# T1027.002 Software Packing

> As of 2026-10-05, T1027.002 (Software Packing) appears in 77 tracked threats, first reported 2026-02-02 and most recently 2026-09-27, with linked actors including 1VPNS, APT38, Armored Likho; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 77 (12 critical, 51 high, 14 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-27
- **Threat actors:** 26
- **Detection rules:** 132 (counts only; Blue tier and above)

## Key facts

- **ID:** T1027.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1027
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1027/002/

## Activity timeline

T1027.002 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 27 reports, and 77 of the 77 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1027.002 Software Packing is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027). Threadlinqs maps 77 of 2623 tracked threats (2.9%) to it; by severity that is 12 critical, 51 high, 14 medium.

Threats that use T1027.002 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (54 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (48 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (47 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (45 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (42 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

26 tracked threat actors appear in the threats that use T1027.002; the most frequent are [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) (2), [APT38](https://intel.threadlinqs.com/actor/APT38) (2), [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) (2), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (2), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1027.002.

- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)

## Data sources

Telemetry that can reveal T1027.002, per MITRE ATT&CK.

- File — File Metadata

## Threat actors using it

- [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) — 2
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 2
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 1
- [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) — 1
- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 1
- [Kapibala](https://intel.threadlinqs.com/actor/Kapibala) — 1

## Tracked threats

The 30 most recent of 77 tracked threats that use T1027.002.

- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…](https://intel.threadlinqs.com/threat/TL-2026-2654) — high — 2026-09-25
- [Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red…](https://intel.threadlinqs.com/threat/TL-2026-2611) — critical — 2026-09-21
- [PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…](https://intel.threadlinqs.com/threat/TL-2026-2527) — high — 2026-09-15
- [ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2](https://intel.threadlinqs.com/threat/TL-2026-2455) — high — 2026-09-12
- [The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2402) — high — 2026-09-08
- [ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport…](https://intel.threadlinqs.com/threat/TL-2026-2387) — critical — 2026-09-08
- [Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for…](https://intel.threadlinqs.com/threat/TL-2026-2323) — high — 2026-09-03
- [Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed…](https://intel.threadlinqs.com/threat/TL-2026-2253) — medium — 2026-08-31
- [BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation](https://intel.threadlinqs.com/threat/TL-2026-2250) — high — 2026-08-31
- [Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware](https://intel.threadlinqs.com/threat/TL-2026-2197) — high — 2026-08-29
- [Agent Tesla v4 Hidden Behind Unicode-Emoji-Obfuscated JScript Evades Detection in BEC Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2108) — high — 2026-08-22
- [SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2200) — high — 2026-08-19
- [CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia](https://intel.threadlinqs.com/threat/TL-2026-2075) — high — 2026-08-19
- [GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruex](https://intel.threadlinqs.com/threat/TL-2026-2059) — medium — 2026-08-18
- [MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generation](https://intel.threadlinqs.com/threat/TL-2026-2036) — high — 2026-08-16
- [VIP Crypt and ASMCrypt: Commercial Crypter Services Enabling Malware Evasion of Windows Defenses](https://intel.threadlinqs.com/threat/TL-2026-2014) — medium — 2026-08-14
- [Crimeware-as-a-Service: Inside the Malware Crypting Services Market and Its Threat Actors](https://intel.threadlinqs.com/threat/TL-2026-2008) — high — 2026-08-13
- [Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Side](https://intel.threadlinqs.com/threat/TL-2026-2002) — high — 2026-08-13
- [ClickFix Attacks Deliver Go-Based macOS Infostealer Targeting Crypto Wallets and Keychain Data](https://intel.threadlinqs.com/threat/TL-2026-1936) — high — 2026-08-07
- [Nearly 800 Malicious npm Packages Deliver Cross-Platform WEL1DROPPER RAT and Infostealer ('Flooding Dropper'…](https://intel.threadlinqs.com/threat/TL-2026-1935) — high — 2026-08-07
- [Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor Obfuscation](https://intel.threadlinqs.com/threat/TL-2026-1914) — high — 2026-08-06
- [TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Repos](https://intel.threadlinqs.com/threat/TL-2026-1859) — high — 2026-08-04
- [Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto…](https://intel.threadlinqs.com/threat/TL-2026-1820) — medium — 2026-08-02
- [Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle Files](https://intel.threadlinqs.com/threat/TL-2026-1817) — high — 2026-08-02
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM…](https://intel.threadlinqs.com/threat/TL-2026-1764) — critical — 2026-07-29
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and…](https://intel.threadlinqs.com/threat/TL-2026-1686) — medium — 2026-07-25
- [FakeGit Campaign Uses 7,600 GitHub Repositories with AgentBaiting to Spread SmartLoader & StealC Malware](https://intel.threadlinqs.com/threat/TL-2026-1565) — high — 2026-07-20

## Related CVEs

CVEs referenced by the tracked threats that use T1027.002, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2020-16040](https://intel.threadlinqs.com/cve/CVE-2020-16040)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-55255](https://intel.threadlinqs.com/cve/CVE-2026-55255)
- [CVE-2026-7273](https://intel.threadlinqs.com/cve/CVE-2026-7273)

## Detection coverage

Threadlinqs maintains 132 detection rules mapped to T1027.002 (SPL 37, KQL 43, Sigma 52). Rule content is available to Blue tier accounts and above; this page shows counts only.

132 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) — 1177 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1027.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
