Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1027/T1027.013
MITRE ATT&CK Sub-Technique

T1027.013: Encrypted/Encoded File

ShareXLinkedInRedditHN

Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as [Software Packing](https://attack.mitre.org/techniques/T1027/002), [Steganography](https://attack.mitre.org/techniques/T1027/003), and [Embedded Payloads](https://attack.mitre.org/techniques/T1027/009), share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140)) at the time of execution/use. This type of file obfuscation can be applied to many file artifacts present on victim hosts, such as malware log/configuration and payload files.(Citation: File obfuscation) Files can be encrypted with a hardcoded or user-supplied key, as well as otherwise obfuscated using standard encoding schemes such as Base64. The entire content of a file may be obfuscated, or just specific functions or values (such as C2 addresses). Encryption and encoding may also be applied in redundant layers for additional protection. For example, adversaries may abuse password-protected Word documents or self-extracting (SFX) archives as a method of encrypting/encoding a file such as a [Phishing](https://attack.mitre.org/techniques/T1566) payload. These files typically function by attaching the intended archived content to a decompressor stub that is executed when the file is invoked (e.g., [User Execution](https://attack.mitre.org/techniques/T1204)).(Citation: SFX - Encrypted/Encoded File) Adversaries may also abuse file-specific as well as custom encoding schemes. For example, Byte Order Mark (BOM) headers in text files may be abused to manipulate and obfuscate file content until [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) execution.

Tactics
Stealth
Platforms
Linux, macOS, Windows

▪Parent technique

T1027: Obfuscated Files or Information

▪Mitigations (2)

M1040Behavior Prevention on Endpoint

Behavior Prevention on Endpoint refers to the use of technologies and strategies to detect and block potentially malicious activities by analyzing the behavior of processes, files, API calls, and other endpoint events. Rather than relying solely on known signatures, this approach leverages heuristics, machine learning, and real-time monitoring to identify anomalous patterns indicative of an attack. This mitigation can be implemented through the following measures: Suspicious Process Behavior: - Implementation: Use Endpoint Detection and Response (EDR) tools to monitor and block processes exhibiting unusual behavior, such as privilege escalation attempts. - Use Case: An attacker uses a known vulnerability to spawn a privileged process from a user-level application. The endpoint tool detects the abnormal parent-child process relationship and blocks the action. Unauthorized File Access: - Implementation: Leverage Data Loss Prevention (DLP) or endpoint tools to block processes attempting to access sensitive files without proper authorization. - Use Case: A process tries to read or modify a sensitive file located in a restricted directory, such as /etc/shadow on Linux or the SAM registry hive on Windows. The endpoint tool identifies this anomalous behavior and prevents it. Abnormal API Calls: - Implementation: Implement runtime analysis tools to monitor API calls and block those associated with malicious activities. - Use Case: A process dynamically injects itself into another process to hijack its execution. The endpoint detects the abnormal use of APIs like `OpenProcess` and `WriteProcessMemory` and terminates the offending process. Exploit Prevention: - Implementation: Use behavioral exploit prevention tools to detect and block exploits attempting to gain unauthorized access. - Use Case: A buffer overflow exploit is launched against a vulnerable application. The endpoint detects the anomalous memory write operation and halts the process.

▪Used by groups (40)

G0007APT28G0012DarkhotelG0024Putter Panda

▪Software using this technique (195)

S0011TaidoormalwareS0013PlugXmalware

▪Reference

T1027.013on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

M1049Antivirus/Antimalware

Antivirus/Antimalware solutions utilize signatures, heuristics, and behavioral analysis to detect, block, and remediate malicious software, including viruses, trojans, ransomware, and spyware. These solutions continuously monitor endpoints and systems for known malicious patterns and suspicious behaviors that indicate compromise. Antivirus/Antimalware software should be deployed across all devices, with automated updates to ensure protection against the latest threats. This mitigation can be implemented through the following measures: Signature-Based Detection: - Implementation: Use predefined signatures to identify known malware based on unique patterns such as file hashes, byte sequences, or command-line arguments. This method is effective against known threats. - Use Case: When malware like "Emotet" is detected, its signature (such as a specific file hash) matches a known database of malicious software, triggering an alert and allowing immediate quarantine of the infected file. Heuristic-Based Detection: - Implementation: Deploy heuristic algorithms that analyze behavior and characteristics of files and processes to identify potential malware, even if it doesn’t match a known signature. - Use Case: If a program attempts to modify multiple critical system files or initiate suspicious network communications, heuristic analysis may flag it as potentially malicious, even if no specific malware signature is available. Behavioral Detection (Behavior Prevention): - Implementation: Use behavioral analysis to detect patterns of abnormal activities, such as unusual system calls, unauthorized file encryption, or attempts to escalate privileges. - Use Case: Behavioral analysis can detect ransomware attacks early by identifying behavior like mass file encryption, even before a specific ransomware signature has been identified. Real-Time Scanning: - Implementation: Enable real-time scanning to automatically inspect files and network traffic for signs of malware as they are accessed, downloaded, or executed. - Use Case: When a user downloads an email attachment, the antivirus solution scans the file in real-time, checking it against both signatures and heuristics to detect any malicious content before it can be opened. Cloud-Assisted Threat Intelligence: - Implementation: Use cloud-based threat intelligence to ensure the antivirus solution can access the latest malware definitions and real-time threat feeds from a global database of emerging threats. - Use Case: Cloud-assisted antivirus solutions quickly identify newly discovered malware by cross-referencing against global threat databases, providing real-time protection against zero-day attacks. **Tools for Implementation**: - Endpoint Security Platforms: Use solutions such as EDR for comprehensive antivirus/antimalware protection across all systems. - Centralized Management: Implement centralized antivirus management consoles that provide visibility into threat activity, enable policy enforcement, and automate updates. - Behavioral Analysis Tools: Leverage solutions with advanced behavioral analysis capabilities to detect malicious activity patterns that don’t rely on known signatures.

G0026APT18
G0027Threat Group-3390
G0032Lazarus Group
G0043Group5
G0045menuPass
G0049OilRig
G0050APT32
G0059Magic Hound
G0064APT33
G0065Leviathan
G0066Elderwood
G0070Dark Caracal
G0073APT19
G0081Tropic Trooper
G0087APT39
G0092TA505
G0094Kimsuky
G0099APT-C-36
G0100Inception
G0103Mofang
G0107Whitefly
G0108Blue Mockingbird
G0117Fox Kitten
G0121Sidewinder
G0126Higaisa
G0134Transparent Tribe
G0139TeamTNT
G1002BITTER
G1009Moses Staff
G1013Metador
G1018TA2541
G1026Malteiro
G1031Saint Bear
G1036Moonstone Sleet
G1046Storm-1811
G1052Contagious Interview
G1054MirrorFace
S0022Uroburosmalware
S0044JHUHUGITmalware
S0046CozyCarmalware
S0074Sakulamalware
S0081Elisemalware
S0082Emissarymalware
S0087Hi-Zormalware
S0113Prikormkamalware
S0125Remsecmalware
S0131TINYTYPHONmalware
S0136USBStealermalware
S0141Winnti for Windowsmalware
S0153RedLeavesmalware
S0168Gazermalware
S0170Helminthmalware
S0172Reavermalware
S0180Volgmermalware
S0213DOGCALLmalware
S0226Smoke Loadermalware
S0228NanHaiShumalware
S0230ZeroTmalware
S0232HOMEFRYmalware
S0236Kwampirsmalware
S0237GravityRATmalware
S0256Mosquitomalware
S0257VERMINmalware
S0263TYPEFRAMEmalware
S0266TrickBotmalware
S0267FELIXROOTmalware
S0268Bisonalmalware
S0284More_eggsmalware
S0330Zeus Pandamalware
S0332Remcostool
S0339Micropsiamalware
S0342GreyEnergymalware
S0345Seasaltmalware
S0347AuditCredmalware
S0348Cardinal RATmalware
S0352OSX_OCEANLOTUS.Dmalware
S0356KONNImalware
S0367Emotetmalware
S0370SamSammalware
S0373Astarothmalware
S0374SpeakUpmalware
S0375Remeximalware
S0380StoneDrillmalware
S0383FlawedGracemalware
S0385njRATmalware
S0386Ursnifmalware
S0387KeyBoymalware
S0388YAHOYAHmalware
S0391HAWKBALLmalware
S0394HiddenWaspmalware
S0395LightNeuronmalware
S0398HyperBromalware
S0401Exaramel for Linuxmalware
S0410Fysbismalware
S0415BOOSTWRITEmalware
S0430Winnti for Linuxmalware
S0431HotCroissantmalware
S0433Rifdoormalware
S0438Attormalware
S0448Rising Sunmalware
S0451LoudMinermalware
S0455Metamorfomalware
S0456Aria-bodymalware
S0462CARROTBATmalware
S0466WindTailmalware
S0468Skidmapmalware
S0473Avengermalware
S0483IcedIDmalware
S0484Carberpmalware
S0487Kesselmalware
S0491StrongPitymalware
S0493GoldenSpymalware
S0496REvilmalware
S0497Daclsmalware
S0501PipeMonmalware
S0520BLINDINGCANmalware
S0526KGH_SPYmalware
S0531Grandoreiromalware
S0534Bazarmalware
S0565Raindropmalware
S0570BitPaymermalware
S0574BendyBearmalware
S0578SUPERNOVAmalware
S0579Waterbearmalware
S0581IronNetInjectortool
S0585Kerrdownmalware
S0587Penquinmalware
S0588GoldMaxmalware
S0601Hildegardmalware
S0603Stuxnetmalware
S0612WastedLockermalware
S0613PS1malware
S0618FIVEHANDSmalware
S0629RainyDaymalware
S0633Slivertool
S0634EnvyScoutmalware
S0657BLUELIGHTmalware
S0658XCSSETmalware
S0661FoggyWebmalware
S0663SysUpdatemalware
S0665ThreatNeedlemalware
S0667Chrommmemalware
S0672Zoxmalware
S0678Torismamalware
S0689WhisperGatemalware
S0695Donuttool
S0698HermeticWizardmalware
S1013ZxxZmalware
S1014DanBotmalware
S1015Milanmalware
S1019Sharkmalware
S1020Kevinmalware
S1027Heyoka Backdoormalware
S1030Squirrelwafflemalware
S1032PyDCryptmalware
S1033DCSrvmalware
S1037STARWHALEmalware
S1041Chinoxymalware
S1044FunnyDreammalware
S1050PcSharetool
S1051KEYPLUGmalware
S1052DEADEYEmalware
S1059metaMainmalware
S1060Mafaldamalware
S1065Woody RATmalware
S1100Ninjamalware
S1111DarkGatemalware
S1113RAPIDPULSEmalware
S1122Mispadumalware
S1124SocGholishmalware
S1132IPsec Helpermalware
S1134DEADWOODmalware
S1141LunarWebmalware
S1142LunarMailmalware
S1148Raccoon Stealermalware
S1150ROADSWEEPmalware
S1153Cuckoo Stealermalware
S1154VersaMemmalware
S1158DUSTPANmalware
S1159DUSTTRAPmalware
S1160Latrodectusmalware
S1164UPSTYLEmalware
S1169Mangomalware
S1180BlackByte Ransomwaremalware
S1182MagicRATmalware
S1183StrelaStealermalware
S1185LightSpymalware
S1190Kapekamalware
S1200StealBitmalware
S1202LockBit 3.0malware
S1207XLoadermalware
S1210Sagerunexmalware
S1212RansomHubmalware
S1213Lumma Stealermalware
S1220MEDUSAmalware
S1221MOPSLEDmalware
S1226BOOKWORMmalware
S1232SplatDroppermalware
S1233PAKLOGmalware
S1235CorKLOGmalware
S1240RedLine Stealermalware
S1242Qilinmalware
S1244Medusa Ransomwaremalware
S1245InvisibleFerretmalware
S1246BeaverTailmalware
S1247Embargomalware
S1248XORIndex Loadermalware
S1249HexEval Loadermalware
S9010GlassWormmalware
S9013DRYHOOKmalware
S9014PHASEJAMmalware
S9015BRICKSTORMmalware
S9016Caminhomalware
S9017DCRATtool
S9018HeartCryptmalware
S9019PureCryptermalware
S9020LODEINFOmalware
S9021DOWNIISSAmalware
S9023HiddenFacemalware
S9024SPAWNCHIMERAmalware
S9025NOOPLDRmalware
S9026ROAMINGHOUSEmalware
S9027ANELLDRmalware
S9028PHPsertmalware
S9031AshTagmalware
S9034Tsundere Botnetmalware
S9036LP-Notesmalware
S9037RustyWatermalware
S9041TeamPCP Cloud Stealermalware
S9043Mini Shai-Huludmalware