Polymorphic Code

T1027.014

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection. Polymorphic code is a type of software capable of changing its runtime footprint during code execution. With each execution of the software, the code is mutated into a different version of itself that achieves the same purpose or objective as the original. This functionality enables the malware to evade traditional signature-based defenses, such as antivirus and antimalware tools.
Other obfuscation techniques can be used in conjunction with polymorphic code to accomplish the intended effects, including using mutation engines to conduct actions such as Software Packing, Command Obfuscation, or Encrypted/Encoded File.

Detection rules0

Rules on DetectionCode tagged with T1027.014.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
MalwareBendyBear

BendyBear changes its runtime footprint during code execution to evade signature-based defenses.

References4

  1. polymorphic-blackberry Open source
    Blackberry. (n.d.). What is Polymorphic Malware?. Retrieved September 27, 2024.
  2. polymorphic-linkedin Open source
    Sherwin Akshay. (2024, May 28). Techniques for concealing malware and hindering analysis: Packing up and unpacking stuff. Retrieved September 27, 2024.
  3. polymorphic-medium Open source
    Shellseekercyber. (2024, January 7). Explainer: Packed Malware. Retrieved September 27, 2024.
  4. polymorphic-sentinelone Open source
    SentinelOne. (2023, March 18). What is Polymorphic Malware? Examples and Challenges. Retrieved September 27, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.