Threat Actors may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis. Malware commonly uses various Native APIfunctions provided by the OS to perform various tasks such as those involving processes, files, and other system artifacts.
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.