Embedded Payloads

T1027.009

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may embed payloads within other files to conceal malicious content from defenses. Otherwise seemingly benign files (such as scripts and executables) may be abused to carry and obfuscate malicious payloads and content. In some cases, embedded payloads may also enable adversaries to Subvert Trust Controls by not impacting execution controls such as digital signatures and notarization tickets.

Adversaries may embed payloads in various file formats to hide payloads. This is similar to Steganography, though does not involve weaving malicious content into specific bytes and patterns related to legitimate digital media formats.

For example, adversaries have been observed embedding payloads within or as an overlay of an otherwise benign binary. Adversaries have also been observed nesting payloads (such as executables and run-only scripts) inside a file of the same format.

Embedded content may also be used as Process Injection payloads used to infect benign system processes. These embedded then injected payloads may be used as part of the modules of malware designed to provide specific features such as encrypting C2 communications in support of an orchestrator module. For example, an embedded module may be injected into default browsers, allowing adversaries to then communicate via the network.

Detection rules2

Rules on DetectionCode tagged with T1027.009.

Sigma2

RuleLevelLog source
Powershell Token Obfuscation - Powershellhighwindows / ps_script
Powershell Token Obfuscation - Process Creationhighwindows / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software19

Campaigns2

Procedure examples24

Groups3

Used byProcedure example
GroupLazarus Group

Lazarus Group has distributed malicious payloads embedded in PNG files.

GroupMoonstone Sleet

Moonstone Sleet embedded payloads in trojanized software for follow-on execution.

GroupTA577

TA577 has used LNK files to execute embedded DLLs.

Software19

Used byProcedure example
MalwareBADHATCH

BADHATCH has an embedded second stage DLL payload within the first stage of the malware.

MalwareCanisterWorm

CanisterWorm has used embedded second stage Base64-encoded payloads.

MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can extract RC4 encrypted embedded payloads for privilege escalation.

MalwareComRAT

ComRAT has embedded a XOR encrypted communications module inside the orchestrator module.

MalwareDEADEYE

The DEADEYE.EMBED variant of DEADEYE has the ability to embed payloads inside of a compiled binary.

MalwareDEADWOOD

DEADWOOD contains an embedded, AES-encrypted payload labeled METADATA that provides configuration information for follow-on execution.

MalwareDtrack

Dtrack has used a dropper that embeds an encrypted payload as extra data.

MalwareDUSTPAN

DUSTPAN decrypts and executes an embedded payload.

View all 19 software examples

Campaigns2

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus uses embedded .dll as apart of a chained delivery mechanism to invoke the COM class factory.

CampaignC0021

For C0021, the threat actors embedded a base64-encoded payload within a LNK file.

References7

  1. GitHub PSImage Open source
    Barrett Adams . (n.d.). Invoke-PSImage . Retrieved September 30, 2022.
  2. Malware Analysis Report ComRAT Open source
    CISA. (2020, October 29). Malware Analysis Report (AR20-303A) MAR-10310246-2.v1 – PowerShell Script: ComRAT. Retrieved September 30, 2022.
  3. Microsoft Learn Open source
    Microsoft. (2021, April 6). 2.5 ExtraData. Retrieved September 30, 2022.
  4. Securelist Dtrack2 Open source
    KONSTANTIN ZYKOV. (2019, September 23). Hello! My name is Dtrack. Retrieved September 30, 2022.
  5. Sentinel Labs Open source
    Phil Stokes. (2021, January 11). FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts. Retrieved September 30, 2022.
  6. SentinelLabs reversing run-only applescripts 2021 Open source
    Phil Stokes. (2021, January 11). FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts. Retrieved September 29, 2022.
  7. Trend Micro Open source
    Karen Victor. (2020, May 18). Reflective Loading Runs Netwalker Fileless Ransomware. Retrieved September 30, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.