ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1132.001×

114 examples

TechniqueUsed byProcedure example
T1132.001
Standard Encoding
MalwareTrickBot

TrickBot can Base64-encode C2 commands.

T1132.001
Standard Encoding
MalwareBLINDINGCAN

BLINDINGCAN has encoded its C2 traffic with Base64.

T1132.001
Standard Encoding
MalwarePikabot

Pikabot uses base64 encoding in conjunction with symmetric encryption mechanisms to obfuscate command and control communications.

T1132.001
Standard Encoding
MalwareSpark

Spark has encoded communications with the C2 server with base64.

T1132.001
Standard Encoding
MalwareBumblebee

Bumblebee has the ability to base64 encode C2 server responses.

T1132.001
Standard Encoding
MalwareBRICKSTORM

BRICKSTORM has leveraged Base64 to encode C2 communications.

T1132.001
Standard Encoding
MalwareTorisma

Torisma has encoded C2 communications with Base64.

T1132.001
Standard Encoding
MalwareBackdoor.Oldrea

Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers.

T1132.001
Standard Encoding
MalwareStuxnet

Stuxnet transforms encrypted binary data into an ASCII string in order to use it as a URL parameter value.

T1132.001
Standard Encoding
MalwareRotaJakiro

RotaJakiro uses ZLIB Compression to compresses data sent to the C2 server in the `payload` section network communication packet.

T1132.001
Standard Encoding
MalwarePOWRUNER

POWRUNER can use base64 encoded C2 communications.

T1132.001
Standard Encoding
MalwareSardonic

Sardonic can encode client ID data in 32 uppercase hex characters and transfer to the actor-controlled C2 server.

T1132.001
Standard Encoding
MalwareMisdat

Misdat network traffic is Base64-encoded plaintext.

T1132.001
Standard Encoding
MalwareTAMECAT

TAMECAT has encoded C2 traffic with Base64.

T1132.001
Standard Encoding
MalwareFelismus

Some Felismus samples use a custom method for C2 traffic that utilizes Base64.

T1132.001
Standard Encoding
MalwarexCaon

xCaon has used Base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwareGomir

Gomir uses Base64-encoded content in HTTP communications to command and control infrastructure.

T1132.001
Standard Encoding
MalwareEmotet

Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Additionally, Emotet has used Base64 to encode data before sending to the C2 server.

T1132.001
Standard Encoding
MalwareMachete

Machete has used base64 encoding.

T1132.001
Standard Encoding
MalwarePrikormka

Prikormka encodes C2 traffic with Base64.

T1132.001
Standard Encoding
MalwareGootloader

Gootloader can retrieve a Base64 encoded stager from C2.

T1132.001
Standard Encoding
MalwarePingPull

PingPull can encode C2 traffic with Base64.

T1132.001
Standard Encoding
MalwareWellMess

WellMess has used Base64 encoding to uniquely identify communication to and from the C2.

T1132.001
Standard Encoding
MalwareMafalda

Mafalda can encode data using Base64 prior to exfiltration.

T1132.001
Standard Encoding
MalwareSquirrelwaffle

Squirrelwaffle has encoded its communications to C2 servers using Base64.

T1132.001
Standard Encoding
MalwareHOPLIGHT

HOPLIGHT has utilized Zlib compression to obfuscate the communications payload.

T1132.001
Standard Encoding
MalwareRDAT

RDAT can communicate with the C2 via base32-encoded subdomains.

T1132.001
Standard Encoding
MalwareOkrum

Okrum has used base64 to encode C2 communication.

T1132.001
Standard Encoding
MalwareRustyWater

RustyWater has encoded collected data with Base64.

T1132.001
Standard Encoding
MalwareFysbis

Fysbis can use Base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwarePowerShower

PowerShower has the ability to encode C2 communications with base64 encoding.

T1132.001
Standard Encoding
MalwareKazuar

Kazuar encodes communications to the C2 server in Base64.

T1132.001
Standard Encoding
MalwareGLASSTOKEN

GLASSTOKEN has hexadecimal and Base64 encoded C2 content.

T1132.001
Standard Encoding
MalwareFlagpro

Flagpro has encoded bidirectional data communications between a target system and C2 server using Base64.

T1132.001
Standard Encoding
MalwareCORESHELL

CORESHELL C2 messages are Base64-encoded.

T1132.001
Standard Encoding
MalwareDarkWatchman

DarkWatchman encodes data using hexadecimal representation before sending it to the C2 server.

T1132.001
Standard Encoding
MalwareBisonal

Bisonal has encoded binary data with Base64 and ASCII.

T1132.001
Standard Encoding
MalwareS-Type

S-Type uses Base64 encoding for C2 traffic.

T1132.001
Standard Encoding
MalwareSeaDuke

SeaDuke C2 traffic is base64-encoded.

T1132.001
Standard Encoding
MalwareBS2005

BS2005 uses Base64 encoding for communication in the message body of an HTTP request.

T1132.001
Standard Encoding
MalwareMongall

Mongall can use Base64 to encode information sent to its C2.

T1132.001
Standard Encoding
MalwareLockBit 3.0

LockBit 3.0 can Base64-encode C2 communication.

T1132.001
Standard Encoding
MalwareCarbanak

Carbanak encodes the message body of HTTP traffic with Base64.

T1132.001
Standard Encoding
MalwareElise

Elise exfiltrates data using cookie values that are Base64-encoded.

T1132.001
Standard Encoding
MalwareLatrodectus

Latrodectus has Base64-encoded the message body of a HTTP request sent to C2.

T1132.001
Standard Encoding
MalwareSaint Bot

Saint Bot has used Base64 to encode its C2 communications.

T1132.001
Standard Encoding
MalwareChaes

Chaes has used Base64 to encode C2 communications.

T1132.001
Standard Encoding
MalwareCharmPower

CharmPower can send additional modules over C2 encoded with base64.

T1132.001
Standard Encoding
MalwareSMOKEDHAM

SMOKEDHAM has encoded its C2 traffic with Base64.

T1132.001
Standard Encoding
MalwareMori

Mori can use Base64 encoded JSON libraries used in C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.