# T1027 Obfuscated Files or Information

> As of 2026-10-05, T1027 (Obfuscated Files or Information) appears in 1177 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including TeamPCP, APT38, Sapphire Sleet; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 1177 (301 critical, 758 high, 104 medium, 6 low)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-03
- **Threat actors:** 198
- **Detection rules:** 1333 (counts only; Blue tier and above)

## Key facts

- **ID:** T1027
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1027/

## Activity timeline

T1027 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 346 reports, and 1175 of the 1177 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1027 Obfuscated Files or Information is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 1177 of 2623 tracked threats (44.9%) to it; by severity that is 301 critical, 758 high, 104 medium, 6 low.

Threats that use T1027 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (707 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (654 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (605 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (593 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (568 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

198 tracked threat actors appear in the threats that use T1027; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (43), [APT38](https://intel.threadlinqs.com/actor/APT38) (33), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (28), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (27), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (19).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1027.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)

## Data sources

Telemetry that can reveal T1027, per MITRE ATT&CK.

- Application Log — Application Log Content
- Command — Command Execution
- File — File Creation, File Metadata
- Module — Module Load
- Process — OS API Execution, Process Creation
- Script — Script Execution
- WMI — WMI Creation
- Windows Registry — Windows Registry Key Creation

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 43
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 33
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 28
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 27
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 19
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 18
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 18
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 16
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 16
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 16
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 16
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 13

## Tracked threats

The 30 most recent of 1177 tracked threats that use T1027.

- [Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…](https://intel.threadlinqs.com/threat/TL-2026-2868) — high — 2026-10-03
- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer](https://intel.threadlinqs.com/threat/TL-2026-2840) — high — 2026-10-02
- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — high — 2026-10-01
- [Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild](https://intel.threadlinqs.com/threat/TL-2026-2820) — critical — 2026-09-30
- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-2806) — high — 2026-09-30
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — high — 2026-09-29
- [PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled…](https://intel.threadlinqs.com/threat/TL-2026-2785) — medium — 2026-09-29
- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers](https://intel.threadlinqs.com/threat/TL-2026-2767) — high — 2026-09-29
- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…](https://intel.threadlinqs.com/threat/TL-2026-2764) — high — 2026-09-28
- [Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…](https://intel.threadlinqs.com/threat/TL-2026-2739) — high — 2026-09-28
- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…](https://intel.threadlinqs.com/threat/TL-2026-2730) — high — 2026-09-28
- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…](https://intel.threadlinqs.com/threat/TL-2026-2726) — critical — 2026-09-28
- [Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments](https://intel.threadlinqs.com/threat/TL-2026-2729) — high — 2026-09-27
- [MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…](https://intel.threadlinqs.com/threat/TL-2026-2723) — high — 2026-09-27
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforce](https://intel.threadlinqs.com/threat/TL-2026-2710) — high — 2026-09-27
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — high — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — high — 2026-09-27
- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2681) — critical — 2026-09-27
- [Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat](https://intel.threadlinqs.com/threat/TL-2026-2702) — critical — 2026-09-26
- [PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistence](https://intel.threadlinqs.com/threat/TL-2026-2674) — high — 2026-09-26
- [CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…](https://intel.threadlinqs.com/threat/TL-2026-2669) — critical — 2026-09-26
- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26

## Related CVEs

CVEs referenced by the tracked threats that use T1027, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)

## Detection coverage

Threadlinqs maintains 1333 detection rules mapped to T1027 (SPL 402, KQL 396, Sigma 534, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

1333 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1027.001 Binary Padding](https://intel.threadlinqs.com/technique/T1027.001) — 14 tracked threats
- [T1027.002 Software Packing](https://intel.threadlinqs.com/technique/T1027.002) — 77 tracked threats
- [T1027.003 Steganography](https://intel.threadlinqs.com/technique/T1027.003) — 40 tracked threats
- [T1027.004 Compile After Delivery](https://intel.threadlinqs.com/technique/T1027.004) — 17 tracked threats
- T1027.005 Indicator Removal from Tools — 3 tracked threats
- [T1027.006 HTML Smuggling](https://intel.threadlinqs.com/technique/T1027.006) — 11 tracked threats
- [T1027.007 Dynamic API Resolution](https://intel.threadlinqs.com/technique/T1027.007) — 13 tracked threats
- T1027.008 Stripped Payloads — 0 tracked threats
- [T1027.009 Embedded Payloads](https://intel.threadlinqs.com/technique/T1027.009) — 15 tracked threats
- [T1027.010 Command Obfuscation](https://intel.threadlinqs.com/technique/T1027.010) — 31 tracked threats
- T1027.011 Fileless Storage — 8 tracked threats
- T1027.012 LNK Icon Smuggling — 1 tracked threat
- [T1027.013 Encrypted/Encoded File](https://intel.threadlinqs.com/technique/T1027.013) — 69 tracked threats
- T1027.014 Polymorphic Code — 3 tracked threats
- T1027.015 Compression — 2 tracked threats
- T1027.016 Junk Code Insertion — 2 tracked threats
- T1027.017 SVG Smuggling — 1 tracked threat
- T1027.018 Invisible Unicode — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1027
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
