Activity timeline
T1027.009 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 6 reports, and 15 of the 15 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1027.009 Embedded Payloads is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1027 Obfuscated Files or Information. Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 1 critical, 13 high, 1 medium.
Threats that use T1027.009 most often also use T1071.001 Web Protocols (10 threats), T1140 Deobfuscate/Decode Files or Information (10 threats), T1204.002 Malicious File (10 threats), T1036.005 Match Legitimate Resource Name or Location (8 threats), T1195.002 Compromise Software Supply Chain (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
1 tracked threat actor appear in the threats that use T1027.009; the most frequent are Black Basta (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1027.009.
Data sources
Telemetry that can reveal T1027.009, per MITRE ATT&CK.
- File — File Creation, File Metadata
Threat actors using it
Tracked threats
15 tracked threats use T1027.009.
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installershigh
- Tropic Trooper Spear-Phishing Campaign Uses LNK Loader, DLL Side-Loading via Signed McAfee Binary, and…high
- CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain…high
- CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta…high
- Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor (QUICAgent)high
- VIP Crypt and ASMCrypt: Commercial Crypter Services Enabling Malware Evasion of Windows Defensesmedium
- SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote Accesshigh
- Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle Fileshigh
- AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loadercritical
- AI Skill-Scanner Bypass — ClawHub, Cisco & Vercel Malicious-Skill Detectors Evaded via Truncation, .pyc…high
- 7-Zip NTFS Handler Heap Overflow CVE-2026-48095 — vtable Hijack via Crafted Archive (GHSL-2026-140)high
- GemStuffer Campaign — RubyGems Registry Abused as Exfiltration Channel for UK Local Government Datahigh
- 109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT) and StealC Infostealer via Cloned Open-Source…high
- Malicious NuGet Packages — JIT Hooking ASP.NET Identity Exfiltration and Persistent Backdoor via Local Proxy…high
- ClickFix Browser Cache Smuggling — Social Engineering MaaS Toolkit Storing Malware Payloads in Browser Cache…high
Detection coverage
Threadlinqs maintains 34 detection rules mapped to T1027.009 (SPL 14, KQL 10, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1027 Obfuscated Files or Information — 1177 tracked threats at the technique level.