ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027.003×

19 examples

TechniqueUsed byProcedure example
T1027.003
Steganography
MalwarePowerDuke

PowerDuke uses steganography to hide backdoors in PNG files, which are also encrypted using the Tiny Encryption Algorithm (TEA).

T1027.003
Steganography
MalwarePikabot

Pikabot loads a set of PNG images stored in the malware's resources section (RCDATA), each with an encrypted section containing portions of the core Pikabot core module. These sections are loaded and decrypted using a bitwise XOR operation with a hardcoded 32 bit key.

T1027.003
Steganography
MalwareAvenger

Avenger can extract backdoor malware from downloaded images.

T1027.003
Steganography
MalwarePolyglotDuke

PolyglotDuke can use steganography to hide C2 information in images.

T1027.003
Steganography
MalwareRegDuke

RegDuke can hide data in images, including use of the Least Significant Bit (LSB).

T1027.003
Steganography
MalwareProLock

ProLock can use .jpg and .bmp files to store its payload.

T1027.003
Steganography
MalwareRDAT

RDAT can also embed data within a BMP image prior to exfiltration.

T1027.003
Steganography
MalwareOkrum

Okrum's payload is encrypted and embedded within its loader, or within a legitimate PNG file.

T1027.003
Steganography
MalwareDiavol

Diavol has obfuscated its main code routines within bitmap images as part of its anti-analysis techniques.

T1027.003
Steganography
MalwareRaindrop

Raindrop used steganography to locate the start of its encoded payload within legitimate 7-Zip code.

T1027.003
Steganography
MalwareIcedID

IcedID has embedded binaries within RC4 encrypted .png files.

T1027.003
Steganography
MalwareObliqueRAT

ObliqueRAT can hide its payload in BMP images hosted on compromised websites.

T1027.003
Steganography
MalwareBandook

Bandook has used .PNG images within a zip file to build the executable.

T1027.003
Steganography
MalwareLiteDuke

LiteDuke has used image files to hide its loader component.

T1027.003
Steganography
MalwareABK

ABK can extract a malicious Portable Executable (PE) from a photo.

T1027.003
Steganography
MalwareRamsay

Ramsay has PE data embedded within JPEG files contained within Word documents.

T1027.003
Steganography
Malwarebuild_downer

build_downer can extract malware from a downloaded JPEG.

T1027.003
Steganography
MalwareBBK

BBK can extract a malicious Portable Executable (PE) from a photo.

T1027.003
Steganography
ToolInvoke-PSImage

Invoke-PSImage can be used to embed a PowerShell script within the pixels of a PNG file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.