T1027.002 - Software Packing is a mitre_attack tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
T1027.002 - Software Packing is a mitre_attack tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed July 2, 2026; most recent activity July 2, 2026.
A multi-stage cyber attack targeted IIS servers, beginning with enumeration commands and escalating to credential extraction using Mimikatz. The attackers uploaded a steganographic webshell and executed a…
T1027.002 - Software Packing is a mitre_attack tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
The most recent intelligence report mentioning T1027.002 - Software Packing on ThreatCluster is dated July 2, 2026.
Across ThreatCluster reporting, T1027.002 - Software Packing most frequently co-occurs with Malware, Phishing, Portugal, Spain, CVE-2023-26360, among 12 tracked related entities.
The most significant recent cluster is “Attackers Exploit WDigest Vulnerability to Harvest Plaintext Credentials” (3 articles · Updated July 2, 2026). T1027.002 - Software Packing appears across 1 threat cluster in total, listed above with sources.
T1027.002 - Software Packing appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.