ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.002×

73 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareTrickBot

TrickBot leverages a custom packer to obfuscate its functionality.

T1027.002
Software Packing
MalwareBLINDINGCAN

BLINDINGCAN has been packed with the UPX packer.

T1027.002
Software Packing
MalwareSpark

Spark has been packed with Enigma Protector to obfuscate its contents.

T1027.002
Software Packing
MalwareTorisma

Torisma has been packed with Iz4 compression.

T1027.002
Software Packing
Malwareyty

yty packs a plugin with UPX.

T1027.002
Software Packing
MalwareCOATHANGER

The first stage of COATHANGER is delivered as a packed file.

T1027.002
Software Packing
MalwareMisdat

Misdat was typically packed using UPX.

T1027.002
Software Packing
MalwareHeartCrypt

HeartCrypt can pack malicious Windows x86 and .NET payloads in order to evade detection.

T1027.002
Software Packing
MalwareAppleSeed

AppleSeed has used UPX packers for its payload DLL.

T1027.002
Software Packing
MalwareNETWIRE

NETWIRE has used .NET packer tools to evade detection.

T1027.002
Software Packing
MalwareGreyEnergy

GreyEnergy is packed for obfuscation.

T1027.002
Software Packing
MalwareEmotet

Emotet has used custom packers to protect its payloads.

T1027.002
Software Packing
MalwareTomiris

Tomiris has been packed with UPX.

T1027.002
Software Packing
MalwareMachete

Machete has been packed with NSIS.

T1027.002
Software Packing
MalwareSquirrelwaffle

Squirrelwaffle has been packed with a custom packer to hide payloads.

T1027.002
Software Packing
MalwareHildegard

Hildegard has packed ELF files into other binaries.

T1027.002
Software Packing
MalwareFYAnti

FYAnti has used ConfuserEx to pack its .NET module.

T1027.002
Software Packing
MalwareZeroT

Some ZeroT DLL files have been packed with UPX.

T1027.002
Software Packing
MalwareRaspberry Robin

Raspberry Robin contains multiple payloads that are packed for defense evasion purposes and unpacked on runtime.

T1027.002
Software Packing
MalwareRaindrop

Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm.

T1027.002
Software Packing
MalwareIcedID

IcedID has packed and encrypted its loader module.

T1027.002
Software Packing
MalwareVERMIN

VERMIN is initially packed.

T1027.002
Software Packing
MalwareDarkComet

DarkComet has the option to compress its payload using UPX or MPRESS.

T1027.002
Software Packing
MalwareFatDuke

FatDuke has been regularly repacked by its operators to create large binaries and evade detection.

T1027.002
Software Packing
MalwareLucifer

Lucifer has used UPX packed binaries.

T1027.002
Software Packing
MalwareDRATzarus

DRATzarus's dropper can be packed with UPX.

T1027.002
Software Packing
MalwareShimRat

ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack.

T1027.002
Software Packing
MalwareChina Chopper

China Chopper's client component is packed with UPX.

T1027.002
Software Packing
MalwareGoldMax

GoldMax has been packed for obfuscation.

T1027.002
Software Packing
MalwareCostaBricks

CostaBricks can implement a custom-built virtual machine mechanism to obfuscate its code.

T1027.002
Software Packing
MalwareHyperBro

HyperBro has the ability to pack its payload.

T1027.002
Software Packing
MalwareAnchor

Anchor has come with a packed payload.

T1027.002
Software Packing
MalwareBabuk

Versions of Babuk have been packed.

T1027.002
Software Packing
MalwareDyre

Dyre has been delivered with encrypted resources and must be unpacked for execution.

T1027.002
Software Packing
MalwareBisonal

Bisonal has used the MPRESS packer and similar tools for obfuscation.

T1027.002
Software Packing
MalwareS-Type

Some S-Type samples have been packed with UPX.

T1027.002
Software Packing
MalwareSeaDuke

SeaDuke has been packed with the UPX packer.

T1027.002
Software Packing
MalwareCuba

Cuba has a packed payload when delivered.

T1027.002
Software Packing
MalwareMongall

Mongall has been packed with Themida.

T1027.002
Software Packing
MalwareLockBit 3.0

LockBit 3.0 can use code packing to hinder analysis.

T1027.002
Software Packing
MalwareLatrodectus

The Latrodectus payload has been packed for obfuscation.

T1027.002
Software Packing
MalwareSaint Bot

Saint Bot has been packed using a dark market crypter.

T1027.002
Software Packing
MalwareSagerunex

Sagerunex has used VMProtect to pack and obscure itself.

T1027.002
Software Packing
MalwareUroburos

Uroburos uses a custom packer.

T1027.002
Software Packing
MalwareMetamorfo

Metamorfo has used VMProtect to pack and protect files.

T1027.002
Software Packing
MalwareTrojan.Karagany

Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer.

T1027.002
Software Packing
MalwareKONNI

KONNI has been packed for obfuscation.

T1027.002
Software Packing
MalwareRedLine Stealer

RedLine Stealer has used obfuscation tools such as DNGuard and Boxed App to pack their code.

T1027.002
Software Packing
MalwareOopsIE

OopsIE uses the SmartAssembly obfuscator to pack an embedded .Net Framework assembly used for C2.

T1027.002
Software Packing
MalwareSDBbot

SDBbot has used a packed installer file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.