• 6ddv8 Delimiter Hex-Split Obfuscation An AutoIt obfuscation variant where hex-encoded payloads are split across hundreds of string-concatenation lines (`$VAR &= "..."`), each fragment polluted with the fixed five-character delimiter `"6dd
  • 7z-sfx-dropper Repurposing the **7-Zip self-extractor (SFX)** as a malware delivery mechanism. The SFX module is a legitimate PE binary that extracts an embedded 7-Zip archive and optionally runs a post-extraction c
  • NtQuerySystemInformation Module Enumeration Using `NtQuerySystemInformation` with `SystemModuleInformation` (class 5) returns the list of loaded kernel modules and their base addresses. Malware uses this to detect specific drivers (VM tools, ED
  • SeDebugPrivilege Escalation Enabling `SeDebugPrivilege` on the current process token grants access to any process on the system, bypassing standard DACL checks. Malware enables this privilege before injecting into or reading mem
  • AMSI Bypass via Byte-Signature Patching A .NET defense-evasion technique in which the malware dynamically resolves `amsi.dll` exports (`AmsiInitialize`, `AmsiOpenSession`, `AmsiScanBuffer`), then scans the function prologues for known byte
  • AMSI Bypass Patch Byte See [[amsi-bypass-byte-patch]] for the full technique description.
  • Chrome App-Bound Encryption Bypass Technique for decrypting Chrome's App-Bound Encryption (ABE) credential database, introduced in Chrome 114 to harden `Login Data` against DPAPI-only decryption. Malware bypasses ABE by retrieving the
  • aspnet_compiler process-name sandbox evasion A behavioral sandbox-evasion technique in which malware checks the process list for the presence of `aspnet_compiler.exe` before executing its payload. The absence of this process indicates a non-deve
  • Audio-Themed Namespace Masquerade A .NET malware technique where malicious classes are named with benign audio-processing terminology to evade string-based detection and analyst suspicion. The malware loads a reflectively-injected pay
  • AutoIt Delimiter + Reverse String Obfuscation A simple but effective string-obfuscation pattern observed in AutoIt-compiled malware. The script encodes sensitive strings (API names, DLL names, payload data) by inserting a fixed delimiter between
  • AutoIt Hex-Split String Obfuscation An AutoIt obfuscation pattern where hex-encoded payloads are broken into tiny fragments and distributed across hundreds of string concatenation lines (`&=`), each fragment polluted with a fixed delimi
  • autoit-overlay-script-placement Placement of a compiled AutoIt v3 script in the file overlay (after the last PE section) rather than inside a `.rsrc` RT_RCDATA resource. This evades automated extraction tools such as `autoit-ripper`
  • AutoIt Shellcode XOR Decryptor A shellcode pattern observed across the [[unclassified-autoit-compiled]] cluster where an x86 shellcode stub, executed via `VirtualAlloc` + `DllCallAddress`, builds a variable-length XOR key on the st
  • AutoIt Stride-3 Hex String Decoder (L300YQJRH) A custom string-obfuscation function observed in compiled AutoIt3 single-file PE droppers. Decoded strings include API names (`kernel32.dll`, `GetTickCount`), type names (`dword`, `long`, `ptr`, `str`
  • AutoIt timing-gate sandbox evasion An anti-debug / anti-sandbox gate implemented in AutoIt malware. The script records the value of `GetTickCount` before a `Sleep` call, sleeps for a known duration (commonly 500 ms), then records `GetT
  • av-registry-exclusion-spray > Defense-evasion technique: systematically add directory/file exclusions to the registry hives of every major endpoint-security product on the victim machine, including both Western and Chinese vendo
  • Batch File Concatenation Obfuscation A DOS batch-script anti-static technique in which a binary payload is split into multiple fragments, each stored as a separate file with a meaningless name. A batch script uses hundreds of `SET` varia
  • Batch Kaomoji-CJK-Noise Obfuscation A DOS batch-script anti-static technique in which the real payload is hidden among massive quantities of undefined-variable expansions containing kaomoji emoticons, CJK ideographs, and Arabic script f
  • Batch PowerShell Variable Expansion Obfuscation A DOS batch-script anti-static technique in which a PowerShell payload is fragmented across tens of `SET` variable assignments, then reassembled in a single line via `%VARNAME%` expansion and passed a
  • Batch Smokescreen Label Obfuscation A DOS batch-script anti-static technique in which the real payload is preceded by thousands of fake `GOTO` labels, each followed by blocks of apparently legitimate Windows system-administration comman
  • BCrypt AES-GCM Payload Decryption Use of the Windows Cryptography API: Next Generation (CNG) — specifically `bcrypt.dll` — to AES-GCM decrypt a downloaded or embedded payload, avoiding custom crypto implementations that might be easie
  • Browser Extension Sideload via CRX3 Malicious browser extension installation by building a valid CRX3 package from embedded resources, computing the extension ID from a public RSA key, writing extension policy registry entries, and inst
  • Caesar-3 Hex Shellcode Staging AutoIt malware pattern: shellcode bytes are encoded as a hex string (e.g., `0x558bec...`), then each character of the hex string is Caesar-shifted by +3, and the result is stored as a large string var
  • CallWindowProc Shellcode Injection A process-injection technique that abuses the `CallWindowProcW` API from `user32.dll`. Because `CallWindowProc` accepts a callback address (`lpPrevWndFunc`) and up to four arguments, it can be repurpo
  • Chrome DevTools Protocol (CDP) Browser Injection Abuse of the Chrome DevTools Protocol (CDP) to silently control Chromium-based browsers (Chrome, Edge, Brave, Vivaldi) for credential extraction, cookie injection, session hijacking, and contact harve
  • Character-Skip Cipher PowerShell Obfuscation A simple but effective static-avoidance technique used in PowerShell malware: sensitive strings (URLs, API calls, paths, headers) are hidden inside noise-padded literals. The decoder extracts every Nt
  • Chrome 128 User-Agent Masquerade Malware hardcodes a fake Google Chrome User-Agent string to masquerade its HTTP requests as legitimate browser traffic. The version number is often absurd or impossible (e.g., `Chrome/7775543322.0.0.0
  • Chrome App-Bound Encryption Bypass Chrome 127+ introduced **App-Bound Encryption (ABE)** to protect the master encryption key stored in `Local State`. Unlike legacy DPAPI, ABE binds the key to the browser process identity via a service
  • Chromium Edge ELF Export Masquerade Malware masquerades as a legitimate Microsoft Edge / Chromium component DLL by embedding real Edge ELF (Early Launch Anti-Malware), Crashpad, and PWA Helper export names into its own PE export table.
  • ClickOnce Certificate Trust Bootstrap A signed PE installs its own Authenticode publisher certificate into the Windows `TrustedPublisher` store, then uses the `SPC_SP_OPUS_INFO_OBJID` (1.3.6.1.4.1.311.4.1.1) attribute inside that signatur
  • companion-file-encrypted-payload Malware technique where the **executable logic is split across multiple files**: a signed or legitimate-appearing PE binary (the "carrier") reads an encrypted payload from one or more companion files
  • Companion-File Key Decryption A defense-evasion technique in which the malware stores its decryption key in a separate file on disk (often with a system-like or benign filename) and reads it at runtime. Without the companion file,
  • ConfuserEx Obfuscation ConfuserEx is an open-source .NET obfuscator that rewrites managed assemblies to impede reverse engineering. It operates at the IL level, applying heavy name mangling, constant encryption, control-flo
  • Costura.Fody IL Merging for .NET Malware Technique: embed all .NET dependencies as compressed resources inside the primary assembly, then load them dynamically at runtime via the Costura.Fody weaver. This collapses a multi-DLL project into a
  • CPlApplet PNG Payload Dropper Phorpiex variant that abuses the `CPlApplet` export interface (typically used by Control Panel applets) to masquerade as a benign system component while decrypting a companion `payload.png` file. Obse
  • Custom User-Agent Masquerade Malware sets an HTTP `User-Agent` header that mimics a legitimate browser, application, or platform — but with a custom or unusual product name that can serve as a family fingerprint.
  • Debug-Build CAPA False Positives When capa analyzes .NET assemblies compiled in Debug configuration, several compiler-generated attributes trigger ATT&CK technique matches that are semantically incorrect. The most common false-positi
  • Delphi DXGI / WGC Screen Capture Technique Detection fingerprint and defensive notes for Delphi/Embarcadero binaries that embed dual-engine screen capture via DXGI Desktop Duplication API and Windows Graphics Capture (WGC).
  • Delphi VCL Certificate Harvesting A build/RE pattern where Delphi VCL RTL bloat inflates a small certificate-stealing payload into a 1.5–5 MB PE, making static triage noisy and behavioural analysis harder because the import table is d
  • Delphi VCL Native Stub → .NET Metadata Loader A delivery chain in which a Borland Delphi VCL native PE32 executable acts as a dropper/loader for an inner .NET Framework payload. The .NET assembly is stored without a standard MZ+PE header — only r
  • Discord Desktop Core Injection Malware modifies the Discord desktop client's `discord_desktop_core/index.js` to inject arbitrary JavaScript that runs with full access to the Discord process. This enables token theft, persistent sur
  • Discord Webhook C2 Exfiltration Using Discord webhooks as a covert data-exfiltration channel. Webhooks are HTTP endpoints that accept JSON payloads and file attachments without authentication beyond the URL token, making them attrac
  • DllCallAddress Shellcode Execution An AutoIt-specific technique for executing shellcode reflectively. The AutoIt script decodes a payload (typically hex-encoded or XOR-encrypted shellcode), allocates executable memory via `VirtualAlloc
  • DNS-over-HTTPS Fallback Malware using DNS-over-HTTPS (DoH) as a fallback or primary resolution mechanism for C2 infrastructure. DoH tunnels DNS queries inside HTTPS, bypassing local DNS filtering and leaving only TLS traffic
  • .NET AssemblyResolve Reflective Plugin Loader **What it does**
  • dotnet-clipboard-ole-hijack — OLE IDataObject COM interop for clipboard manipulation in .NET A .NET-specific collection technique in which malware uses the Windows OLE `IDataObject` COM interface (via `System.Runtime.InteropServices.ComTypes.IDataObject`) to read, write, and enumerate clipboa
  • .NET Hidden VNC (HVNC) Desktop Control Technique: create a secondary, invisible Windows desktop (via `CreateDesktopW`) and run a victim's browser or application session inside it, while streaming the pixel buffer to a remote attacker over
  • .NET Native AOT Compilation for Malware .NET Native AOT (ahead-of-time compilation via `PublishAot`) compiles managed IL into native machine code, producing a self-contained PE with **no CLR header, no IL metadata, and no COM_DESCRIPTOR dir
  • double-extension-masquerade Abuse of Windows Explorer's "Hide extensions for known file types" default to present a malicious PE as a benign file type. The attacker appends a fake extension before the real one — e.g., `Payment_P
  • Email Harvesting via CDP Browser Automation Use of Chrome DevTools Protocol (CDP) to silently navigate to webmail services (Outlook Web, Gmail) and instant messaging web apps (WhatsApp Web), extract contact lists, and relay outbound messages th
  • ENS Ethereum C2 Resolution Malware resolves its command-and-control endpoint by querying an Ethereum Name Service (ENS) text record via public Ethereum RPC endpoints. The ENS name itself may be hardcoded, derived from a seed, o
  • UAC Bypass via Event Viewer (eventvwr.exe mscfile Hijack) Abuses the auto-elevation behavior of `eventvwr.exe` on Windows. Event Viewer is a "Trusted Installer" binary that auto-elevates by invoking the `mmc.exe` COM object via the `mscfile` shell handler. B
  • Fraud Overlay Hole System Native Windows Forms overlay system that draws a blocking screen or a "hole" form over the victim's desktop or browser window, intercepting mouse and keyboard input while presenting attacker-controlle
  • Function Return-This Global Construction A JavaScript obfuscation technique used in Windows Script Host (WSH) environments to access the global `WScript` object without hardcoding its name. The idiom `Function('return this')()` constructs an
  • fused-string-api-decoding Go malware anti-static technique observed across the [[lummastealer]], [[acrstealer]], and [[orderreshop]] clusters. Windows API names are fused with their parent DLL names into single indivisible `.r
  • German LCID Sandbox Gate A sandbox-evasion technique used by JScript droppers to restrict execution to German-speaking Windows systems. The script reads `HKCU\Control Panel\International\Locale` via `WScript.Shell.RegRead`, p
  • GetTickCount Anti-Emulation Loop An anti-emulation technique that repeatedly calls `GetTickCount` (or `QueryPerformanceCounter`) and measures elapsed time between operations. Emulators and sandbox hooks often artificially speed up or
  • go-fake-sourcepath-masquerade — Go pclntab source-path injection for vendor masquerade Go binaries compiled with the standard toolchain embed a program-counter-to-line-number table (`pclntab`) used for stack traces and panics. This table retains the original source-file paths, including
  • Go Function Name Randomization Anti-static technique observed in Go-compiled malware where the `main` package functions are given random alphanumeric names at build time. The Go compiler preserves these names in the `.gopclntab`/`.
  • Go goroutine concurrency in main payload path The Go compiler emits `go func()` statements as goroutine launches, creating an anonymous closure that appears as a `.func1` child symbol in the binary's `.symtab`. In malware, this primitive enables
  • GoFile.io Exfiltration Malware exfiltrates stolen data by uploading ZIP archives to GoFile.io, a free file-hosting service that requires no authentication. The uploaded files are then shared with the operator via the return
  • hangul-syllable-steganography Hangul Syllable steganography is a custom payload-hiding technique in which raw binary data (typically a PE or .NET assembly) is encoded as a string of Korean Hangul Syllable characters. The Hangul Sy
  • IFEO Offline Hive Paralyze A technique to disable security tools by modifying the Image File Execution Options (IFEO) registry hive offline — bypassing real-time AV hooks that monitor live registry writes.
  • javascript-obfuscator Commercial-grade JavaScript obfuscation produced by the `javascript-obfuscator` npm package (open-source, widely abused by malware authors). Recognisable by three structural features that survive mini
  • JS Control-Flow Flattening + String-Array Obfuscation A JavaScript obfuscation pattern produced by the `javascript-obfuscator` npm package (or compatible tooling), observed in JScript/WScript droppers targeting Windows. Combines three anti-static techniq
  • js-custom-noise-obfuscation Custom JavaScript obfuscation technique characterised by embedding the real payload at the end of a massive noise block, then wrapping meaningful strings in a split-string array with comma-separated c
  • JS Dictionary Character Lookup Obfuscation A JavaScript obfuscation technique that maps a large set of natural-language keys (typically English words or phrases) to single ASCII characters, then assembles the real payload at runtime by concate
  • js-fixed-delimiter-concat-obfuscation JScript anti-static technique: split payload across hundreds of `+=` string-concatenation lines, interleaving a fixed noise token between every payload character. The noise token is stripped at runtim
  • JS Noise-Payload Reassignment Eval A hand-rolled JavaScript/JScript obfuscation technique that hides a real payload inside a massive repetitive noise string, then extracts it via sequential variable-reassignment statements and executes
  • JS Noise-Variable Concatenation Obfuscation JScript obfuscation technique where random-length noise variable names (15–20 lowercase characters, no semantic content) are assigned single-character string values, then concatenated via `+` operator
  • jscript-environment-variable-staging A defense-evasion and payload-delivery technique in which a JScript/WScript carrier encodes a binary payload (typically a PE or .NET assembly) as a series of strings, assigns each string to a unique p
  • JScript Hex+ROT WMI Reflective Dropper A three-stage JScript obfuscation pipeline followed by WMI hidden-process creation and a PowerShell reflective .NET assembly loader. Observed in Polish-language purchase-order spam lures.
  • JScript Sequential Variable Reassignment Eval Obfuscation A hand-rolled JavaScript/JScript obfuscation technique that hides a real payload by splitting every character into a separate variable assignment statement. Each unique variable name is assigned a cha
  • K30ZWMBJJ String Obfuscation A custom string-obfuscation function found in the decompiled AutoIt script of the `b017d189` sample. It protects shellcode-staging API names and file paths from static string extraction. The technique
  • Kill-Switch Domain Check A malware sample contains a hardcoded domain or URL that it queries at startup (typically via HTTP GET). If the query succeeds — meaning the domain is registered, resolves, and returns any HTTP respon
  • LZSS Payload Decompression LZSS (Lempel-Ziv-Storer-Szymanski) is a sliding-window dictionary compressor used by the SilverFox/ValleyRAT cluster to hide its second-stage payload inside the PE. At runtime, a small decompressor st
  • LZSS/XZ Embedded Decompressor Custom in-memory LZSS-style decompressor observed in the [[esmk-crypter-loader]] family. The engine uses a sliding-window hash table for match lookup and emits back-reference / length pairs. The magic
  • Magnification API Screen Capture Abuse of the Windows Magnification API (`Magnification.dll`) to capture the desktop or specific window regions at high quality with programmatic control over scaling, filtering, and excluded windows.
  • Marker File Mutex Gating A lightweight runtime gating mechanism: the dropper checks for the existence of a specific file (typically under `%appdata%` or `%TEMP%`). If present, the gated payload branch is skipped. If absent, t
  • MessagePack Asynchronous RAT Protocol A .NET C2 wire-format protocol used by [[asyncrat]] and conceptually related to the [[protobuf-net-asymmetric-client-rat-protocol]] seen in [[quasar]]. MessagePack-serialized objects are transmitted i
  • Modular Builder License Fingerprint Builder-kit malware that is sold as malware-as-a-service often embeds a license key and hardware-ID check to enforce per-customer licensing. The license string format and hardware-ID field become a st
  • MSVC Stub Data-Section Payload Loader Malware build pattern: a small MSVC C++ outer PE carries an encrypted threat payload inside its `.data` section. At runtime the stub hides the console, delays execution via a PRNG-derived `Sleep`, all
  • Mutex Single-Instance Gating A runtime gating mechanism where malware creates a named mutex (via `CreateMutexW`) or event (via `CreateEventW`) on first execution. On subsequent runs, the same call fails with `ERROR_ALREADY_EXISTS
  • Nibble-Encoded Resource Payload A lightweight pre-decryption obfuscation layer observed in the [[esmk-crypter-loader]] family. Before the main decryption routine runs, the payload bytes extracted from the PE resource section are nib
  • NSIS LZMA Embedded Payload Hiding Malware authors compile a Nullsoft Scriptable Install System (NSIS) self-extracting installer and embed the malicious payload as one or more files inside the LZMA-compressed archive appended after the
  • OT Software Filename Masquerade Malware distributed with filenames that mimic legitimate industrial-control-system (ICS) engineering software, programmable-logic-controller (PLC) programming tools, or operational-technology (OT) uti
  • P3059Y1DO Stride-3 Decimal String Obfuscation A custom string-obfuscation function used by the `unclassified-autoit-compiled` cluster of AutoItSC droppers. The function iterates over an input string in steps of 3, takes the first two characters o
  • Parasitic PE Section Append Infection A file-infection technique in which a parasitic malware appends a new PE section to existing executables, copies its payload shellcode into that section, and patches the victim's entry point to trampo
  • PEB-Walking API Resolution Runtime API resolution technique used by the blackmatter / unattributed MSVC 14.12 reflective-loader cluster (40+ confirmed siblings). The binary resolves ~30+ threat APIs at runtime by walking the PE
  • Phorpiex Loader — initterm Hijack MSVC 9.0 (MSVCR90.dll) reflective loader technique observed in early Phorpiex samples. The malware hijacks the C runtime initialisation path (`_initterm` / `_initterm_e`) to execute its payload before
  • poem-word-list-steganography A custom steganography technique where a malware author composes a fixed-length word list (typically 256 words to map directly to byte values 0x00-0xFF) written as natural-language prose — often a poe
  • powershell-cradle-downloader A malware delivery pattern where a compiled binary (PE, .NET, or script) calls `powershell.exe -Command` (or `-EncodedCommand`) to execute a one-line or multi-statement payload string inline. The Powe
  • PowerShell Token Substitution Loader A PowerShell anti-static technique in which the script source is encoded with a single-character token-substitution cipher, then fragmented across multiple `SET` variable assignments in a parent batch
  • prng-seeded-c2-url-decoding Technique observed across Go infostealer families (ACR Stealer, Lumma) where C2 URLs, paths, or payloads are decoded at runtime using a `math/rand` PRNG seeded with hardcoded constants or time-based v
  • Process Hollowing Targeting svchost.exe / RegSvcs.exe A manual PE loader / process hollowing technique embedded in x86 shellcode dropped by the `unclassified-autoit-compiled` AutoItSC cluster. The shellcode decrypts an inner payload (typically a .NET ass
  • Process Hollowing A defense-evasion technique where a benign process is created in a suspended state, its memory is unmapped or overwritten, and malicious code is written into the hollowed space before the thread is re
  • protector-lab-overlay Protector Lab (`plab`) is a commercial Windows PE packer / protector that encrypts the real payload into a large AES-256-GCM overlay appended to the end of the PE file. The outer stub is a MinGW-w64 o
  • Protobuf-net Asymmetric Client–RAT Protocol A .NET remote-access trojan (RAT) communication pattern using protobuf-net as the serialization layer over an asynchronous TCP socket. The server acts as a listener; the client initiates an encrypted
  • PyArmor Runtime Obfuscation PyArmor is a Python obfuscation tool that encrypts Python source code or bytecode and bundles a C-extension runtime (`pyarmor_runtime.pyd` on Windows) to decrypt and execute at load time. It is common
  • Python Embeddable Runtime with EnumDesktopWindows Callback Injection A multi-stage dropper that bundles a full Python embeddable Windows runtime inside a ZIP archive. The entry script is heavily obfuscated, decodes to a `ctypes` loader, allocates RWX memory, copies an
  • Python-Packed Payload Malware logic authored in Python, compiled to `.pyc`/`.pyo`, and bundled inside a Windows PE via PyInstaller, py2exe, or cx_Freeze. The outer PE is a stock bootloader; the actual IOCs, C2 logic, and e
  • QUIC/HTTP3 C2 Transport Malware using QUIC (RFC 9000) or HTTP/3 as its primary command-and-control transport. QUIC runs over UDP and provides built-in encryption (TLS 1.3) and stream multiplexing, making it harder to inspect
  • Rail-Fence Cipher Payload Obfuscation A custom obfuscation technique observed in XLoader batch-script droppers. The attacker encrypts a binary payload with AES-256-CBC, then applies a rail-fence (zigzag) transposition cipher whose rail co
  • raw-socket-ddos-flooder Technique where malware opens `SOCK_RAW` (or `SOCK_PACKET`) sockets with `IP_HDRINCL` to craft Layer-3/Layer-2 packets directly. Used to generate high-volume DoS traffic with spoofed or randomised sou
  • raw-tcp-c2-socket — Raw TCP socket C2 without application-layer framing Malware that communicates with its operator over raw TCP sockets without wrapping the payload in HTTP, HTTPS, DNS, or another application-layer protocol. The C2 traffic is typically a custom byte stre
  • RC4-encrypted PowerShell payload staging A malware staging technique in which a PowerShell payload is encrypted with RC4 and delivered inside another script (e.g. JavaScript or batch). At runtime, the outer script decrypts the RC4 ciphertext
  • RC4 In-Place Section Decryption Malware encrypts one or more PE sections (commonly `.text`, `.data`, and the import table) with RC4 at build time, then decrypts them in-place at runtime using a hardcoded or derived key. This hides c
  • RC4 + XOR Double-Stage Driver Decryption A two-stage decryption routine where an embedded driver image is first decrypted with a hardcoded RC4 key, then passed through an additional XOR pass before being written to disk and loaded into the k
  • rdata-encrypted-payload-loader Malware build pattern: the threat payload is encrypted and stored inside the `.rdata` section of a PE loader stub. At runtime the stub copies the ciphertext into a freshly allocated heap, decrypts it
  • Reflective Assembly Delegate Execution A .NET execution technique in which a byte array (decrypted from a resource, overlay, or network stream) is loaded into memory via `Assembly.Load(byte[])` and then invoked through `MethodBase.Invoke`,
  • Registry Disk Enum VM Detection A sandbox/VM evasion technique that reads the `Disk\Enum` registry key to detect virtualised storage controllers.
  • Registry-Segmented Payload Staging A payload staging technique where a dropper splits a large string (Base64, hex, or raw) into fixed-size segments (typically 10 000–20 000 characters) and stores each segment as a separate `REG_SZ` val
  • REST API C2 Masquerade Malware that communicates with its C2 server using HTTP verbs and resource paths that mimic a legitimate web service or SaaS API. The intent is to blend malicious traffic with benign application traff
  • Rolling XOR Section Decryption An in-place decryption routine that XORs each byte of a PE section with a key byte plus a running delta (typically the loop index or an incrementing counter). The key itself is often read from a compa
  • RtlGetVersion OS Build Gating An anti-sandbox / anti-emulation gate that resolves `RtlGetVersion` from `ntdll.dll` at runtime, fills an `OSVERSIONINFOEXW` struct, and validates `dwBuildNumber` against a hardcoded minimum (e.g. `0x
  • Rust Async RAT Framework A recurring build pattern observed in modern Windows RAT/stealer families: native Rust compiled with the MSVC toolchain, using `tokio` for async I/O, `tokio-tungstenite` for WebSocket C2, `serde_json`
  • Rust ureq/rustls Downloader Build Pattern A Rust-compiled Windows PE32+ x64 downloader that uses the `ureq` synchronous HTTP client library with `rustls` (pure-Rust TLS) for payload retrieval. The pattern is characterized by extensive Cargo r
  • S30K9CPG Caesar-5 XOR String Obfuscation A string-obfuscation function used in AutoIt-compiled droppers within the [[unclassified-autoit-compiled]] cluster. Decodes API names and DLL paths by subtracting 5 from each ASCII value, then XORing
  • Semantic Jargon Export Obfuscation PE export table flooded with a mix of semantically-plausible, real-world API names (typically from legitimate open-source or commercial libraries) and random alphanumeric noise names. The legitimate-l
  • SendKeys PowerShell Injection A defense-evasion technique where a Visual Basic or JScript dropper launches `powershell.exe` in a visible window, then uses `WshShell.SendKeys` to inject keystrokes into the PowerShell console as if
  • Setup Factory Encrypted-Overlay Dropper Technique: repurposing the legitimate Setup Factory installer-builder runtime as a malware dropper by embedding an encrypted payload in the installer data overlay.
  • Shellcode Self-Injection via ntdll.dll Scratchpad A staging technique observed in parasitic file infectors where the infector copies its payload shellcode into a temporary memory region (here, a newly-created section mapped at `0x60000000` with PAGE_
  • signed-carrier-combo Malware evasion technique that combines a **valid Authenticode-signed carrier PE** with an **encrypted companion payload** distributed inside a **silent self-extracting archive** (typically 7-Zip SFX)
  • SmartAssembly Obfuscation SmartAssembly is a commercial .NET obfuscator/packer by Redgate. Malware authors abuse its string encryption, control-flow obfuscation, and anti-tamper features.
  • Social-Engineering Filename Lure Malware distributors repackage benign or malicious executables with filenames that mimic legitimate business documents — purchase orders, invoices, shipping bills, payment advices, salary slips, RFQs
  • Socket.IO C2 Transport Malware uses the Socket.IO library to establish a persistent, bidirectional, event-driven WebSocket-over-HTTP C2 channel. Events are used to issue commands (`client-execute-command`), transfer files (
  • SOCKS5 Proxy Pivoting Malware embedding a SOCKS5 proxy server to pivot traffic through compromised hosts. Enables the attacker to route additional C2 traffic or external connections through the infected machine.
  • steam-error-reporter-masquerade Abuse of Valve's legitimate **Steam Error Reporter** (`steamerrorreporter64.exe`) — a signed MSVC C++ x64 binary — by repackaging it inside a 7-Zip SFX archive alongside encrypted companion files. The
  • stolen-authenticode-certificate-signing **Technique:** Signing a benign or malicious binary with a stolen, expired, or revoked code-signing certificate to bypass Windows SmartScreen, application whitelisting, and user suspicion.
  • SystemRoot Poison DLL Hijack A defense-evasion technique in which a stager overwrites the `SystemRoot` (and related `windir` / `WINDIR`) environment variables to point to an attacker-controlled UNC path before launching a signed
  • Task Scheduler Persistence Malware creating or modifying Windows Task Scheduler entries to survive reboots. The `github.com/capnspacehook/taskmaster` Go library wraps COM automation of the Task Scheduler 2.0 API (`Schedule.Serv
  • Themida Packed Boot LZ77 Decompressor A specific Themida/WinLicense packing pattern observed in x64 PE32+ malware: the entry point is relocated to a `.boot` section containing a compact LZ77 bit-stream decompressor that unpacks an encrypt
  • TLS Callback Anti-Analysis — pre-execution code via Thread-Local Storage callbacks On Windows, PE files can declare a Thread-Local Storage (TLS) directory. The loader walks the `AddressOfCallBacks` array and invokes each function pointer **before** the executable's normal entry poin
  • Token Duplication Privilege Escalation Malware duplicating access tokens from higher-privilege processes (e.g., SYSTEM services, lsass.exe) to escalate its own privileges. Enables access to protected credential stores and elevated operatio
  • Trif32 Caesar-Shift-23 Decoder A trivial string-encoding utility class named `Trif32` that applies a Caesar cipher with a fixed shift of 23 positions (or equivalently, a left shift of 3). The string "Trif32" itself is likely a garb
  • truncated-go-pe64 — Truncated Go PE64+ binaries where only headers + partial .text survive A structural corruption pattern observed in Go-compiled PE64+ x64 binaries where the on-disk image contains only the DOS/NT headers and a partial `.text` section, while all remaining sections (`.rdata
  • U30JZ3SO7 Permutation-XOR String Obfuscation A custom AutoIt string-obfuscation function that hides API names and string literals inside compiled AutoIt3 scripts. It combines a **key-scheduled permutation** ( Fisher-Yates-like shuffle driven by
  • Unicode Control-Character Name Obfuscation .NET malware technique where all type names, method names, and sometimes field names are replaced with sequences of Unicode control characters (C0/C1 controls such as `U+0002`, `U+0003`, `U+0005`) and
  • Userinit Registry Persistence Appending a payload path to the `Userinit` registry value under `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon`, causing the payload to execute every time a user logs on.
  • Version Info Masquerade Malware authors clone or fabricate VS_VERSIONINFO resource blocks in PE binaries to make their executables appear as legitimate, well-known software during superficial triage. By copying CompanyName,
  • WebAssembly In-Process Loader Malware embedding a WebAssembly (Wasm) runtime to load and execute compiled `.wasm` modules inside the same process. This provides architecture-agnostic payload delivery and can evade signature-based
  • Watchdog Process Respawning A lightweight self-healing mechanism where a batch script or secondary process monitors the primary malware process and respawns it if it terminates. Often paired with persistence mechanisms to ensure
  • WebDAV Regsvr32 DLL Sideloading A defense-evasion execution chain in which a script (JScript, batch, or VBScript) mounts an attacker-controlled WebDAV share via `net use \\host@port\DavWWWRoot\` and then calls `regsvr32 /s` to silen
  • WebSocket C2 Transport Malware using WebSocket (RFC 6455) as its primary command-and-control channel, typically over TLS (`wss://`). Observed in Go-based malware via `github.com/gorilla/websocket`.
  • WinInet + URLMon Dual-Path HTTP Downloader A downloader that implements two independent HTTP fetch paths — a primary WinInet path (`InternetOpenW` → `InternetOpenUrlW` → `InternetReadFile` → `WriteFile`) and a fallback URLMon path (`URLDownloa
  • WMI System Fingerprinting Windows Management Instrumentation (WMI) queries used by JScript/WScript droppers to harvest victim-system metadata before exfiltration. Typically queries `Win32_OperatingSystem` for caption, architec
  • WScript LNK PowerShell Cradle A multi-stage execution chain observed in invoice-themed JavaScript droppers:
  • wscript-powershell-cradle Multi-stage execution chain: JScript/WScript carrier instantiates `WScript.Shell` (or `Shell.Application`), expands environment variables, and spawns `powershell.exe` with `-ExecutionPolicy Bypass` an
  • x64 Architecture Check via Program Files (x86) An anti-sandbox / anti-emulation gate that checks for the presence of the `%SYSTEMDRIVE%\Program Files (x86)` directory via `PathFileExistsW`. This directory only exists on 64-bit Windows installation
  • XMM Word-Wise Payload Decryption A payload-decryption technique that uses SSE2 XMM registers to operate on 128-bit blocks of encrypted data in-place. The typical sequence is:
  • XOR + NOT String Decryption A lightweight anti-static string obfuscation technique observed in MSVC 9.0 PE32 malware (Phorpiex campaign). Strings are encoded at build time by XOR-ing each byte with a repeating 4-byte key, then a
  • XOR-Encrypted PE Payload Staging A multi-stage payload delivery pattern where a secondary PE is written to disk encrypted with a repeating XOR key, then read back and decrypted in-memory by a shellcode loader before execution.
  • XOR string decryption loop A static string obfuscation technique observed in Zig-compiled malware where encrypted blobs and their XOR keys are stored in `.rdata`, then decrypted at runtime into stack-allocated buffers before us
  • XOR-decrypted .NET assembly reflective loading A defense-evasion technique in which a malware payload encrypts a .NET assembly with a simple XOR cipher, decrypts it at runtime in PowerShell, and loads it reflectively into the current process via `
  • XSLT JScript Extension Execution A defense-evasion and execution technique in which a JScript/WScript carrier constructs an XSL stylesheet containing an `msxsl:script` block with `language="JScript"` and `implements-prefix="u"`. The
  • Z30PER Hex-Split String Obfuscation A string-obfuscation technique used in compiled AutoIt v3 scripts where plaintext strings are encoded as a sequence of 3-character groups. Each group consists of two hex digits representing one byte,
  • Zig-compiled malware Malware compiled with the Zig programming language and its self-hosted compiler. Zig produces native PE/ELF/Mach-O binaries via LLVM/LLD with minimal runtime, making it an attractive target for author
  • Zone.Identifier ADS Deletion A defense-evasion technique to remove the "Downloaded from Internet" mark from a freshly downloaded file. Windows appends an Alternate Data Stream (ADS) named `Zone.Identifier` to files fetched from t