Software Packing

T1027.002

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.

Utilities used to perform software packing are called packers. Example packers are MPRESS and UPX. A more comprehensive list of known packers is available, but adversaries may create their own packing techniques that do not leave the same artifacts as well-known packers to evade defenses.

Detection rules1

Rules on DetectionCode tagged with T1027.002.

Sigma1

RuleLevelLog source
Python Image Load By Non-Python Processlowwindows / image_load

Splunk0

No Splunk rules are mapped to this technique yet.

Groups23

Software73

Show 49 more

Campaigns7

Procedure examples103

Groups23

Used byProcedure example
GroupAoqin Dragon

Aoqin Dragon has used the Themida packer to obfuscate malicious payloads.

GroupAPT29

APT29 used UPX to pack files.

GroupAPT3

APT3 has been known to pack their tools.

GroupAPT38

APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants.

GroupAPT39

APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection.

GroupAPT41

APT41 uses packers such as Themida to obfuscate malicious files.

GroupDark Caracal

Dark Caracal has used UPX to pack Bandook.

GroupElderwood

Elderwood has packed malware payloads before delivery to victims.

View all 23 groups examples

Software73

Used byProcedure example
MalwareAnchor

Anchor has come with a packed payload.

MalwareAppleSeed

AppleSeed has used UPX packers for its payload DLL.

MalwareAstaroth

Astaroth uses a software packer called Pe123\RPolyCryptor.

MalwareBabuk

Versions of Babuk have been packed.

MalwareBazar

Bazar has a variant with a packed payload.

MalwareBisonal

Bisonal has used the MPRESS packer and similar tools for obfuscation.

MalwareBLINDINGCAN

BLINDINGCAN has been packed with the UPX packer.

MalwareChina Chopper

China Chopper's client component is packed with UPX.

View all 73 software examples

Campaigns7

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used UPX to pack a copy of Mimikatz.

CampaignC0017

During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries.

CampaignNight Dragon

During Night Dragon, threat actors used software packing in its tools.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection.

CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors used UPX to pack some payloads.

CampaignOperation Spalax

For Operation Spalax, the threat actors used a variety of packers, including CyaX, to obfuscate malicious executables.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors UPX-packed malicous payloads including 4L4MD4R ransomware.

References2

  1. Awesome Executable Packing Open source
    Alexandre D'Hondt. (n.d.). Awesome Executable Packing. Retrieved March 11, 2022.
  2. ESET FinFisher Jan 2018 Open source
    Kafka, F. (2018, January). ESET's Guide to Deobfuscating and Devirtualizing FinFisher. Retrieved August 12, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.