Activity timeline
T1027.010 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 12 reports, and 31 of the 31 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1027.010 Command Obfuscation is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1027 Obfuscated Files or Information. Threadlinqs maps 31 of 2623 tracked threats (1.2%) to it; by severity that is 9 critical, 17 high, 5 medium.
Threats that use T1027.010 most often also use T1071.001 Web Protocols (23 threats), T1005 Data from Local System (18 threats), T1140 Deobfuscate/Decode Files or Information (18 threats), T1041 Exfiltration Over C2 Channel (17 threats), T1082 System Information Discovery (17 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
17 tracked threat actors appear in the threats that use T1027.010; the most frequent are Akira (2), MuddyWater (2), Storm-1567 (2), APT38 (1), APT44 (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1027.010.
Data sources
Telemetry that can reveal T1027.010, per MITRE ATT&CK.
- Command — Command Execution
- File — File Metadata
- Script — Script Execution
Threat actors using it
Tracked threats
The 30 most recent of 31 tracked threats that use T1027.010.
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group Lists Hyundai Turkey Assessment Data on Dark Web…high
- UAC-0145 (Sandworm subcluster) trojanizes WireGuard VPN client "SopraVPN" in fake IT recruitment campaign…high
- Claude-Powered OpenClaw AI Agent Autonomously Exploits Gym Booking API Authorization Flawmedium
- Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor Obfuscationhigh
- Pre-auth RCE chains in Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 (CVE-2026-31986)critical
- NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail…high
- Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Commandmedium
- ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension…high
- CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)critical
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…high
- Joyfill npm Packages Compromised with Blockchain C2 Loadermedium
- North Korean Contagious Interview Campaign Deploys OtterCookie via SVG Steganography to Steal Developer…high
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- 148 Malicious npm Packages ('Lucide Proxy') Disguise as School Wi-Fi Bypass / Tutoring Proxies to Hijack…high
- npm Supply-Chain Attack on @asyncapi Packages Deploys Miasma Botnet via IPFS-Hosted Second-Stage Payloadhigh
- npm Supply Chain Attack: @injectivelabs/sdk-ts v1.20.21 and 17 Sibling Packages Infected with Cryptocurrency…high
- JADEPUFFER Agentic Ransomware: Autonomous LLM Agent Exploits Langflow (CVE-2025-3248) and Nacos…critical
- Armored Likho APT Deploys BusySnake Python Stealer with PyArmor Obfuscation Against Government and Power…high
- CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap…critical
- Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)critical
- ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via…high
- New Wave of SVG-Attachment Phishing — application/ecmascript MIME Evasion + XOR-Decoded Browser Redirect…medium
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…high
- The Gentlemen Ransomware (RaaS) — Defense Evasion TTPs: Event Log Clearing, Defender Disable & AV Exclusions…high
- Weaver E-cology Unauthenticated RCE (CVE-2026-22679) — Active Exploitation Since Mid-March 2026 via dubboApi…critical
- UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…high
- Tesseract OCR Typosquat Campaign — ClickFix Multi-Stage Malware Targeting Developers via Fake OCR Tool Sites…high
- CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP — Iran MOIS-Linked MuddyWater AI-Assisted Malware…critical
Detection coverage
Threadlinqs maintains 62 detection rules mapped to T1027.010 (SPL 21, KQL 15, Sigma 26). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1027 Obfuscated Files or Information — 1177 tracked threats at the technique level.