ATT&CK · T1027.002 · sub-technique
Software Packing
Tactics: stealth
About
Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code. Utilities used to perform software packing are called packers. Example packers are MPRESS and UPX. A more comprehensive list of known packers is available, but adversaries may create their own packing techniques that do not leave the same artifacts as well-known packers to evade defenses.
Used by actors
23 known groups
Software
73 malware/tools implement this
Corpus indicators tagged with this technique
5,100 indicators in the corpus carry T1027.002.
Showing the top 30 by severity of 5,100.