ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
CampaignOperation Wocao

During Operation Wocao, threat actors encrypted IP addresses used for "Agent" proxy hops with RC4.

T1001
Data Obfuscation
GroupGamaredon Group

Gamaredon Group has used obfuscated VBScripts with randomly generated variable names and concatenated strings.

T1001
Data Obfuscation
MalwareNinja

Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests.

T1001
Data Obfuscation
MalwareSystemBC

SystemBC has encoded with XOR and encrypted with RC4 its beacon.

T1001
Data Obfuscation
MalwareFlawedAmmyy

FlawedAmmyy may obfuscate portions of the initial C2 handshake.

T1001
Data Obfuscation
MalwareRDAT

RDAT has used encoded data within subdomains as AES ciphertext to communicate from the host to the C2.

T1001
Data Obfuscation
MalwareOkrum

Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests.

T1001
Data Obfuscation
MalwareDarkGate

DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining.

T1001
Data Obfuscation
MalwareStrelaStealer

StrelaStealer encrypts the payload of HTTP POST communications using the same XOR key used for the malware's DLL payload.

T1001
Data Obfuscation
MalwareFRAMESTING

FRAMESTING can send and receive zlib compressed data within `POST` requests.

T1001
Data Obfuscation
MalwareTrailBlazer

TrailBlazer can masquerade its C2 traffic as legitimate Google Notifications HTTP requests.

T1001
Data Obfuscation
MalwareFunnyDream

FunnyDream can send compressed and obfuscated packets to C2.

T1001
Data Obfuscation
MalwareSideTwist

SideTwist can embed C2 responses in the source code of a fake Flickr webpage.

T1001
Data Obfuscation
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has hashed a string containing system information prior to exfiltration via POST requests.

T1001
Data Obfuscation
Toolevilginx2

evilginx2 can modify the Origin and Referrer fields in HTTPS headers it relays between intended victims and legitimate websites to comply with cross-origin resource sharing (CORS) restrictions.

T1001.001
Junk Data
GroupAPT28

APT28 added "junk data" to each encoded string, preventing trivial decoding without knowledge of the junk removal algorithm. Each implant was given a "junk length" value when created, tracked by the controller software to allow seamless communication but prevent analysis of the command protocol on the wire.

T1001.001
Junk Data
MalwareDowndelph

Downdelph inserts pseudo-random characters between each original character during encoding of C2 network requests, making it difficult to write signatures on them.

T1001.001
Junk Data
MalwareUPSTYLE

UPSTYLE retrieves a non-existent webpage from the command and control server then parses commands from the resulting error logs to decode commands to the web shell.

T1001.001
Junk Data
MalwareTurian

Turian can insert pseudo-random characters into its network encryption setup.

T1001.001
Junk Data
MalwareWellMess

WellMess can use junk data in the Base64 string for additional obfuscation.

T1001.001
Junk Data
MalwareGoldMax

GoldMax has used decoy traffic to surround its malicious network traffic to avoid detection.

T1001.001
Junk Data
MalwareBeaverTail

BeaverTail has added junk data or a dummy character prepended to a string to hamper decoding attempts.

T1001.001
Junk Data
MalwareLODEINFO

LODEINFO can append C2 communication with randomly generated junk data.

T1001.001
Junk Data
MalwareP8RAT

P8RAT can send randomly-generated data as part of its C2 communication.

T1001.001
Junk Data
MalwareMori

Mori has obfuscated the FML.dll with 200MB of junk data.

T1001.001
Junk Data
MalwareBendyBear

BendyBear has used byte randomization to obscure its behavior.

T1001.001
Junk Data
MalwareUroburos

Uroburos can add extra characters in encoded strings to help mimic DNS legitimate requests.

T1001.001
Junk Data
MalwareSUNBURST

SUNBURST added junk bytes to its C2 over HTTP.

T1001.001
Junk Data
MalwareP2P ZeuS

P2P ZeuS added junk data to outgoing UDP packets to peer implants.

T1001.001
Junk Data
MalwarePLEAD

PLEAD samples were found to be highly obfuscated with junk code.

T1001.001
Junk Data
MalwareTrailBlazer

TrailBlazer has used random identifier strings to obscure its C2 operations and result codes.

T1001.001
Junk Data
MalwareGrimAgent

GrimAgent can pad C2 messages with random generated values.

T1001.001
Junk Data
MalwareKevin

Kevin can generate a sequence of dummy HTTP C2 requests to obscure traffic.

T1001.002
Steganography
MalwareLunarWeb

LunarWeb can receive C2 commands hidden in the structure of .jpg and .gif images.

T1001.002
Steganography
GroupAxiom

Axiom has used steganography to hide its C2 communications.

T1001.002
Steganography
MalwareHAMMERTOSS

HAMMERTOSS is controlled via commands that are appended to image files.

T1001.002
Steganography
ToolSliver

Sliver can encode binary data into a .PNG file for C2 communication.

T1001.002
Steganography
CampaignOperation Ghost

During Operation Ghost, APT29 used steganography to hide the communications between the implants and their C&C servers.

T1001.002
Steganography
MalwareZox

Zox has used the .PNG file format for C2 communications.

T1001.002
Steganography
MalwareLightNeuron

LightNeuron is controlled via commands that are embedded into PDFs and JPGs using steganographic methods.

T1001.002
Steganography
MalwareZeroT

ZeroT has retrieved stage 2 payloads as Bitmap images that use Least Significant Bit (LSB) steganography.

T1001.002
Steganography
MalwareDaserf

Daserf can use steganography to hide malicious code downloaded to the victim.

T1001.002
Steganography
MalwareRDAT

RDAT can process steganographic images attached to email messages to send and receive C2 commands. RDAT can also embed additional messages within BMP images to communicate with the RDAT operator.

T1001.002
Steganography
MalwareLunarMail

LunarMail can parse IDAT chunks from .png files to look for zlib-compressed and AES encrypted C2 commands.

T1001.002
Steganography
MalwareDuqu

When the Duqu command and control is operating over HTTP or HTTPS, Duqu uploads data to its controller by appending it to a blank JPG file.

T1001.002
Steganography
MalwareSUNBURST

SUNBURST C2 data attempted to appear as benign XML related to .NET assemblies or as a faux JSON blob.

T1001.003
Protocol or Service Impersonation
CampaignC0017

During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server.

T1001.003
Protocol or Service Impersonation
GroupMustang Panda

Mustang Panda has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. Mustang Panda has used FakeTLS to communicate with its C2 servers.

T1001.003
Protocol or Service Impersonation
GroupHigaisa

Higaisa used a FakeTLS session for C2 communications.

T1001.003
Protocol or Service Impersonation
GroupLazarus Group

Lazarus Group malware also uses a unique form of communication encryption known as FakeTLS that mimics TLS but uses a different encryption method, potentially evading SSL traffic inspection/decryption.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.