ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1027×

18 examples

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupGALLIUM

GALLIUM used a modified version of HTRAN in which they obfuscated strings such as debug messages in an apparent attempt to evade detection.

T1027
Obfuscated Files or Information
GroupAPT3

APT3 obfuscates files or information to help evade defensive measures.

T1027
Obfuscated Files or Information
GroupKimsuky

Kimsuky has obfuscated binary strings including the use of XOR encryption and Base64 encoding. Kimsuky has also modified the first byte of DLL implants targeting victims to prevent recognition of the executable file format. Kimsuky has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions that complicate static analysis.

T1027
Obfuscated Files or Information
GroupAPT41

APT41 used VMProtected binaries in multiple intrusions.

T1027
Obfuscated Files or Information
GroupGamaredon Group

Gamaredon Group has delivered self-extracting 7z archive files within malicious document attachments. Additionally, Gamaredon Group has used an obfuscated .drv file.

T1027
Obfuscated Files or Information
GroupGallmaker

Gallmaker obfuscated shellcode used during execution.

T1027
Obfuscated Files or Information
GroupSandworm Team

Sandworm Team has used Base64 encoding within malware variants.

T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1027
Obfuscated Files or Information
GroupRocke

Rocke has modified UPX headers after packing files to break unpackers.

T1027
Obfuscated Files or Information
GroupAPT37

APT37 obfuscates strings and payloads.

T1027
Obfuscated Files or Information
GroupKe3chang

Ke3chang has used Base64-encoded shellcode strings.

T1027
Obfuscated Files or Information
GroupRedCurl

RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files.

T1027
Obfuscated Files or Information
GroupBackdoorDiplomacy

BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect.

T1027
Obfuscated Files or Information
GroupWindshift

Windshift has used string encoding with floating point calculations.

T1027
Obfuscated Files or Information
GroupAPT-C-36

APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats.

T1027
Obfuscated Files or Information
GroupEarth Lusca

Earth Lusca used Base64 to encode strings.

T1027
Obfuscated Files or Information
GroupBlackOasis

BlackOasis's first stage shellcode contains a NOP sled with alternative instructions that was likely designed to bypass antivirus tools.

T1027
Obfuscated Files or Information
GroupMoonstone Sleet

Moonstone Sleet delivers encrypted payloads in pieces that are then combined together to form a new portable executable (PE) file during installation.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.