ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.013×

40 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupElderwood

Elderwood has encrypted documents and malicious executables.

T1027.013
Encrypted/Encoded File
GroupKimsuky

Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads.

T1027.013
Encrypted/Encoded File
GroupmenuPass

menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40.

T1027.013
Encrypted/Encoded File
GroupAPT32

APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor.

T1027.013
Encrypted/Encoded File
GroupStorm-1811

Storm-1811 XOR encodes a Cobalt Strike installation payload in a DLL file that is decoded with a hardcoded key when called by a legitimate 7zip installation process.

T1027.013
Encrypted/Encoded File
GroupTeamTNT

TeamTNT has encrypted its binaries via AES and encoded files using Base64.

T1027.013
Encrypted/Encoded File
GroupAPT18

APT18 obfuscates strings in the payload.

T1027.013
Encrypted/Encoded File
GroupSidewinder

Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads.

T1027.013
Encrypted/Encoded File
GroupAPT39

APT39 has used malware to drop encrypted CAB files.

T1027.013
Encrypted/Encoded File
GroupContagious Interview

Contagious Interview has used hexadecimal string encoding to hide critical JavaScript module names, function names, and C2 URLs, which are decoded dynamically at runtime.

T1027.013
Encrypted/Encoded File
GroupTA2541

TA2541 has used compressed and char-encoded scripts in operations.

T1027.013
Encrypted/Encoded File
GroupMoses Staff

Moses Staff has used obfuscated web shells in their operations.

T1027.013
Encrypted/Encoded File
GroupOilRig

OilRig has encrypted and encoded data in its malware, including by using base64.

T1027.013
Encrypted/Encoded File
GroupHigaisa

Higaisa used Base64 encoded compressed payloads.

T1027.013
Encrypted/Encoded File
GroupTropic Trooper

Tropic Trooper has encrypted configuration files.

T1027.013
Encrypted/Encoded File
GroupPutter Panda

Droppers used by Putter Panda use RC4 or a 16-byte XOR key consisting of the bytes 0xA0 – 0xAF to obfuscate payloads.

T1027.013
Encrypted/Encoded File
GroupSaint Bear

Saint Bear initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader.

T1027.013
Encrypted/Encoded File
GroupLeviathan

Leviathan has obfuscated code using base64.

T1027.013
Encrypted/Encoded File
GroupGroup5

Group5 disguised its malicious binaries with several layers of obfuscation, including encrypting the files.

T1027.013
Encrypted/Encoded File
GroupBlue Mockingbird

Blue Mockingbird has obfuscated the wallet address in the payload binary.

T1027.013
Encrypted/Encoded File
GroupTA505

TA505 has password-protected malicious Word documents.

T1027.013
Encrypted/Encoded File
GroupBITTER

BITTER has used a RAR SFX dropper to deliver malware.

T1027.013
Encrypted/Encoded File
GroupMofang

Mofang has encrypted payloads before they are downloaded to victims.

T1027.013
Encrypted/Encoded File
GroupDark Caracal

Dark Caracal has obfuscated strings in Bandook by base64 encoding, and then encrypting them.

T1027.013
Encrypted/Encoded File
GroupMirrorFace

MirrorFace has used Base64 encoded shellcode in infection chains to evade detection.

T1027.013
Encrypted/Encoded File
GroupDarkhotel

Darkhotel has obfuscated code using RC4, XOR, and RSA.

T1027.013
Encrypted/Encoded File
GroupWhitefly

Whitefly has encrypted the payload used for C2.

T1027.013
Encrypted/Encoded File
GroupAPT28

APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4.

T1027.013
Encrypted/Encoded File
GroupMalteiro

Malteiro has used scripts encoded in Base64 certificates to distribute malware to victims.

T1027.013
Encrypted/Encoded File
GroupMetador

Metador has encrypted their payloads.

T1027.013
Encrypted/Encoded File
GroupFox Kitten

Fox Kitten has base64 encoded payloads to avoid detection.

T1027.013
Encrypted/Encoded File
GroupAPT-C-36

APT-C-36 has used encoded and obfuscated files, images, and executables.

T1027.013
Encrypted/Encoded File
GroupLazarus Group

Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names.

T1027.013
Encrypted/Encoded File
GroupTransparent Tribe

Transparent Tribe has dropped encoded executables on compromised hosts.

T1027.013
Encrypted/Encoded File
GroupMoonstone Sleet

Moonstone Sleet has used encrypted payloads within files for follow-on execution and defense evasion.

T1027.013
Encrypted/Encoded File
GroupInception

Inception has encrypted malware payloads dropped on victim machines with AES and RC4 encryption.

T1027.013
Encrypted/Encoded File
GroupMagic Hound

Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES.

T1027.013
Encrypted/Encoded File
GroupThreat Group-3390

A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder.

T1027.013
Encrypted/Encoded File
GroupAPT33

APT33 has used base64 to encode payloads.

T1027.013
Encrypted/Encoded File
GroupAPT19

APT19 used Base64 to obfuscate payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.