Activity timeline
T1027.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 27 reports, and 77 of the 77 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1027.002 Software Packing is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1027 Obfuscated Files or Information. Threadlinqs maps 77 of 2623 tracked threats (2.9%) to it; by severity that is 12 critical, 51 high, 14 medium.
Threats that use T1027.002 most often also use T1071.001 Web Protocols (54 threats), T1082 System Information Discovery (48 threats), T1204.002 Malicious File (47 threats), T1036.005 Match Legitimate Resource Name or Location (45 threats), T1005 Data from Local System (42 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
26 tracked threat actors appear in the threats that use T1027.002; the most frequent are 1VPNS (2), APT38 (2), Armored Likho (2), Contagious Interview (2), Lazarus Group (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1027.002.
Data sources
Telemetry that can reveal T1027.002, per MITRE ATT&CK.
- File — File Metadata
Threat actors using it
Tracked threats
The 30 most recent of 77 tracked threats that use T1027.002.
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…high
- Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red…critical
- PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…high
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2high
- The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…high
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport…critical
- Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for…high
- Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed…medium
- BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operationhigh
- Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malwarehigh
- Agent Tesla v4 Hidden Behind Unicode-Emoji-Obfuscated JScript Evades Detection in BEC Campaign Targeting…high
- SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governmentshigh
- CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russiahigh
- GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruexmedium
- MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generationhigh
- VIP Crypt and ASMCrypt: Commercial Crypter Services Enabling Malware Evasion of Windows Defensesmedium
- Crimeware-as-a-Service: Inside the Malware Crypting Services Market and Its Threat Actorshigh
- Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Sidehigh
- ClickFix Attacks Deliver Go-Based macOS Infostealer Targeting Crypto Wallets and Keychain Datahigh
- Nearly 800 Malicious npm Packages Deliver Cross-Platform WEL1DROPPER RAT and Infostealer ('Flooding Dropper'…high
- Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor Obfuscationhigh
- TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Reposhigh
- Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto…medium
- Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle Fileshigh
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…high
- Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM…critical
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiledhigh
- AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and…medium
- FakeGit Campaign Uses 7,600 GitHub Repositories with AgentBaiting to Spread SmartLoader & StealC Malwarehigh
Detection coverage
Threadlinqs maintains 132 detection rules mapped to T1027.002 (SPL 37, KQL 43, Sigma 52). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1027 Obfuscated Files or Information — 1177 tracked threats at the technique level.