# T1027.001 Binary Padding

> As of 2026-10-05, T1027.001 (Binary Padding) appears in 14 tracked threats, first reported 2026-04-08 and most recently 2026-09-29, with linked actors including UNC1549, Grandoreiro operators, TA455; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 14 (2 critical, 9 high, 3 medium)
- **First seen:** 2026-04-08
- **Last seen:** 2026-09-29
- **Threat actors:** 4
- **Detection rules:** 18 (counts only; Blue tier and above)

## Key facts

- **ID:** T1027.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1027
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1027/001/

## Activity timeline

T1027.001 first appeared in tracked threats on 2026-04-08 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 6 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1027.001 Binary Padding is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027). Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 9 high, 3 medium.

Threats that use T1027.001 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (14 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (10 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (10 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (10 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1027.001; the most frequent are [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) (2), [Grandoreiro operators](https://intel.threadlinqs.com/actor/Grandoreiro%20operators) (1), [TA455](https://intel.threadlinqs.com/actor/TA455) (1), [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) (1).

## Data sources

Telemetry that can reveal T1027.001, per MITRE ATT&CK.

- File — File Metadata

## Threat actors using it

- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 2
- [Grandoreiro operators](https://intel.threadlinqs.com/actor/Grandoreiro%20operators) — 1
- [TA455](https://intel.threadlinqs.com/actor/TA455) — 1
- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 1

## Tracked threats

14 tracked threats use T1027.001.

- [OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers](https://intel.threadlinqs.com/threat/TL-2026-2767) — high — 2026-09-29
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [Lampion Banking Trojan (ChePro Lineage) Multistage Phishing/Evasion Campaign Targets Portugal](https://intel.threadlinqs.com/threat/TL-2026-1619) — medium — 2026-07-22
- [Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…](https://intel.threadlinqs.com/threat/TL-2026-1486) — medium — 2026-07-18
- [Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour…](https://intel.threadlinqs.com/threat/TL-2026-1448) — high — 2026-07-17
- [AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loader](https://intel.threadlinqs.com/threat/TL-2026-1387) — critical — 2026-07-15
- [Vidar Infostealer and XMRig Cryptominer Malvertising Campaign Targeting SMBs (Factory-v3 / X3D MINER)](https://intel.threadlinqs.com/threat/TL-2026-1183) — medium — 2026-07-10
- [Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and…](https://intel.threadlinqs.com/threat/TL-2026-1079) — high — 2026-07-02
- [OpenClaw / ClawHub AI Skill Marketplace Supply-Chain Compromise — Malicious Skills cluw, AMOS, omnicogg…](https://intel.threadlinqs.com/threat/TL-2026-0921) — high — 2026-06-23
- [UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting…](https://intel.threadlinqs.com/threat/TL-2026-0815) — high — 2026-06-16
- [Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-0979) — critical — 2026-06-12
- [Screening Serpens (UNC1549) 2026 Espionage Campaign — Six New RATs (MiniUpdate & MiniJunk V2) via…](https://intel.threadlinqs.com/threat/TL-2026-0562) — high — 2026-05-22
- [OpenClaw Hologram Rust Infostealer — Multi-Wave Campaign Abusing Hookdeck Webhook Gateway as C2 Relay](https://intel.threadlinqs.com/threat/TL-2026-0480) — high — 2026-05-07
- [Grandoreiro Banking Trojan Multi-Vector Campaign: ClickFix Delivery via canalmodup.com, Dual DLL Sideloading…](https://intel.threadlinqs.com/threat/TL-2026-2069) — high — 2026-04-08

## Detection coverage

Threadlinqs maintains 18 detection rules mapped to T1027.001 (SPL 9, KQL 2, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

18 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) — 1177 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1027.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
