Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareBoxCaon | BoxCaon used the "StackStrings" obfuscation technique to hide malicious functionalities. |
| T1027 Obfuscated Files or Information |
MalwareNightClub | NightClub can obfuscate strings using the congruential generator `(LCG): staten+1 = (690069 × staten + 1) mod 232`. |
| T1027 Obfuscated Files or Information |
MalwareSDBbot | SDBbot has the ability to XOR the strings for its installer component with a hardcoded 128 byte key. |
| T1027 Obfuscated Files or Information |
MalwareRTM | RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm. |
| T1027 Obfuscated Files or Information |
MalwareSodaMaster | SodaMaster can use "stackstrings" for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareStrelaStealer | StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives. |
| T1027 Obfuscated Files or Information |
MalwareDrovorub | Drovorub has used XOR encrypted payloads in WebSocket client to server messages. |
| T1027 Obfuscated Files or Information |
MalwareKobalos | Kobalos encrypts all strings using RC4 and bundles all functionality into a single function call. |
| T1027 Obfuscated Files or Information |
MalwareRyuk | Ryuk can use anti-disassembly and code transformation obfuscation techniques. |
| T1027 Obfuscated Files or Information |
MalwareFinal1stspy | Final1stspy obfuscates strings with base64 encoding. |
| T1027 Obfuscated Files or Information |
MalwareFinFisher | FinFisher is heavily obfuscated in many ways, including through the use of spaghetti code in its functions in an effort to confuse disassembly programs. It also uses a custom XOR algorithm to obfuscate code. |
| T1027 Obfuscated Files or Information |
MalwareCobalt Strike | Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata. |
| T1027 Obfuscated Files or Information |
MalwareSUNBURST | SUNBURST obfuscated collected system information using a FNV-1a + XOR algorithm. |
| T1027 Obfuscated Files or Information |
MalwareValak | Valak has the ability to base64 encode and XOR encrypt strings. |
| T1027 Obfuscated Files or Information |
MalwareSamurai | Samurai can encrypt the names of requested APIs. |
| T1027 Obfuscated Files or Information |
MalwarePoisonIvy | PoisonIvy hides any strings related to its own indicators of compromise. |
| T1027 Obfuscated Files or Information |
MalwareNanoCore | NanoCore’s plugins were obfuscated with Eazfuscater.NET 3.3. |
| T1027 Obfuscated Files or Information |
MalwareTajMahal | TajMahal has used an encrypted Virtual File System to store plugins. |
| T1027 Obfuscated Files or Information |
MalwareDaserf | Daserf uses encrypted Windows APIs and also encrypts data using the alternative base64+RC4 or the Caesar cipher. |
| T1027 Obfuscated Files or Information |
MalwareCarbon | Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm. |
| T1027 Obfuscated Files or Information |
MalwarePisloader | Pisloader obfuscates files by splitting strings into smaller sub-strings and including "garbage" strings that are never used. The malware also uses return-oriented programming (ROP) technique and single-byte XOR to obfuscate data. |
| T1027 Obfuscated Files or Information |
MalwareRamsay | Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. Ramsay can also embed information within document footers. |
| T1027 Obfuscated Files or Information |
MalwarePillowmint | Pillowmint has obfuscated the AES key used for encryption. |
| T1027 Obfuscated Files or Information |
MalwareSUNSPOT | SUNSPOT encrypted log entries it collected with the stream cipher RC4 using a hard-coded key. It also uses AES128-CBC encrypted blobs for SUNBURST source code and data extracted from the SolarWinds Orion <MsBuild.exe</code> process. |
| T1027 Obfuscated Files or Information |
MalwareANELLDR | ANELLDR code implements anti-analysis techniques including control flow flattening and Mixed Boolean Arithmetic (MBA). |
| T1027 Obfuscated Files or Information |
MalwareBoomBox | BoomBox can encrypt data using AES prior to exfiltration. |
| T1027 Obfuscated Files or Information |
MalwarePUNCHTRACK | PUNCHTRACK is loaded and executed by a highly obfuscated launcher. |
| T1027 Obfuscated Files or Information |
MalwareInnaputRAT | InnaputRAT uses an 8-byte XOR key to obfuscate API names and other strings contained in the payload. |
| T1027 Obfuscated Files or Information |
MalwareGrimAgent | GrimAgent has used Rotate on Right (RoR) and Rotate on Left (RoL) functionality to encrypt strings. |
| T1027 Obfuscated Files or Information |
MalwareLokibot | Lokibot has obfuscated strings with base64 encoding. |
| T1027 Obfuscated Files or Information |
MalwarePoetRAT | PoetRAT has used a custom encryption scheme for communication between scripts. |
| T1027 Obfuscated Files or Information |
MalwareCoinTicker | CoinTicker initially downloads a hidden encoded file. |
| T1027 Obfuscated Files or Information |
MalwareEbury | Ebury has obfuscated its strings with a simple XOR encryption with a static key. |
| T1027 Obfuscated Files or Information |
MalwareMaze | Maze has decrypted strings and other important information during the encryption process. Maze also calls certain functions dynamically to hinder analysis. |
| T1027 Obfuscated Files or Information |
MalwareComRAT | ComRAT has encrypted its virtual file system using AES-256 in XTS mode. |
| T1027 Obfuscated Files or Information |
MalwarePowerStallion | PowerStallion uses a XOR cipher to encrypt command output written to its OneDrive C2 server. |
| T1027 Obfuscated Files or Information |
MalwareShai-Hulud | Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account. Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes. |
| T1027 Obfuscated Files or Information |
MalwareJPIN | A JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer. |
| T1027 Obfuscated Files or Information |
MalwareHTTPBrowser | HTTPBrowser's code may be obfuscated through structured exception handling and return-oriented programming. |
| T1027 Obfuscated Files or Information |
MalwareKillDisk | KillDisk uses VMProtect to make reverse engineering the malware more difficult. |
| T1027 Obfuscated Files or Information |
MalwareAppleJeus | AppleJeus has XOR-encrypted collected system information prior to sending to a C2. AppleJeus has also used the open source ADVObfuscation library for its components. |
| T1027 Obfuscated Files or Information |
MalwareSoreFang | SoreFang has the ability to encode and RC6 encrypt data sent to C2. |
| T1027 Obfuscated Files or Information |
MalwareIndustroyer | Industroyer uses heavily obfuscated code in its Windows Notepad backdoor. |
| T1027 Obfuscated Files or Information |
MalwareAgent Tesla | Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings. |
| T1027 Obfuscated Files or Information |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON has encrypted strings with RC4. |
| T1027 Obfuscated Files or Information |
MalwareShadowPad | ShadowPad has encrypted its payload, a virtual file system, and various files. |
| T1027 Obfuscated Files or Information |
MalwareQakBot | QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells. |
| T1027 Obfuscated Files or Information |
MalwareHancitor | Hancitor has used Base64 to encode malicious links. |
| T1027 Obfuscated Files or Information |
MalwarejRAT | jRAT’s Java payload is encrypted with AES. Additionally, backdoor files are encrypted using DES as a stream cipher. Later variants of jRAT also incorporated AV evasion methods such as Java bytecode obfuscation via the commercial Allatori obfuscation tool. |
| T1027 Obfuscated Files or Information |
MalwareDridex | Dridex's strings are obfuscated using RC4. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.