ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareMachete

Machete has been packed with NSIS.

T1027.002
Software Packing
MalwareSquirrelwaffle

Squirrelwaffle has been packed with a custom packer to hide payloads.

T1027.002
Software Packing
MalwareHildegard

Hildegard has packed ELF files into other binaries.

T1027.002
Software Packing
MalwareFYAnti

FYAnti has used ConfuserEx to pack its .NET module.

T1027.002
Software Packing
MalwareZeroT

Some ZeroT DLL files have been packed with UPX.

T1027.002
Software Packing
MalwareRaspberry Robin

Raspberry Robin contains multiple payloads that are packed for defense evasion purposes and unpacked on runtime.

T1027.002
Software Packing
MalwareRaindrop

Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm.

T1027.002
Software Packing
MalwareIcedID

IcedID has packed and encrypted its loader module.

T1027.002
Software Packing
MalwareVERMIN

VERMIN is initially packed.

T1027.002
Software Packing
MalwareDarkComet

DarkComet has the option to compress its payload using UPX or MPRESS.

T1027.002
Software Packing
MalwareFatDuke

FatDuke has been regularly repacked by its operators to create large binaries and evade detection.

T1027.002
Software Packing
MalwareLucifer

Lucifer has used UPX packed binaries.

T1027.002
Software Packing
MalwareDRATzarus

DRATzarus's dropper can be packed with UPX.

T1027.002
Software Packing
MalwareShimRat

ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack.

T1027.002
Software Packing
MalwareChina Chopper

China Chopper's client component is packed with UPX.

T1027.002
Software Packing
MalwareGoldMax

GoldMax has been packed for obfuscation.

T1027.002
Software Packing
MalwareCostaBricks

CostaBricks can implement a custom-built virtual machine mechanism to obfuscate its code.

T1027.002
Software Packing
MalwareHyperBro

HyperBro has the ability to pack its payload.

T1027.002
Software Packing
MalwareAnchor

Anchor has come with a packed payload.

T1027.002
Software Packing
MalwareBabuk

Versions of Babuk have been packed.

T1027.002
Software Packing
MalwareDyre

Dyre has been delivered with encrypted resources and must be unpacked for execution.

T1027.002
Software Packing
MalwareBisonal

Bisonal has used the MPRESS packer and similar tools for obfuscation.

T1027.002
Software Packing
MalwareS-Type

Some S-Type samples have been packed with UPX.

T1027.002
Software Packing
MalwareSeaDuke

SeaDuke has been packed with the UPX packer.

T1027.002
Software Packing
MalwareCuba

Cuba has a packed payload when delivered.

T1027.002
Software Packing
MalwareMongall

Mongall has been packed with Themida.

T1027.002
Software Packing
MalwareLockBit 3.0

LockBit 3.0 can use code packing to hinder analysis.

T1027.002
Software Packing
MalwareLatrodectus

The Latrodectus payload has been packed for obfuscation.

T1027.002
Software Packing
MalwareSaint Bot

Saint Bot has been packed using a dark market crypter.

T1027.002
Software Packing
MalwareSagerunex

Sagerunex has used VMProtect to pack and obscure itself.

T1027.002
Software Packing
MalwareUroburos

Uroburos uses a custom packer.

T1027.002
Software Packing
MalwareMetamorfo

Metamorfo has used VMProtect to pack and protect files.

T1027.002
Software Packing
MalwareTrojan.Karagany

Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer.

T1027.002
Software Packing
MalwareKONNI

KONNI has been packed for obfuscation.

T1027.002
Software Packing
MalwareRedLine Stealer

RedLine Stealer has used obfuscation tools such as DNGuard and Boxed App to pack their code.

T1027.002
Software Packing
MalwareOopsIE

OopsIE uses the SmartAssembly obfuscator to pack an embedded .Net Framework assembly used for C2.

T1027.002
Software Packing
MalwareSDBbot

SDBbot has used a packed installer file.

T1027.002
Software Packing
MalwareStrelaStealer

StrelaStealer variants have used packers to obfuscate payloads and make analysis more difficult.

T1027.002
Software Packing
MalwareLiteDuke

LiteDuke has been packed with multiple layers of encryption.

T1027.002
Software Packing
MalwareBazar

Bazar has a variant with a packed payload.

T1027.002
Software Packing
MalwareXLoader

XLoader uses various packers, including CyaX, to obfuscate malicious executables.

T1027.002
Software Packing
MalwareZebrocy

Zebrocy's Delphi variant was packed with UPX.

T1027.002
Software Packing
MalwareFinFisher

A FinFisher variant uses a custom packer.

T1027.002
Software Packing
MalwareHotCroissant

HotCroissant has used the open source UPX executable packer.

T1027.002
Software Packing
MalwareValak

Valak has used packed DLL payloads.

T1027.002
Software Packing
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has a variant that is packed with UPX.

T1027.002
Software Packing
MalwareDaserf

A version of Daserf uses the MPRESS packer.

T1027.002
Software Packing
MalwareSysUpdate

SysUpdate has been packed with VMProtect.

T1027.002
Software Packing
MalwareClop

Clop has been packed to help avoid detection.

T1027.002
Software Packing
MalwareLokibot

Lokibot has used several packing methods for obfuscation.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.