Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe, csc.exe, or GCC/MinGW.
Source code payloads may also be encrypted, encoded, and/or embedded within other files, such as those delivered as a Phishing. Payloads may also be delivered in formats unrecognizable and inherently benign to the native OS (ex: EXEs on macOS/Linux) before later being (re)compiled into a proper executable binary with a bundled compiler and execution framework.
Rules on DetectionCode tagged with T1027.004.
| Rule | Level | Log source |
|---|---|---|
| Csc.EXE Execution Form Potentially Suspicious Parent | high | windows / process_creation |
| Visual Basic Command Line Compiler Usage | high | windows / process_creation |
| Dynamic .NET Compilation Via Csc.EXE | medium | windows / process_creation |
| Potential Application Whitelisting Bypass via Dnx.EXE | medium | windows / process_creation |
| Dynamic CSharp Compile Artefact | low | windows / file_event |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| CSC Net On The Fly Compilation | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Linux Suspicious GCC Invocation Building Init Shared Object | TTP | NULL | Sysmon for Linux EventID 1 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupGamaredon Group | Gamaredon Group has compiled the source code for a downloader directly on the infected system using the built-in |
| GroupMuddyWater | MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code. |
| GroupRocke | Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC). |
| GroupSea Turtle | Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments. |
| Used by | Procedure example |
|---|---|
| MalwareCardinal RAT | Cardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code. |
| MalwareDarkWatchman | DarkWatchman has used the |
| MalwareFoggyWeb | FoggyWeb can compile and execute source code sent to the compromised AD FS server via a specific HTTP POST. |
| MalwarenjRAT | njRAT has used AutoIt to compile the payload and main script into a single executable after delivery. |
| MalwareSamurai | Samurai can compile and execute downloaded modules at runtime. |
| ToolSliver | Sliver includes functionality to retrieve source code and compile locally prior to execution in victim environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.