Real-world descriptions of how a group, tool or campaign used a technique.
40 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupElderwood | Elderwood has encrypted documents and malicious executables. |
| T1027.013 Encrypted/Encoded File |
GroupKimsuky | Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads. |
| T1027.013 Encrypted/Encoded File |
GroupmenuPass | menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40. |
| T1027.013 Encrypted/Encoded File |
GroupAPT32 | APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor. |
| T1027.013 Encrypted/Encoded File |
GroupStorm-1811 | Storm-1811 XOR encodes a Cobalt Strike installation payload in a DLL file that is decoded with a hardcoded key when called by a legitimate 7zip installation process. |
| T1027.013 Encrypted/Encoded File |
GroupTeamTNT | TeamTNT has encrypted its binaries via AES and encoded files using Base64. |
| T1027.013 Encrypted/Encoded File |
GroupAPT18 | APT18 obfuscates strings in the payload. |
| T1027.013 Encrypted/Encoded File |
GroupSidewinder | Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads. |
| T1027.013 Encrypted/Encoded File |
GroupAPT39 | APT39 has used malware to drop encrypted CAB files. |
| T1027.013 Encrypted/Encoded File |
GroupContagious Interview | Contagious Interview has used hexadecimal string encoding to hide critical JavaScript module names, function names, and C2 URLs, which are decoded dynamically at runtime. |
| T1027.013 Encrypted/Encoded File |
GroupTA2541 | TA2541 has used compressed and char-encoded scripts in operations. |
| T1027.013 Encrypted/Encoded File |
GroupMoses Staff | Moses Staff has used obfuscated web shells in their operations. |
| T1027.013 Encrypted/Encoded File |
GroupOilRig | OilRig has encrypted and encoded data in its malware, including by using base64. |
| T1027.013 Encrypted/Encoded File |
GroupHigaisa | Higaisa used Base64 encoded compressed payloads. |
| T1027.013 Encrypted/Encoded File |
GroupTropic Trooper | Tropic Trooper has encrypted configuration files. |
| T1027.013 Encrypted/Encoded File |
GroupPutter Panda | Droppers used by Putter Panda use RC4 or a 16-byte XOR key consisting of the bytes 0xA0 – 0xAF to obfuscate payloads. |
| T1027.013 Encrypted/Encoded File |
GroupSaint Bear | Saint Bear initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader. |
| T1027.013 Encrypted/Encoded File |
GroupLeviathan | Leviathan has obfuscated code using base64. |
| T1027.013 Encrypted/Encoded File |
GroupGroup5 | Group5 disguised its malicious binaries with several layers of obfuscation, including encrypting the files. |
| T1027.013 Encrypted/Encoded File |
GroupBlue Mockingbird | Blue Mockingbird has obfuscated the wallet address in the payload binary. |
| T1027.013 Encrypted/Encoded File |
GroupTA505 | TA505 has password-protected malicious Word documents. |
| T1027.013 Encrypted/Encoded File |
GroupBITTER | BITTER has used a RAR SFX dropper to deliver malware. |
| T1027.013 Encrypted/Encoded File |
GroupMofang | Mofang has encrypted payloads before they are downloaded to victims. |
| T1027.013 Encrypted/Encoded File |
GroupDark Caracal | Dark Caracal has obfuscated strings in Bandook by base64 encoding, and then encrypting them. |
| T1027.013 Encrypted/Encoded File |
GroupMirrorFace | MirrorFace has used Base64 encoded shellcode in infection chains to evade detection. |
| T1027.013 Encrypted/Encoded File |
GroupDarkhotel | Darkhotel has obfuscated code using RC4, XOR, and RSA. |
| T1027.013 Encrypted/Encoded File |
GroupWhitefly | Whitefly has encrypted the payload used for C2. |
| T1027.013 Encrypted/Encoded File |
GroupAPT28 | APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4. |
| T1027.013 Encrypted/Encoded File |
GroupMalteiro | Malteiro has used scripts encoded in Base64 certificates to distribute malware to victims. |
| T1027.013 Encrypted/Encoded File |
GroupMetador | Metador has encrypted their payloads. |
| T1027.013 Encrypted/Encoded File |
GroupFox Kitten | Fox Kitten has base64 encoded payloads to avoid detection. |
| T1027.013 Encrypted/Encoded File |
GroupAPT-C-36 | APT-C-36 has used encoded and obfuscated files, images, and executables. |
| T1027.013 Encrypted/Encoded File |
GroupLazarus Group | Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names. |
| T1027.013 Encrypted/Encoded File |
GroupTransparent Tribe | Transparent Tribe has dropped encoded executables on compromised hosts. |
| T1027.013 Encrypted/Encoded File |
GroupMoonstone Sleet | Moonstone Sleet has used encrypted payloads within files for follow-on execution and defense evasion. |
| T1027.013 Encrypted/Encoded File |
GroupInception | Inception has encrypted malware payloads dropped on victim machines with AES and RC4 encryption. |
| T1027.013 Encrypted/Encoded File |
GroupMagic Hound | Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES. |
| T1027.013 Encrypted/Encoded File |
GroupThreat Group-3390 | A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder. |
| T1027.013 Encrypted/Encoded File |
GroupAPT33 | APT33 has used base64 to encode payloads. |
| T1027.013 Encrypted/Encoded File |
GroupAPT19 | APT19 used Base64 to obfuscate payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.