Standardseverity: HighDraft

CAPEC-636Hiding Malicious Data or Code within Files

Abstraction
Standard
Status
Draft
Severity
High

Description

Files on various operating systems can have a complex format which allows for the storage of other data, in addition to its contents. Often this is metadata about the file, such as a cached thumbnail for an image file. Unless utilities are invoked in a particular way, this data is not visible during the normal use of the file. It is possible for an attacker to store malicious data or code using these facilities, which would be difficult to discover.

Related weaknesses· 1

CWE-506

MITRE ATT&CK crosswalk· 5

T1001.002: Data Obfuscation: SteganographyT1027.003: Obfuscated Files or Information: SteganographyT1027.004: Obfuscated Files or Information: Compile After DeliveryT1218.001: Signed Binary Proxy Execution: Compiled HTML FileT1221: Template Injection

Related attack patterns· 1

CAPEC-165 (ChildOf)

Exploits1

TypeTargetConfidenceTier
WeaknessEmbedded Malicious Codecwe-506100%live

Related to5

TypeTargetConfidenceTier
SubTechniqueSteganographyt1001.002100%live
SubTechniqueCompile After Deliveryt1027.004100%live
TechniqueTemplate Injectiont1221100%live
SubTechniqueSteganographyt1027.003100%live
SubTechniqueCompiled HTML Filet1218.001100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Screen Temporary Files for Sensitive Information
CAPEC
File Manipulation
CAPEC
File Content Injection
Sub-technique
Embedded Payloads
CAPEC
Leverage Executable Code in Non-Executable Files
CAPEC
Probe System Files
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.