Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareNinja | Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests. |
| T1001 Data Obfuscation |
MalwareSystemBC | SystemBC has encoded with XOR and encrypted with RC4 its beacon. |
| T1001 Data Obfuscation |
MalwareFlawedAmmyy | FlawedAmmyy may obfuscate portions of the initial C2 handshake. |
| T1001 Data Obfuscation |
MalwareRDAT | RDAT has used encoded data within subdomains as AES ciphertext to communicate from the host to the C2. |
| T1001 Data Obfuscation |
MalwareOkrum | Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests. |
| T1001 Data Obfuscation |
MalwareDarkGate | DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining. |
| T1001 Data Obfuscation |
MalwareStrelaStealer | StrelaStealer encrypts the payload of HTTP POST communications using the same XOR key used for the malware's DLL payload. |
| T1001 Data Obfuscation |
MalwareFRAMESTING | FRAMESTING can send and receive zlib compressed data within `POST` requests. |
| T1001 Data Obfuscation |
MalwareTrailBlazer | TrailBlazer can masquerade its C2 traffic as legitimate Google Notifications HTTP requests. |
| T1001 Data Obfuscation |
MalwareFunnyDream | FunnyDream can send compressed and obfuscated packets to C2. |
| T1001 Data Obfuscation |
MalwareSideTwist | SideTwist can embed C2 responses in the source code of a fake Flickr webpage. |
| T1001 Data Obfuscation |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has hashed a string containing system information prior to exfiltration via POST requests. |
| T1001 Data Obfuscation |
Toolevilginx2 | evilginx2 can modify the Origin and Referrer fields in HTTPS headers it relays between intended victims and legitimate websites to comply with cross-origin resource sharing (CORS) restrictions. |
| T1001.001 Junk Data |
MalwareDowndelph | Downdelph inserts pseudo-random characters between each original character during encoding of C2 network requests, making it difficult to write signatures on them. |
| T1001.001 Junk Data |
MalwareUPSTYLE | UPSTYLE retrieves a non-existent webpage from the command and control server then parses commands from the resulting error logs to decode commands to the web shell. |
| T1001.001 Junk Data |
MalwareTurian | Turian can insert pseudo-random characters into its network encryption setup. |
| T1001.001 Junk Data |
MalwareWellMess | WellMess can use junk data in the Base64 string for additional obfuscation. |
| T1001.001 Junk Data |
MalwareGoldMax | GoldMax has used decoy traffic to surround its malicious network traffic to avoid detection. |
| T1001.001 Junk Data |
MalwareBeaverTail | BeaverTail has added junk data or a dummy character prepended to a string to hamper decoding attempts. |
| T1001.001 Junk Data |
MalwareLODEINFO | LODEINFO can append C2 communication with randomly generated junk data. |
| T1001.001 Junk Data |
MalwareP8RAT | P8RAT can send randomly-generated data as part of its C2 communication. |
| T1001.001 Junk Data |
MalwareMori | Mori has obfuscated the FML.dll with 200MB of junk data. |
| T1001.001 Junk Data |
MalwareBendyBear | BendyBear has used byte randomization to obscure its behavior. |
| T1001.001 Junk Data |
MalwareUroburos | Uroburos can add extra characters in encoded strings to help mimic DNS legitimate requests. |
| T1001.001 Junk Data |
MalwareSUNBURST | SUNBURST added junk bytes to its C2 over HTTP. |
| T1001.001 Junk Data |
MalwareP2P ZeuS | P2P ZeuS added junk data to outgoing UDP packets to peer implants. |
| T1001.001 Junk Data |
MalwarePLEAD | PLEAD samples were found to be highly obfuscated with junk code. |
| T1001.001 Junk Data |
MalwareTrailBlazer | TrailBlazer has used random identifier strings to obscure its C2 operations and result codes. |
| T1001.001 Junk Data |
MalwareGrimAgent | GrimAgent can pad C2 messages with random generated values. |
| T1001.001 Junk Data |
MalwareKevin | Kevin can generate a sequence of dummy HTTP C2 requests to obscure traffic. |
| T1001.002 Steganography |
MalwareLunarWeb | LunarWeb can receive C2 commands hidden in the structure of .jpg and .gif images. |
| T1001.002 Steganography |
MalwareHAMMERTOSS | HAMMERTOSS is controlled via commands that are appended to image files. |
| T1001.002 Steganography |
ToolSliver | Sliver can encode binary data into a .PNG file for C2 communication. |
| T1001.002 Steganography |
MalwareZox | Zox has used the .PNG file format for C2 communications. |
| T1001.002 Steganography |
MalwareLightNeuron | LightNeuron is controlled via commands that are embedded into PDFs and JPGs using steganographic methods. |
| T1001.002 Steganography |
MalwareZeroT | ZeroT has retrieved stage 2 payloads as Bitmap images that use Least Significant Bit (LSB) steganography. |
| T1001.002 Steganography |
MalwareDaserf | Daserf can use steganography to hide malicious code downloaded to the victim. |
| T1001.002 Steganography |
MalwareRDAT | RDAT can process steganographic images attached to email messages to send and receive C2 commands. RDAT can also embed additional messages within BMP images to communicate with the RDAT operator. |
| T1001.002 Steganography |
MalwareLunarMail | LunarMail can parse IDAT chunks from .png files to look for zlib-compressed and AES encrypted C2 commands. |
| T1001.002 Steganography |
MalwareDuqu | When the Duqu command and control is operating over HTTP or HTTPS, Duqu uploads data to its controller by appending it to a blank JPG file. |
| T1001.002 Steganography |
MalwareSUNBURST | SUNBURST C2 data attempted to appear as benign XML related to .NET assemblies or as a faux JSON blob. |
| T1001.003 Protocol or Service Impersonation |
MalwareNinja | Ninja has the ability to mimic legitimate services with customized HTTP URL paths and headers to hide malicious traffic. |
| T1001.003 Protocol or Service Impersonation |
MalwareBankshot | Bankshot generates a false TLS handshake using a public certificate to disguise C2 network communications. |
| T1001.003 Protocol or Service Impersonation |
MalwareTONESHELL | TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3. |
| T1001.003 Protocol or Service Impersonation |
MalwareBOOKWORM | BOOKWORM has modified HTTP POST requests to resemble legitimate communications. |
| T1001.003 Protocol or Service Impersonation |
MalwarePUBLOAD | PUBLOAD has modified HTTP POST requests to resemble legitimate communications. PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03. |
| T1001.003 Protocol or Service Impersonation |
MalwareInvisiMole | InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP. |
| T1001.003 Protocol or Service Impersonation |
MalwareOkrum | Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests. |
| T1001.003 Protocol or Service Impersonation |
MalwareKeyBoy | KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic. |
| T1001.003 Protocol or Service Impersonation |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE has used FakeTLS for session authentication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.