Obfuscated Files or Information: Dynamic API Resolution

Threat Actors may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis. Malware commonly uses various Native APIfunctions provided by the OS to perform various tasks such as those involving processes, files, and other system artifacts.

ID: ATAGS-T1104.005
Sub-technique of:  ATAGS-T1104
Tactic: Defense Evasion
Targeted Components: Software
Responsibility: Provider
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.