# T1027.004 Compile After Delivery

> As of 2026-10-05, T1027.004 (Compile After Delivery) appears in 17 tracked threats, first reported 2026-02-15 and most recently 2026-10-03, with linked actors including APT34, APT38, Cavern Manticore; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 17 (3 critical, 10 high, 4 medium)
- **First seen:** 2026-02-15
- **Last seen:** 2026-10-03
- **Threat actors:** 11
- **Detection rules:** 27 (counts only; Blue tier and above)

## Key facts

- **ID:** T1027.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1027
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1027/004/

## Activity timeline

T1027.004 first appeared in tracked threats on 2026-02-15 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 7 reports, and 17 of the 17 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1027.004 Compile After Delivery is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027). Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 3 critical, 10 high, 4 medium.

Threats that use T1027.004 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (15 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (12 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (12 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (10 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

11 tracked threat actors appear in the threats that use T1027.004; the most frequent are [APT34](https://intel.threadlinqs.com/actor/APT34) (1), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (1), [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) (1), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (1).

## Data sources

Telemetry that can reveal T1027.004, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation, File Metadata
- Process — Process Creation

## Threat actors using it

- [APT34](https://intel.threadlinqs.com/actor/APT34) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 1
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 1
- [UAC-0247](https://intel.threadlinqs.com/actor/UAC-0247) — 1
- [UNC6201](https://intel.threadlinqs.com/actor/UNC6201) — 1
- [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) — 1

## Tracked threats

17 tracked threats use T1027.004.

- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto…](https://intel.threadlinqs.com/threat/TL-2026-1820) — medium — 2026-08-02
- [BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-1719) — high — 2026-07-27
- [Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…](https://intel.threadlinqs.com/threat/TL-2026-1588) — high — 2026-07-21
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [Photo ZIP Campaign Delivers TonRAT Node.js Implant to Hospitality Sector via Authentication Laundering](https://intel.threadlinqs.com/threat/TL-2026-1406) — high — 2026-07-16
- [CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Unpatched Chain Component, PoC Public)](https://intel.threadlinqs.com/threat/TL-2026-1341) — critical — 2026-07-14
- [Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide…](https://intel.threadlinqs.com/threat/TL-2026-1156) — medium — 2026-07-03
- [ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1062) — high — 2026-07-02
- [Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers](https://intel.threadlinqs.com/threat/TL-2026-0822) — high — 2026-06-16
- [AI Skill-Scanner Bypass — ClawHub, Cisco & Vercel Malicious-Skill Detectors Evaded via Truncation, .pyc…](https://intel.threadlinqs.com/threat/TL-2026-0702) — high — 2026-06-07
- [vpmdhaj npm Supply Chain Attack — 14 OpenSearch/ElasticSearch Typosquats Steal AWS/Vault/CI-CD Secrets via…](https://intel.threadlinqs.com/threat/TL-2026-0623) — high — 2026-05-29
- [Backdoored Cemu v2.6 GitHub Release — TeamPCP Supply Chain Campaign Extends to Cemu Nintendo Wii U Emulator…](https://intel.threadlinqs.com/threat/TL-2026-0515) — high — 2026-05-14
- [AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian Governments, Hospitals, and Defense Personnel](https://intel.threadlinqs.com/threat/TL-2026-0389) — high — 2026-04-17
- [CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP — Iran MOIS-Linked MuddyWater AI-Assisted Malware…](https://intel.threadlinqs.com/threat/TL-2026-0160) — critical — 2026-03-01
- [Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon…](https://intel.threadlinqs.com/threat/TL-2026-0123) — critical — 2026-02-21
- [ZETARINK Ransomware v1.22 — Go-Based File Encryption with Garble Obfuscation and Tor Recovery Portal](https://intel.threadlinqs.com/threat/TL-2026-0086) — medium — 2026-02-15

## Related CVEs

CVEs referenced by the tracked threats that use T1027.004, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)

## Detection coverage

Threadlinqs maintains 27 detection rules mapped to T1027.004 (SPL 10, KQL 10, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

27 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) — 1177 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1027.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
