ATT&CK Technique · Stealth
T1027.013 Encrypted/Encoded FileMapped by 5 reports, 5 detection rules and 5 tracked actors on The Hunters Ledger. Technique page on attack.mitre.org.
← All techniques and the coverage heatmap
Reports
Each report maps this technique in its own ATT&CK table, at the confidence the report states. The link opens that table.
Detection rules
Rules whose ATT&CK coverage line names this technique, by detection page. The link opens the page's coverage table.
Detection rules
BellaMain Turkish PhaaS Panel (79.137.192.3)BellaMain Wadanz Author Functions (YARA, Detection)
Detection rules
Rhadamanthys MaaS Customer Deep-Dive (79.137.192.3)Rhadamanthys Operator-Modified Q3VM Bytecode Magic (YARA, Detection)
Detection rules
HijackLoader / Penguish / Rugmi to AsyncRAT Multi-Vector Phishing Campaignnetworkspec17.log PNG-IDAT Carrier (YARA, Detection)
Detection rules
Sliver C2 Toolchain with ScareCrow Loader (45.94.31.220)ScareCrow Go Loader (OneDriveSync.exe) (YARA, Detection); ScareCrow Build Pipeline Source Code Artifacts (YARA, Hunting)
Tracked actors
Designations whose reports map this technique.
- UTA-2026-001: Sliver C2 operator with an automated ScareCrow, Donut and SysWhispers3 build pipeline
- UTA-2026-007: HijackLoader customer running a 15-month multi-vector phishing campaign into an AsyncRAT-class RAT
- UTA-2026-008: Developer and operator of the BellaMain Turkish phishing-as-a-service panel
- UTA-2026-009: Multi-product fraud operator pairing a real VPN service with a brand-impersonation phishing library
- UTA-2026-010: Rhadamanthys MaaS customer with a self-built loader (customer side only, never the vendor)
ATT&CK v19.2. MITRE ATT&CK® is a registered trademark of The MITRE Corporation; technique names are MITRE's and link to MITRE's own pages. The mapping on each linked page is this publication's reading of its own evidence.