# T1027.010 Command Obfuscation

> As of 2026-10-05, T1027.010 (Command Obfuscation) appears in 31 tracked threats, first reported 2026-02-28 and most recently 2026-09-27, with linked actors including Akira, MuddyWater, Storm-1567; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 31 (9 critical, 17 high, 5 medium)
- **First seen:** 2026-02-28
- **Last seen:** 2026-09-27
- **Threat actors:** 17
- **Detection rules:** 62 (counts only; Blue tier and above)

## Key facts

- **ID:** T1027.010
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1027
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1027/010/

## Activity timeline

T1027.010 first appeared in tracked threats on 2026-02-28 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 12 reports, and 31 of the 31 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1027.010 Command Obfuscation is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027). Threadlinqs maps 31 of 2623 tracked threats (1.2%) to it; by severity that is 9 critical, 17 high, 5 medium.

Threats that use T1027.010 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (23 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (18 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (18 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (17 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (17 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

17 tracked threat actors appear in the threats that use T1027.010; the most frequent are [Akira](https://intel.threadlinqs.com/actor/Akira) (2), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (2), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (2), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [APT44](https://intel.threadlinqs.com/actor/APT44) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1027.010.

- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)

## Data sources

Telemetry that can reveal T1027.010, per MITRE ATT&CK.

- Command — Command Execution
- File — File Metadata
- Script — Script Execution

## Threat actors using it

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 2
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 2
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) — 1
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 1
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 1
- [LenAI](https://intel.threadlinqs.com/actor/LenAI) — 1
- [PolinRider](https://intel.threadlinqs.com/actor/PolinRider) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1

## Tracked threats

The 30 most recent of 31 tracked threats that use T1027.010.

- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group Lists Hyundai Turkey Assessment Data on Dark Web…](https://intel.threadlinqs.com/threat/TL-2026-2023) — high — 2026-08-15
- [UAC-0145 (Sandworm subcluster) trojanizes WireGuard VPN client "SopraVPN" in fake IT recruitment campaign…](https://intel.threadlinqs.com/threat/TL-2026-1973) — high — 2026-08-10
- [Claude-Powered OpenClaw AI Agent Autonomously Exploits Gym Booking API Authorization Flaw](https://intel.threadlinqs.com/threat/TL-2026-1965) — medium — 2026-08-10
- [Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor Obfuscation](https://intel.threadlinqs.com/threat/TL-2026-1914) — high — 2026-08-06
- [Pre-auth RCE chains in Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 (CVE-2026-31986)](https://intel.threadlinqs.com/threat/TL-2026-1898) — critical — 2026-08-05
- [NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail…](https://intel.threadlinqs.com/threat/TL-2026-1856) — high — 2026-08-04
- [Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Command](https://intel.threadlinqs.com/threat/TL-2026-1813) — medium — 2026-08-02
- [ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension…](https://intel.threadlinqs.com/threat/TL-2026-1800) — high — 2026-07-31
- [CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)](https://intel.threadlinqs.com/threat/TL-2026-1799) — critical — 2026-07-31
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [Joyfill npm Packages Compromised with Blockchain C2 Loader](https://intel.threadlinqs.com/threat/TL-2026-1771) — medium — 2026-07-30
- [North Korean Contagious Interview Campaign Deploys OtterCookie via SVG Steganography to Steal Developer…](https://intel.threadlinqs.com/threat/TL-2026-1571) — high — 2026-07-20
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [148 Malicious npm Packages ('Lucide Proxy') Disguise as School Wi-Fi Bypass / Tutoring Proxies to Hijack…](https://intel.threadlinqs.com/threat/TL-2026-1296) — high — 2026-07-14
- [npm Supply-Chain Attack on @asyncapi Packages Deploys Miasma Botnet via IPFS-Hosted Second-Stage Payload](https://intel.threadlinqs.com/threat/TL-2026-1293) — high — 2026-07-14
- [npm Supply Chain Attack: @injectivelabs/sdk-ts v1.20.21 and 17 Sibling Packages Infected with Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-1153) — high — 2026-07-09
- [JADEPUFFER Agentic Ransomware: Autonomous LLM Agent Exploits Langflow (CVE-2025-3248) and Nacos…](https://intel.threadlinqs.com/threat/TL-2026-1102) — critical — 2026-07-04
- [Armored Likho APT Deploys BusySnake Python Stealer with PyArmor Obfuscation Against Government and Power…](https://intel.threadlinqs.com/threat/TL-2026-1097) — high — 2026-07-03
- [CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap…](https://intel.threadlinqs.com/threat/TL-2026-1045) — critical — 2026-07-01
- [Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)](https://intel.threadlinqs.com/threat/TL-2026-1135) — critical — 2026-06-29
- [ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via…](https://intel.threadlinqs.com/threat/TL-2026-0817) — high — 2026-06-16
- [New Wave of SVG-Attachment Phishing — application/ecmascript MIME Evasion + XOR-Decoded Browser Redirect…](https://intel.threadlinqs.com/threat/TL-2026-0657) — medium — 2026-06-02
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…](https://intel.threadlinqs.com/threat/TL-2026-0610) — high — 2026-05-27
- [The Gentlemen Ransomware (RaaS) — Defense Evasion TTPs: Event Log Clearing, Defender Disable & AV Exclusions…](https://intel.threadlinqs.com/threat/TL-2026-0555) — high — 2026-05-21
- [Weaver E-cology Unauthenticated RCE (CVE-2026-22679) — Active Exploitation Since Mid-March 2026 via dubboApi…](https://intel.threadlinqs.com/threat/TL-2026-0455) — critical — 2026-05-04
- [UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…](https://intel.threadlinqs.com/threat/TL-2026-0415) — high — 2026-04-23
- [Tesseract OCR Typosquat Campaign — ClickFix Multi-Stage Malware Targeting Developers via Fake OCR Tool Sites…](https://intel.threadlinqs.com/threat/TL-2026-0162) — high — 2026-03-01
- [CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP — Iran MOIS-Linked MuddyWater AI-Assisted Malware…](https://intel.threadlinqs.com/threat/TL-2026-0160) — critical — 2026-03-01

## Related CVEs

CVEs referenced by the tracked threats that use T1027.010, most frequent first.

- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-67649](https://intel.threadlinqs.com/cve/CVE-2025-67649)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2026-22679](https://intel.threadlinqs.com/cve/CVE-2026-22679)
- [CVE-2026-88771](https://intel.threadlinqs.com/cve/CVE-2026-88771)
- [CVE-2026-88772](https://intel.threadlinqs.com/cve/CVE-2026-88772)
- [CVE-2026-88773](https://intel.threadlinqs.com/cve/CVE-2026-88773)
- [CVE-2026-88774](https://intel.threadlinqs.com/cve/CVE-2026-88774)
- [CVE-2026-88775](https://intel.threadlinqs.com/cve/CVE-2026-88775)
- [CVE-2026-88776](https://intel.threadlinqs.com/cve/CVE-2026-88776)
- [CVE-2026-88777](https://intel.threadlinqs.com/cve/CVE-2026-88777)
- [CVE-2026-88778](https://intel.threadlinqs.com/cve/CVE-2026-88778)

## Detection coverage

Threadlinqs maintains 62 detection rules mapped to T1027.010 (SPL 21, KQL 15, Sigma 26). Rule content is available to Blue tier accounts and above; this page shows counts only.

62 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) — 1177 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1027.010
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
