Real-world descriptions of how a group, tool or campaign used a technique.
29 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupKimsuky | Kimsuky has encoded malicious PowerShell scripts using Base64. |
| T1027.010 Command Obfuscation |
GroupPatchwork | Patchwork has obfuscated a script with Crypto Obfuscator. |
| T1027.010 Command Obfuscation |
GroupAPT32 | APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell. |
| T1027.010 Command Obfuscation |
GroupMuddyWater | MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupFIN6 | FIN6 has used encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupGamaredon Group | Gamaredon Group has used obfuscated or encrypted scripts. |
| T1027.010 Command Obfuscation |
GroupLeafminer | Leafminer obfuscated scripts that were used on victim machines. |
| T1027.010 Command Obfuscation |
GroupFIN7 | FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands. |
| T1027.010 Command Obfuscation |
GroupSandworm Team | Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor. |
| T1027.010 Command Obfuscation |
GroupSidewinder | Sidewinder has used base64 encoding for scripts. |
| T1027.010 Command Obfuscation |
GroupContagious Interview | Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions. |
| T1027.010 Command Obfuscation |
GroupAquatic Panda | Aquatic Panda has encoded PowerShell commands in Base64. |
| T1027.010 Command Obfuscation |
GroupTurla | Turla has used encryption (including salted 3DES via PowerSploit's |
| T1027.010 Command Obfuscation |
GroupTA505 | TA505 has used base64 encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupChimera | Chimera has encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupMedusa Group | Medusa Group has obfuscated PowerShell scripts with Base64 encoding. Medusa Group has also obfuscated the code of dropped kernel drivers using a software known as Safengine Shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code. |
| T1027.010 Command Obfuscation |
GroupTA551 | TA551 has used obfuscated variable names in a JavaScript configuration file. |
| T1027.010 Command Obfuscation |
GroupLazyScripter | LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques. |
| T1027.010 Command Obfuscation |
GroupFox Kitten | Fox Kitten has base64 encoded scripts to avoid detection. |
| T1027.010 Command Obfuscation |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has executed base64 encoded PowerShell scripts on compromised hosts. |
| T1027.010 Command Obfuscation |
GroupSilence | Silence has used environment variable string substitution for obfuscation. |
| T1027.010 Command Obfuscation |
GroupCobalt Group | Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4. |
| T1027.010 Command Obfuscation |
GroupWizard Spider | Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands. |
| T1027.010 Command Obfuscation |
GroupPlay | Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts. |
| T1027.010 Command Obfuscation |
GroupHEXANE | HEXANE has used Base64-encoded scripts. |
| T1027.010 Command Obfuscation |
GroupWIRTE | WIRTE has XOR encrypted command line strings to conceal malware execution chains. |
| T1027.010 Command Obfuscation |
GroupMagic Hound | Magic Hound has used base64-encoded commands. |
| T1027.010 Command Obfuscation |
GroupFIN8 | FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads. |
| T1027.010 Command Obfuscation |
GroupAPT19 | APT19 used Base64 to obfuscate executed commands. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.