Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1001
MITRE ATT&CK Technique

T1001: Data Obfuscation

ShareXLinkedInRedditHN

Adversaries may obfuscate command and control traffic to make it more difficult to detect.(Citation: Bitdefender FunnyDream Campaign November 2020) Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols.

Tactics
Command and Control
Platforms
ESXi, Linux, macOS, Windows

▪Sub-techniques (3)

T1001.001Junk DataT1001.002SteganographyT1001.003Protocol or Service Impersonation

▪Mitigations (1)

M1031Network Intrusion Prevention

Use intrusion detection signatures to block traffic at network boundaries.

▪Used by groups (1)

G0047Gamaredon Group

▪Software using this technique (13)

S0381FlawedAmmyymalwareS0439OkrummalwareS0495RDATmalwareS0533SLOTHFULMEDIAmalwareS0610SideTwistmalwareS0682TrailBlazermalwareS1044FunnyDreammalwareS1100NinjamalwareS1111DarkGatemalwareS1120FRAMESTINGmalwareS1183StrelaStealermalwareS9001SystemBCmalwareS9003evilginx2tool

▪Reference

T1001on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.