ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.003×

10 examples

TechniqueUsed byProcedure example
T1027.003
Steganography
GroupMuddyWater

MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg.

T1027.003
Steganography
GroupAndariel

Andariel has hidden malicious executables within PNG files.

T1027.003
Steganography
GroupAPT37

APT37 uses steganography to send images to users that are embedded with shellcode.

T1027.003
Steganography
GroupTropic Trooper

Tropic Trooper has used JPG files with encrypted payloads to mask their backdoor routines and evade detection.

T1027.003
Steganography
GroupLeviathan

Leviathan has used steganography to hide stolen data inside other files stored on Github.

T1027.003
Steganography
GroupBRONZE BUTLER

BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads.

T1027.003
Steganography
GroupTA551

TA551 has hidden encoded data for malware DLLs in a PNG.

T1027.003
Steganography
GroupAPT-C-36

APT-C-36 has used steganography to hide malicious code, typically in the resource section of executable files.

T1027.003
Steganography
GroupEarth Lusca

Earth Lusca has used steganography to hide shellcode in a BMP image file.

T1027.003
Steganography
GroupTeamPCP

TeamPCP has hidden malicious payloads in the frame data of WAV audio files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.