Compile After Delivery

T1027.004

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe, csc.exe, or GCC/MinGW.

Source code payloads may also be encrypted, encoded, and/or embedded within other files, such as those delivered as a Phishing. Payloads may also be delivered in formats unrecognizable and inherently benign to the native OS (ex: EXEs on macOS/Linux) before later being (re)compiled into a proper executable binary with a bundled compiler and execution framework.

Detection rules7

Rules on DetectionCode tagged with T1027.004.

Sigma5

RuleLevelLog source
Csc.EXE Execution Form Potentially Suspicious Parenthighwindows / process_creation
Visual Basic Command Line Compiler Usagehighwindows / process_creation
Dynamic .NET Compilation Via Csc.EXEmediumwindows / process_creation
Potential Application Whitelisting Bypass via Dnx.EXEmediumwindows / process_creation
Dynamic CSharp Compile Artefactlowwindows / file_event

Splunk2

RuleTypeRiskData source
CSC Net On The Fly CompilationHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Linux Suspicious GCC Invocation Building Init Shared ObjectTTPNULLSysmon for Linux EventID 1

Groups4

Software6

Campaigns0

None recorded.

Procedure examples10

Groups4

Used byProcedure example
GroupGamaredon Group

Gamaredon Group has compiled the source code for a downloader directly on the infected system using the built-in Microsoft.CSharp.CSharpCodeProvider class.

GroupMuddyWater

MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code.

GroupRocke

Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC).

GroupSea Turtle

Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments.

Software6

Used byProcedure example
MalwareCardinal RAT

Cardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code.

MalwareDarkWatchman

DarkWatchman has used the csc.exe tool to compile a C# executable.

MalwareFoggyWeb

FoggyWeb can compile and execute source code sent to the compromised AD FS server via a specific HTTP POST.

MalwarenjRAT

njRAT has used AutoIt to compile the payload and main script into a single executable after delivery.

MalwareSamurai

Samurai can compile and execute downloaded modules at runtime.

ToolSliver

Sliver includes functionality to retrieve source code and compile locally prior to execution in victim environments.

References3

  1. ATTACK IQ Open source
    Federico Quattrin, Nick Desler, Tin Tam, & Matthew Rutkoske. (2023, March 16). Hiding in Plain Sight: Monitoring and Testing for Living-Off-the-Land Binaries. Retrieved July 15, 2024.
  2. ClearSky MuddyWater Nov 2018 Open source
    ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.
  3. TrendMicro WindowsAppMac Open source
    Trend Micro. (2019, February 11). Windows App Runs on Mac, Downloads Info Stealer and Adware. Retrieved April 25, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.