Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org
Adversaries may embed payloads within other files to conceal malicious content from defenses. Otherwise seemingly benign files (such as scripts and executables) may be abused to carry and obfuscate malicious payloads and content. In some cases, embedded payloads may also enable adversaries to Subvert Trust Controls by not impacting execution controls such as digital signatures and notarization tickets.
Adversaries may embed payloads in various file formats to hide payloads. This is similar to Steganography, though does not involve weaving malicious content into specific bytes and patterns related to legitimate digital media formats.
For example, adversaries have been observed embedding payloads within or as an overlay of an otherwise benign binary. Adversaries have also been observed nesting payloads (such as executables and run-only scripts) inside a file of the same format.
Embedded content may also be used as Process Injection payloads used to infect benign system processes. These embedded then injected payloads may be used as part of the modules of malware designed to provide specific features such as encrypting C2 communications in support of an orchestrator module. For example, an embedded module may be injected into default browsers, allowing adversaries to then communicate via the network.
Rules on DetectionCode tagged with T1027.009.
| Rule | Level | Log source |
|---|---|---|
| Powershell Token Obfuscation - Powershell | high | windows / ps_script |
| Powershell Token Obfuscation - Process Creation | high | windows / process_creation |
| Used by | Procedure example |
|---|---|
| GroupLazarus Group | Lazarus Group has distributed malicious payloads embedded in PNG files. |
| GroupMoonstone Sleet | Moonstone Sleet embedded payloads in trojanized software for follow-on execution. |
| GroupTA577 | TA577 has used LNK files to execute embedded DLLs. |
| Used by | Procedure example |
|---|---|
| MalwareBADHATCH | BADHATCH has an embedded second stage DLL payload within the first stage of the malware. |
| MalwareCanisterWorm | CanisterWorm has used embedded second stage Base64-encoded payloads. |
| MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can extract RC4 encrypted embedded payloads for privilege escalation. |
| MalwareComRAT | ComRAT has embedded a XOR encrypted communications module inside the orchestrator module. |
| MalwareDEADEYE | The DEADEYE.EMBED variant of DEADEYE has the ability to embed payloads inside of a compiled binary. |
| MalwareDEADWOOD | DEADWOOD contains an embedded, AES-encrypted payload labeled |
| MalwareDtrack | Dtrack has used a dropper that embeds an encrypted payload as extra data. |
| MalwareDUSTPAN | DUSTPAN decrypts and executes an embedded payload. |
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus uses embedded .dll as apart of a chained delivery mechanism to invoke the COM class factory. |
| CampaignC0021 | For C0021, the threat actors embedded a base64-encoded payload within a LNK file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.