# T1027.009 Embedded Payloads

> As of 2026-10-05, T1027.009 (Embedded Payloads) appears in 15 tracked threats, first reported 2026-02-21 and most recently 2026-09-29, with linked actors including Black Basta; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 15 (1 critical, 13 high, 1 medium)
- **First seen:** 2026-02-21
- **Last seen:** 2026-09-29
- **Threat actors:** 1
- **Detection rules:** 34 (counts only; Blue tier and above)

## Key facts

- **ID:** T1027.009
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1027
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1027/009/

## Activity timeline

T1027.009 first appeared in tracked threats on 2026-02-21 and was most recently reported on 2026-09-29. The busiest month was 2026-08 with 6 reports, and 15 of the 15 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1027.009 Embedded Payloads is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027). Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 1 critical, 13 high, 1 medium.

Threats that use T1027.009 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (10 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (10 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (10 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (8 threats), [T1195.002 Compromise Software Supply Chain](https://intel.threadlinqs.com/technique/T1195.002) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1027.009; the most frequent are [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1027.009.

- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)

## Data sources

Telemetry that can reveal T1027.009, per MITRE ATT&CK.

- File — File Creation, File Metadata

## Threat actors using it

- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1

## Tracked threats

15 tracked threats use T1027.009.

- [OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers](https://intel.threadlinqs.com/threat/TL-2026-2767) — high — 2026-09-29
- [Tropic Trooper Spear-Phishing Campaign Uses LNK Loader, DLL Side-Loading via Signed McAfee Binary, and…](https://intel.threadlinqs.com/threat/TL-2026-2427) — high — 2026-09-10
- [CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-2151) — high — 2026-08-26
- [CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta…](https://intel.threadlinqs.com/threat/TL-2026-2135) — high — 2026-08-24
- [Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor (QUICAgent)](https://intel.threadlinqs.com/threat/TL-2026-2040) — high — 2026-08-17
- [VIP Crypt and ASMCrypt: Commercial Crypter Services Enabling Malware Evasion of Windows Defenses](https://intel.threadlinqs.com/threat/TL-2026-2014) — medium — 2026-08-14
- [SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1880) — high — 2026-08-04
- [Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle Files](https://intel.threadlinqs.com/threat/TL-2026-1817) — high — 2026-08-02
- [AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loader](https://intel.threadlinqs.com/threat/TL-2026-1387) — critical — 2026-07-15
- [AI Skill-Scanner Bypass — ClawHub, Cisco & Vercel Malicious-Skill Detectors Evaded via Truncation, .pyc…](https://intel.threadlinqs.com/threat/TL-2026-0702) — high — 2026-06-07
- [7-Zip NTFS Handler Heap Overflow CVE-2026-48095 — vtable Hijack via Crafted Archive (GHSL-2026-140)](https://intel.threadlinqs.com/threat/TL-2026-0586) — high — 2026-05-26
- [GemStuffer Campaign — RubyGems Registry Abused as Exfiltration Channel for UK Local Government Data](https://intel.threadlinqs.com/threat/TL-2026-0505) — high — 2026-05-13
- [109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT) and StealC Infostealer via Cloned Open-Source…](https://intel.threadlinqs.com/threat/TL-2026-0457) — high — 2026-05-05
- [Malicious NuGet Packages — JIT Hooking ASP.NET Identity Exfiltration and Persistent Backdoor via Local Proxy…](https://intel.threadlinqs.com/threat/TL-2026-0137) — high — 2026-02-24
- [ClickFix Browser Cache Smuggling — Social Engineering MaaS Toolkit Storing Malware Payloads in Browser Cache…](https://intel.threadlinqs.com/threat/TL-2026-0127) — high — 2026-02-21

## Related CVEs

CVEs referenced by the tracked threats that use T1027.009, most frequent first.

- [CVE-2026-48095](https://intel.threadlinqs.com/cve/CVE-2026-48095)

## Detection coverage

Threadlinqs maintains 34 detection rules mapped to T1027.009 (SPL 14, KQL 10, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

34 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) — 1177 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1027.009
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
