40
Groups Using This
1
Tactics
3
Platforms
28
Prevalence Rank
Description

Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as Software Packing, Steganography, and Embedded Payloads, share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., Deobfuscate/Decode Files or Information) at the time of execution/use. This type of file obfuscation can be applied to many file artifacts present on victim hosts, such as malware log/configuration and payload files. Files can be encrypted with a hardcoded or user-supplied key, as well as otherwise obfuscated using standard encoding schemes such as Base64. The entire content of a file may be obfuscated, or just specific functions or values (such as C2 addresses). Encryption and encoding may also be applied in redundant layers for additional protection. For example, adversaries may abuse password-protected Word documents or self-extracting (SFX) archives as a method of encrypting/encoding a file such as a Phishing payload. These files typically function by attaching the intended archived content to a decompressor stub that is executed when the file is invoked (e.g., User Execution). Adversaries may also abuse file-specific as well as custom encoding schemes. For example, Byte Order Mark (BOM) headers in text files may be abused to manipulate and obfuscate file content until Command and Scripting Interpreter execution.

View MITRE record โ†—

Platforms
LinuxmacOSWindows
Groups Using T1027.013 (40)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0032
Lazarus Group
๐Ÿ‡ฐ๐Ÿ‡ต North Korea93 techniques26 software
G0007
APT28
๐Ÿ‡ท๐Ÿ‡บ Russia93 techniques29 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G0139
TeamTNT
56 techniques4 software
G1052
Contagious Interview
๐Ÿ‡ฐ๐Ÿ‡ต North Korea54 techniques4 software
G0087
APT39
๐Ÿ‡ฎ๐Ÿ‡ท Iran53 techniques11 software
G0065
Leviathan
๐Ÿ‡จ๐Ÿ‡ณ China50 techniques17 software
G0045
menuPass
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques25 software
G1054
MirrorFace
๐Ÿ‡จ๐Ÿ‡ณ China43 techniques16 software
G0117
Fox Kitten
๐Ÿ‡ฎ๐Ÿ‡ท Iran41 techniques5 software
G0081
Tropic Trooper
40 techniques6 software
G0099
APT-C-36
38 techniques9 software
G0092
TA505
34 techniques16 software
G1046
Storm-1811
31 techniques7 software
G0064
APT33
๐Ÿ‡ฎ๐Ÿ‡ท Iran31 techniques16 software
G1036
Moonstone Sleet
๐Ÿ‡ฐ๐Ÿ‡ต North Korea30 techniques1 software
G0121
Sidewinder
๐Ÿ‡จ๐Ÿ‡ณ China30 techniques1 software
G0126
Higaisa
๐Ÿ‡ท๐Ÿ‡บ Russia28 techniques3 software
G1018
TA2541
28 techniques9 software
G0012
Darkhotel
๐Ÿ‡ฐ๐Ÿ‡ท South Korea24 techniques0 software
G0100
Inception
๐Ÿ‡ท๐Ÿ‡บ Russia22 techniques3 software
G0108
Blue Mockingbird
22 techniques2 software
G0073
APT19
๐Ÿ‡จ๐Ÿ‡ณ China21 techniques2 software
G1031
Saint Bear
๐Ÿ‡ท๐Ÿ‡บ Russia18 techniques2 software
G1002
BITTER
๐Ÿ‡จ๐Ÿ‡ณ China16 techniques1 software
G0134
Transparent Tribe
๐Ÿ‡ต๐Ÿ‡ฐ Pakistan14 techniques5 software
G0070
Dark Caracal
๐Ÿ‡ฑ๐Ÿ‡ง Lebanon12 techniques3 software
G0026
APT18
12 techniques5 software
G1026
Malteiro
12 techniques1 software
G1009
Moses Staff
๐Ÿ‡ฎ๐Ÿ‡ท Iran12 techniques4 software
G1013
Metador
9 techniques2 software
G0066
Elderwood
๐Ÿ‡จ๐Ÿ‡ณ China9 techniques9 software
G0107
Whitefly
9 techniques1 software
G0103
Mofang
๐Ÿ‡จ๐Ÿ‡ณ China6 techniques2 software
G0024
Putter Panda
๐Ÿ‡จ๐Ÿ‡ณ China4 techniques4 software
G0043
Group5
๐Ÿ‡ฎ๐Ÿ‡ท Iran4 techniques2 software
โ†‘