T1027.001: T1027.001
Essential information
- MITRE technique ID
T1027.001- Confidence
- 100/100
- Revoked
- No
- Published
- 05/02/2020 15:04
- Modified
- 27/03/2026 01:09
- Author / Source
- The MITRE Corporation
Aliases
Binary Padding
Platforms
windows macos linux
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | defense-evasion |
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (29)
-
BlackBasta usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SLOW#TEMPEST usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
LummaStealer usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed…
First seen 01/01/1970 · Last seen 16/11/5138 · -
UNC3886 usesThe MITRE Corporation Confidence 100
[UNC3886](https://attack.mitre.org/groups/G1048) is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Storm-0494 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Magic Hound](https://attack.mitre.org/groups/G0059) is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Patchwork](https://attack.mitre.org/groups/G0040) is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Hive0145 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Transparent Tribe](https://attack.mitre.org/groups/G0134) is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.(Citation: Proofpoint…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Raspberry Robin usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (77)
-
Meduza usesFamily
-
Gremlin stealer usesFamily
-
REPTILE usesFamily
-
WormGPT usesFamily
-
ScatterBrain usesFamily
-
DeedRAT usesFamily
-
FormBook usesFamily
-
Comnie uses
-
PLUSINJECT usesFamily
-
Global Socket usesFamily
-
POISONPLUG.SHADOW usesFamily
-
Strela Stealer usesFamily
Reports (34)
-
5 MITREs 5 Malwares 6 Observables 1 APT
-
12 MITREs 1 Malware 10 Observables
-
15 MITREs 1 Malware 28 Observables 1 APT
-
11 MITREs 1 Malware 5 Observables
-
10 MITREs 3 Malwares
-
15 MITREs 1 Malware 10 Observables 1 APT
-
15 MITREs 2 Malwares 1 APT
-
3 CVEs 9 MITREs 6 Malwares 14 Observables 1 APT
-
11 MITREs 6 Malwares 12 Observables
-
17 MITREs 1 Malware 1 APT
-
8 MITREs 3 Malwares 12 Observables 1 APT
-
20 MITREs 2 Malwares 2 Observables 1 APT
Vulnerabilities (CVE) (8)
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- Attack vector
- LOCAL
- Published
- 13/08/2024
- Modified
- 21/12/2025
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to …
- Attack vector
- Local
- Published
- 13/03/2025
- Modified
- 21/12/2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before …
- Attack vector
- Network
- Published
- 04/04/2025
- Modified
- 21/12/2025
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI …
- Attack vector
- Local
- Published
- 14/03/2023
- Modified
- 21/12/2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, …
- Attack vector
- Network
- Published
- 05/12/2025
- Modified
- 29/05/2026