GroupTeamPCP | TeamPCP has hidden malicious payloads in the frame data of WAV audio files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.