Umbra Wiki technique technique/T1027.004
Back to wiki

T1027.004 — Compile After Delivery

provenance: imported · ATT&CK: T1027.004

T1027.004: Compile After Delivery

MITRE ATT&CK® Enterprise technique

Tactics Stealth
Platforms Linux, macOS, Windows
Permissions required
Version 2.0
Parent technique T1027

Description

Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe(Citation: ATTACK IQ), csc.exe, or GCC/MinGW.(Citation: ClearSky MuddyWater Nov 2018)

Source code payloads may also be encrypted, encoded, and/or embedded within other files, such as those delivered as a Phishing. Payloads may also be delivered in formats unrecognizable and inherently benign to the native OS (ex: EXEs on macOS/Linux) before later being (re)compiled into a proper executable binary with a bundled compiler and execution framework.(Citation: TrendMicro WindowsAppMac)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1027/004
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/