Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.003 Steganography |
MalwarePowerDuke | PowerDuke uses steganography to hide backdoors in PNG files, which are also encrypted using the Tiny Encryption Algorithm (TEA). |
| T1027.003 Steganography |
MalwarePikabot | Pikabot loads a set of PNG images stored in the malware's resources section (RCDATA), each with an encrypted section containing portions of the core Pikabot core module. These sections are loaded and decrypted using a bitwise XOR operation with a hardcoded 32 bit key. |
| T1027.003 Steganography |
MalwareAvenger | Avenger can extract backdoor malware from downloaded images. |
| T1027.003 Steganography |
MalwarePolyglotDuke | PolyglotDuke can use steganography to hide C2 information in images. |
| T1027.003 Steganography |
MalwareRegDuke | RegDuke can hide data in images, including use of the Least Significant Bit (LSB). |
| T1027.003 Steganography |
MalwareProLock | ProLock can use .jpg and .bmp files to store its payload. |
| T1027.003 Steganography |
MalwareRDAT | RDAT can also embed data within a BMP image prior to exfiltration. |
| T1027.003 Steganography |
MalwareOkrum | Okrum's payload is encrypted and embedded within its loader, or within a legitimate PNG file. |
| T1027.003 Steganography |
MalwareDiavol | Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques. |
| T1027.003 Steganography |
MalwareRaindrop | Raindrop used steganography to locate the start of its encoded payload within legitimate 7-Zip code. |
| T1027.003 Steganography |
MalwareIcedID | IcedID has embedded binaries within RC4 encrypted .png files. |
| T1027.003 Steganography |
MalwareObliqueRAT | ObliqueRAT can hide its payload in BMP images hosted on compromised websites. |
| T1027.003 Steganography |
MalwareBandook | Bandook has used .PNG images within a zip file to build the executable. |
| T1027.003 Steganography |
MalwareLiteDuke | LiteDuke has used image files to hide its loader component. |
| T1027.003 Steganography |
MalwareABK | ABK can extract a malicious Portable Executable (PE) from a photo. |
| T1027.003 Steganography |
MalwareRamsay | Ramsay has PE data embedded within JPEG files contained within Word documents. |
| T1027.003 Steganography |
Malwarebuild_downer | build_downer can extract malware from a downloaded JPEG. |
| T1027.003 Steganography |
MalwareBBK | BBK can extract a malicious Portable Executable (PE) from a photo. |
| T1027.003 Steganography |
ToolInvoke-PSImage | Invoke-PSImage can be used to embed a PowerShell script within the pixels of a PNG file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.