ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.010×

29 examples

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupKimsuky

Kimsuky has encoded malicious PowerShell scripts using Base64.

T1027.010
Command Obfuscation
GroupPatchwork

Patchwork has obfuscated a script with Crypto Obfuscator.

T1027.010
Command Obfuscation
GroupAPT32

APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell.

T1027.010
Command Obfuscation
GroupMuddyWater

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.

T1027.010
Command Obfuscation
GroupFIN6

FIN6 has used encoded PowerShell commands.

T1027.010
Command Obfuscation
GroupGamaredon Group

Gamaredon Group has used obfuscated or encrypted scripts.

T1027.010
Command Obfuscation
GroupLeafminer

Leafminer obfuscated scripts that were used on victim machines.

T1027.010
Command Obfuscation
GroupFIN7

FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands.

T1027.010
Command Obfuscation
GroupSandworm Team

Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor.

T1027.010
Command Obfuscation
GroupSidewinder

Sidewinder has used base64 encoding for scripts.

T1027.010
Command Obfuscation
GroupContagious Interview

Contagious Interview has obfuscated JavaScript code using Base64 and variable substitutions.

T1027.010
Command Obfuscation
GroupAquatic Panda

Aquatic Panda has encoded PowerShell commands in Base64.

T1027.010
Command Obfuscation
GroupTurla

Turla has used encryption (including salted 3DES via PowerSploit's Out-EncryptedScript.ps1), random variable names, and base64 encoding to obfuscate PowerShell commands and payloads.

T1027.010
Command Obfuscation
GroupTA505

TA505 has used base64 encoded PowerShell commands.

T1027.010
Command Obfuscation
GroupChimera

Chimera has encoded PowerShell commands.

T1027.010
Command Obfuscation
GroupMedusa Group

Medusa Group has obfuscated PowerShell scripts with Base64 encoding. Medusa Group has also obfuscated the code of dropped kernel drivers using a software known as Safengine Shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code.

T1027.010
Command Obfuscation
GroupTA551

TA551 has used obfuscated variable names in a JavaScript configuration file.

T1027.010
Command Obfuscation
GroupLazyScripter

LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques.

T1027.010
Command Obfuscation
GroupFox Kitten

Fox Kitten has base64 encoded scripts to avoid detection.

T1027.010
Command Obfuscation
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has executed base64 encoded PowerShell scripts on compromised hosts.

T1027.010
Command Obfuscation
GroupSilence

Silence has used environment variable string substitution for obfuscation.

T1027.010
Command Obfuscation
GroupCobalt Group

Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4.

T1027.010
Command Obfuscation
GroupWizard Spider

Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands.

T1027.010
Command Obfuscation
GroupPlay

Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.

T1027.010
Command Obfuscation
GroupHEXANE

HEXANE has used Base64-encoded scripts.

T1027.010
Command Obfuscation
GroupWIRTE

WIRTE has XOR encrypted command line strings to conceal malware execution chains.

T1027.010
Command Obfuscation
GroupMagic Hound

Magic Hound has used base64-encoded commands.

T1027.010
Command Obfuscation
GroupFIN8

FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads.

T1027.010
Command Obfuscation
GroupAPT19

APT19 used Base64 to obfuscate executed commands.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.