Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.009 Embedded Payloads |
MalwarePikabot | Pikabot further decrypts information embedded via steganography using AES-CBC with the same 32 bit key as initial XOR operations combined with the first 16 bytes of the encrypted data as an initialization vector. Other Pikabot variants include encrypted, chunked sections of the stage 2 payload in the initial loader |
| T1027.009 Embedded Payloads |
MalwaremacOS.OSAMiner | macOS.OSAMiner has embedded Stripped Payloads within another run-only Stripped Payloads. |
| T1027.009 Embedded Payloads |
MalwareEmotet | Emotet has dropped an embedded executable at `%Temp%\setup.exe`. Additionally, Emotet may embed entire code into other files. |
| T1027.009 Embedded Payloads |
MalwareDUSTTRAP | DUSTTRAP contains additional embedded DLLs and configuration files that are loaded into memory during execution. |
| T1027.009 Embedded Payloads |
MalwareBADHATCH | BADHATCH has an embedded second stage DLL payload within the first stage of the malware. |
| T1027.009 Embedded Payloads |
MalwareDUSTPAN | DUSTPAN decrypts and executes an embedded payload. |
| T1027.009 Embedded Payloads |
MalwareMoneybird | Moneybird contains a configuration blob embedded in the malware itself. |
| T1027.009 Embedded Payloads |
MalwareIcedID | IcedID has embedded malicious functionality in a legitimate DLL file. |
| T1027.009 Embedded Payloads |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can extract RC4 encrypted embedded payloads for privilege escalation. |
| T1027.009 Embedded Payloads |
MalwareMultiLayer Wiper | MultiLayer Wiper contains two binaries in its resources section, MultiList and MultiWip. MultiLayer Wiper drops and executes each of these items when run, then deletes them after execution. |
| T1027.009 Embedded Payloads |
MalwareNetwalker | Netwalker's DLL has been embedded within the PowerShell script in hex format. |
| T1027.009 Embedded Payloads |
MalwareSMOKEDHAM | The SMOKEDHAM source code is embedded in the dropper as an encrypted string. |
| T1027.009 Embedded Payloads |
MalwareUroburos | The Uroburos Queue file contains embedded executable files along with key material, communication channels, and modes of operation. |
| T1027.009 Embedded Payloads |
MalwareDEADEYE | The DEADEYE.EMBED variant of DEADEYE has the ability to embed payloads inside of a compiled binary. |
| T1027.009 Embedded Payloads |
MalwareComRAT | ComRAT has embedded a XOR encrypted communications module inside the orchestrator module. |
| T1027.009 Embedded Payloads |
MalwareDEADWOOD | DEADWOOD contains an embedded, AES-encrypted payload labeled |
| T1027.009 Embedded Payloads |
MalwareDtrack | Dtrack has used a dropper that embeds an encrypted payload as extra data. |
| T1027.009 Embedded Payloads |
ToolInvoke-PSImage | Invoke-PSImage can be used to embed payload data within a new image file. |
| T1027.009 Embedded Payloads |
MalwareCanisterWorm | CanisterWorm has used embedded second stage Base64-encoded payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.