T1027.002: T1027.002
Essential information
- MITRE technique ID
T1027.002- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 27/03/2026 01:12
- Author / Source
- The MITRE Corporation
Aliases
Software Packing
Platforms
windows macos linux
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | defense-evasion |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (67)
-
Rocke usesThe MITRE Corporation Confidence 100
[Rocke](https://attack.mitre.org/groups/G0106) is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name [Rocke](https://attack.mitre.org/groups/G0106) comes…
First seen 01/01/1970 · Last seen 16/11/5138 · -
ITG05 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ischhfd83 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
UAC-0063 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Chinese APTs usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[APT38](https://attack.mitre.org/groups/G0082) is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.(Citation: CISA AA20-239A BeagleBoyz August 2020)…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[ZIRCONIUM](https://attack.mitre.org/groups/G0128) is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at…
First seen 01/01/1970 · Last seen 16/11/5138 · -
play usesThe MITRE Corporation Confidence 100
Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to…
First seen 01/01/1970 · Last seen 16/11/5138 · -
VasyGrek usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
INC usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
TA2541 usesThe MITRE Corporation Confidence 100
[TA2541](https://attack.mitre.org/groups/G1018) is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. [TA2541](https://attack.mitre.org/groups/G1018) campaigns are typically high volume and…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (95)
-
Mzmess usesFamily
-
LokiBot usesFamily
-
LucidRook usesFamily
-
PLUSDROP usesFamily
-
VBCloud usesFamily
-
ComRAT - S0126 uses
-
QUIETCANARY usesFamily The MITRE Corporation Confidence 100
[QUIETCANARY](https://attack.mitre.org/software/S1076) is a backdoor tool written in .NET that has been used since at least 2022 to gather and exfiltrate data from victim networks.(Citation: Mandiant Suspected Turla Campaign…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Endico usesFamily
-
Casbaneiro usesFamily
-
PetitPotato usesFamily
-
Daserf uses
-
Trojan.Karagany uses
Reports (50)
-
AlienVault Confidence 100 20 MITREs 9 IOCs 3 Observables
-
AlienVault Confidence 100 14 MITREs 1 Malware 4 IOCs 1 APT
-
AlienVault Confidence 100 4 CVEs 19 MITREs 4 Malwares 25 IOCs 25 Observables 1 APT
-
2 CVEs 22 MITREs 24 Malwares 102 Observables 1 APT
-
AlienVault Confidence 100 18 MITREs 3 Malwares 8 IOCs 8 Observables 1 APT
-
AlienVault Confidence 100 19 MITREs 1 Malware 34 IOCs 34 Observables
-
19 MITREs 3 Malwares 32 Observables 1 APT
-
19 MITREs 5 Observables
-
AlienVault Confidence 100 23 MITREs 1 Malware 8 IOCs 8 Observables
-
20 MITREs 6 Malwares 10 Observables 1 APT
-
3 CVEs 20 MITREs 1 Malware 25 Observables
-
AlienVault Confidence 100 20 MITREs 1 Malware 10 IOCs 10 Observables
Vulnerabilities (CVE) (75)
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This …
- Attack vector
- Network
- Published
- 07/02/2025
- Modified
- 21/12/2025
Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in …
- Attack vector
- NETWORK
- Published
- 11/07/2025
- Modified
- 21/12/2025
Reflected Cross-Site Scripting (XSS)
- Attack vector
- NETWORK
- Published
- 19/07/2023
- Modified
- 21/12/2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured …
- Attack vector
- Network
- Published
- 26/08/2025
- Modified
- 27/05/2026
Privilege Escalation to root administrator (nsroot)
- Attack vector
- ADJACENT_NETWORK
- Published
- 19/07/2023
- Modified
- 21/12/2025
Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which can lead to …
- Attack vector
- NETWORK
- Published
- 23/10/2024
- Modified
- 21/12/2025
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 15/08/2012
- Modified
- 27/04/2026
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow …
- Attack vector
- Network
- Published
- 31/10/2023
- Modified
- 21/12/2025
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code …
- Published
- 03/11/2021
- Modified
- 20/12/2025
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing …
- Attack vector
- NETWORK
- Published
- 13/04/2024
- Modified
- 21/12/2025
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
- Attack vector
- Network
- Published
- 04/10/2023
- Modified
- 29/05/2026
Campaign (3)
-
Night Dragon uses
-
Operation Spalax uses
-
SharePoint ToolShell Exploitation uses