T1027.004 — Compile After Delivery
T1027.004: Compile After Delivery
MITRE ATT&CK® Enterprise technique
| Tactics | Stealth |
| Platforms | Linux, macOS, Windows |
| Permissions required | — |
| Version | 2.0 |
| Parent technique | T1027 |
Description
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe(Citation: ATTACK IQ), csc.exe, or GCC/MinGW.(Citation: ClearSky MuddyWater Nov 2018)
Source code payloads may also be encrypted, encoded, and/or embedded within other files, such as those delivered as a Phishing. Payloads may also be delivered in formats unrecognizable and inherently benign to the native OS (ex: EXEs on macOS/Linux) before later being (re)compiled into a proper executable binary with a bundled compiler and execution framework.(Citation: TrendMicro WindowsAppMac)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1027/004
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/