Activity timeline
T1027 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 346 reports, and 1175 of the 1177 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1027 Obfuscated Files or Information is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 1177 of 2623 tracked threats (44.9%) to it; by severity that is 301 critical, 758 high, 104 medium, 6 low.
Threats that use T1027 most often also use T1082 System Information Discovery (707 threats), T1005 Data from Local System (654 threats), T1041 Exfiltration Over C2 Channel (605 threats), T1059 Command and Scripting Interpreter (593 threats), T1140 Deobfuscate/Decode Files or Information (568 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
198 tracked threat actors appear in the threats that use T1027; the most frequent are TeamPCP (43), APT38 (33), Sapphire Sleet (28), Stardust Chollima (27), Lazarus Group (19).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1027.
Data sources
Telemetry that can reveal T1027, per MITRE ATT&CK.
- Application Log — Application Log Content
- Command — Command Execution
- File — File Creation, File Metadata
- Module — Module Load
- Process — OS API Execution, Process Creation
- Script — Script Execution
- WMI — WMI Creation
- Windows Registry — Windows Registry Key Creation
Threat actors using it
Tracked threats
The 30 most recent of 1177 tracked threats that use T1027.
- Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…high
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- CloudSyncD macOS Backdoor Delivered via Fake Zoom Installerhigh
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wildcritical
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)high
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled…medium
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installershigh
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…high
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…high
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…critical
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deploymentshigh
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…high
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforcehigh
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvestershigh
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environmentshigh
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…critical
- Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threatcritical
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…medium
Detection coverage
Threadlinqs maintains 1333 detection rules mapped to T1027 (SPL 402, KQL 396, Sigma 534, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1027.001 Binary Padding — 14 tracked threats
- T1027.002 Software Packing — 77 tracked threats
- T1027.003 Steganography — 40 tracked threats
- T1027.004 Compile After Delivery — 17 tracked threats
- T1027.005 Indicator Removal from Tools — 3 tracked threats
- T1027.006 HTML Smuggling — 11 tracked threats
- T1027.007 Dynamic API Resolution — 13 tracked threats
- T1027.008 Stripped Payloads — 0 tracked threats
- T1027.009 Embedded Payloads — 15 tracked threats
- T1027.010 Command Obfuscation — 31 tracked threats
- T1027.011 Fileless Storage — 8 tracked threats
- T1027.012 LNK Icon Smuggling — 1 tracked threat
- T1027.013 Encrypted/Encoded File — 69 tracked threats
- T1027.014 Polymorphic Code — 3 tracked threats
- T1027.015 Compression — 2 tracked threats
- T1027.016 Junk Code Insertion — 2 tracked threats
- T1027.017 SVG Smuggling — 1 tracked threat
- T1027.018 Invisible Unicode — 0 tracked threats