Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org
Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.
Utilities used to perform software packing are called packers. Example packers are MPRESS and UPX. A more comprehensive list of known packers is available, but adversaries may create their own packing techniques that do not leave the same artifacts as well-known packers to evade defenses.
Rules on DetectionCode tagged with T1027.002.
| Rule | Level | Log source |
|---|---|---|
| Python Image Load By Non-Python Process | low | windows / image_load |
| Used by | Procedure example |
|---|---|
| GroupAoqin Dragon | Aoqin Dragon has used the Themida packer to obfuscate malicious payloads. |
| GroupAPT29 | APT29 used UPX to pack files. |
| GroupAPT3 | APT3 has been known to pack their tools. |
| GroupAPT38 | APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants. |
| GroupAPT39 | APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection. |
| GroupAPT41 | APT41 uses packers such as Themida to obfuscate malicious files. |
| GroupDark Caracal | Dark Caracal has used UPX to pack Bandook. |
| GroupElderwood | Elderwood has packed malware payloads before delivery to victims. |
| Used by | Procedure example |
|---|---|
| MalwareAnchor | Anchor has come with a packed payload. |
| MalwareAppleSeed | AppleSeed has used UPX packers for its payload DLL. |
| MalwareAstaroth | Astaroth uses a software packer called Pe123\RPolyCryptor. |
| MalwareBabuk | Versions of Babuk have been packed. |
| MalwareBazar | Bazar has a variant with a packed payload. |
| MalwareBisonal | Bisonal has used the MPRESS packer and similar tools for obfuscation. |
| MalwareBLINDINGCAN | BLINDINGCAN has been packed with the UPX packer. |
| MalwareChina Chopper | China Chopper's client component is packed with UPX. |
| Used by | Procedure example |
|---|---|
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used UPX to pack a copy of Mimikatz. |
| CampaignC0017 | During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries. |
| CampaignNight Dragon | During Night Dragon, threat actors used software packing in its tools. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection. |
| CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors used UPX to pack some payloads. |
| CampaignOperation Spalax | For Operation Spalax, the threat actors used a variety of packers, including CyaX, to obfuscate malicious executables. |
| CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors UPX-packed malicous payloads including 4L4MD4R ransomware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.