T1027.002 Software Packing — ATT&CK Technique
Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code. Utilities used to perform software packing are called packers. Example packers are MPRESS and UPX. A more comprehensive list of known packers is available, but adversaries may create their own packing techniques that do not leave the same artifacts as well-known packers to evade defenses.
Detection coverage (1)
Malware using this technique
- TrickBot
- BLINDINGCAN
- Spark
- Torisma
- yty
- KONNI
- COATHANGER
- HeartCrypt
- ShimRat
- AppleSeed
- NETWIRE
- GreyEnergy
- Emotet
- Tomiris
- Machete
- Squirrelwaffle
- Hildegard
- FYAnti
- ZeroT
- Raspberry Robin
- Raindrop
- VERMIN
- DarkComet
- FatDuke
- Lucifer
- DRATzarus
- Daserf
- China Chopper
- GoldMax
- CostaBricks
- HyperBro
- Anchor
- Babuk
- Bazar
- Dyre
- Bisonal
- S-Type
- SeaDuke
- Cuba
- LockBit 3.0
- Latrodectus
- Saint Bot
- Melcoz
- Sagerunex
- Uroburos
- Metamorfo
- Trojan.Karagany
- RedLine Stealer
- OopsIE
- SDBbot