Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1027/T1027.002
MITRE ATT&CK Sub-Technique

T1027.002: Software Packing

ShareXLinkedInRedditHN

Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.(Citation: ESET FinFisher Jan 2018) Utilities used to perform software packing are called packers. Example packers are MPRESS and UPX. A more comprehensive list of known packers is available, but adversaries may create their own packing techniques that do not leave the same artifacts as well-known packers to evade defenses.(Citation: Awesome Executable Packing)

Tactics
Stealth
Platforms
Linux, macOS, Windows

▪Parent technique

T1027: Obfuscated Files or Information

▪Mitigations (1)

M1049Antivirus/Antimalware

Antivirus/Antimalware solutions utilize signatures, heuristics, and behavioral analysis to detect, block, and remediate malicious software, including viruses, trojans, ransomware, and spyware. These solutions continuously monitor endpoints and systems for known malicious patterns and suspicious behaviors that indicate compromise. Antivirus/Antimalware software should be deployed across all devices, with automated updates to ensure protection against the latest threats. This mitigation can be implemented through the following measures: Signature-Based Detection: - Implementation: Use predefined signatures to identify known malware based on unique patterns such as file hashes, byte sequences, or command-line arguments. This method is effective against known threats. - Use Case: When malware like "Emotet" is detected, its signature (such as a specific file hash) matches a known database of malicious software, triggering an alert and allowing immediate quarantine of the infected file. Heuristic-Based Detection: - Implementation: Deploy heuristic algorithms that analyze behavior and characteristics of files and processes to identify potential malware, even if it doesn’t match a known signature. - Use Case: If a program attempts to modify multiple critical system files or initiate suspicious network communications, heuristic analysis may flag it as potentially malicious, even if no specific malware signature is available. Behavioral Detection (Behavior Prevention): - Implementation: Use behavioral analysis to detect patterns of abnormal activities, such as unusual system calls, unauthorized file encryption, or attempts to escalate privileges. - Use Case: Behavioral analysis can detect ransomware attacks early by identifying behavior like mass file encryption, even before a specific ransomware signature has been identified. Real-Time Scanning: - Implementation: Enable real-time scanning to automatically inspect files and network traffic for signs of malware as they are accessed, downloaded, or executed. - Use Case: When a user downloads an email attachment, the antivirus solution scans the file in real-time, checking it against both signatures and heuristics to detect any malicious content before it can be opened. Cloud-Assisted Threat Intelligence: - Implementation: Use cloud-based threat intelligence to ensure the antivirus solution can access the latest malware definitions and real-time threat feeds from a global database of emerging threats. - Use Case: Cloud-assisted antivirus solutions quickly identify newly discovered malware by cross-referencing against global threat databases, providing real-time protection against zero-day attacks. **Tools for Implementation**: - Endpoint Security Platforms: Use solutions such as EDR for comprehensive antivirus/antimalware protection across all systems. - Centralized Management: Implement centralized antivirus management consoles that provide visibility into threat activity, enable policy enforcement, and automate updates. - Behavioral Analysis Tools: Leverage solutions with advanced behavioral analysis capabilities to detect malicious activity patterns that don’t rely on known signatures.

▪Used by groups (23)

G0016APT29G0022APT3G0027Threat Group-3390G0040PatchworkG0066ElderwoodG0070Dark CaracalG0082APT38G0087APT39G0089The White CompanyG0092TA505G0093GALLIUMG0094KimsukyG0096APT41G0106RockeG0128ZIRCONIUMG0139TeamTNTG1007Aoqin DragonG1017Volt TyphoonG1018TA2541G1019MoustachedBouncerG1031Saint BearG1051Medusa GroupG1053Storm-0501

▪Software using this technique (73)

S0020China ChoppermalwareS0022UroburosmalwareS0024DyremalwareS0053SeaDukemalwareS0083MisdatmalwareS0085S-TypemalwareS0094Trojan.KaraganymalwareS0132H1N1malwareS0182FinFishermalwareS0187DaserfmalwareS0198NETWIREmalwareS0230ZeroTmalwareS0248ytymalwareS0251ZebrocymalwareS0257VERMINmalwareS0264OopsIEmalwareS0266TrickBotmalwareS0268BisonalmalwareS0281DokmalwareS0283jRATmalwareS0334DarkCometmalwareS0342GreyEnergymalwareS0352OSX_OCEANLOTUS.DmalwareS0356KONNImalwareS0367EmotetmalwareS0373AstarothmalwareS0398HyperBromalwareS0409MachetemalwareS0431HotCroissantmalwareS0444ShimRatmalwareS0447LokibotmalwareS0455MetamorfomalwareS0461SDBbotmalwareS0476ValakmalwareS0483IcedIDmalwareS0504AnchormalwareS0512FatDukemalwareS0513LiteDukemalwareS0520BLINDINGCANmalwareS0527CSPY DownloadertoolS0530MelcozmalwareS0532LucifermalwareS0534BazarmalwareS0543SparkmalwareS0554EgregormalwareS0565RaindropmalwareS0588GoldMaxmalwareS0601HildegardmalwareS0611ClopmalwareS0614CostaBricksmalwareS0622AppleSeedmalwareS0625CubamalwareS0628FYAntimalwareS0638BabukmalwareS0650QakBotmalwareS0663SysUpdatemalwareS0671TomirismalwareS0678TorismamalwareS0694DRATzarusmalwareS0695DonuttoolS1018Saint BotmalwareS1026MongallmalwareS1030SquirrelwafflemalwareS1105COATHANGERmalwareS1130Raspberry RobinmalwareS1160LatrodectusmalwareS1183StrelaStealermalwareS1196Troll StealermalwareS1202LockBit 3.0malwareS1207XLoadermalwareS1210SagerunexmalwareS1240RedLine StealermalwareS9018HeartCryptmalware

▪Reference

T1027.002on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.