TACTIC: DEFENSE EVASION

Obfuscated Files or Information (T1027): real cases

MITRE Definition ↗
Adversaries encrypt or encode payload strings and executable code to conceal malicious contents.

Key Facts

Technique ID
T1027
Defense Evasion
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1027.
  • Tactical Phase: Defense Evasion.
  • Substantiated in 1 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Criminal Complaint ¶ 63, Page 42
"Park and his co-conspirators heavily obfuscated WannaCry and Destover binaries with custom XOR encoders and commercial packers."
U.S. District Court for the Central District of California View full case dossier →