Compliance Node Overview
MITRE ATT&CK T1027.003 (Steganography) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may use steganography techniques in order to prevent the detection of hidden information. Steganographic techniques can be used to hide data in digital media such as images, audio tracks, video clips, or text files. Duqu was an early example of malware that used steganography. It encrypted the gathered information from a victim's system and hid it within an image before exfiltrating the image to a C2 server. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, CM-02, CM-06, CM-07, SI-02, SI-03, SI-04, SI-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1027/003/
SHA-256 integrity: 5c694cc1b2be4995f8190ed107ce4b39de8c706832bdd95849d40b1ba8c6b6c1
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1027.003: Steganography (https://attack.mitre.org/techniques/T1027/003/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access