Real-world descriptions of how a group, tool or campaign used a technique.
167 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.001 Symmetric Cryptography |
MalwareTrickBot | TrickBot uses a custom crypter leveraging Microsoft’s CryptoAPI to encrypt C2 traffic.Newer versions of TrickBot have been known to use `bcrypt` to encrypt and digitally sign responses to their C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareBLINDINGCAN | BLINDINGCAN has encrypted its C2 traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareNinja | Ninja can XOR and AES encrypt C2 messages. |
| T1573.001 Symmetric Cryptography |
MalwarePikabot | Earlier Pikabot variants use a custom encryption procedure leveraging multiple mechanisms including AES with multiple rounds of Base64 encoding for its command and control communication. Later Pikabot variants eliminate the use of AES and instead use RC4 encryption for transmitted information. |
| T1573.001 Symmetric Cryptography |
MalwareBumblebee | Bumblebee can encrypt C2 requests and responses with RC4 |
| T1573.001 Symmetric Cryptography |
MalwareTorisma | Torisma has encrypted its C2 communications using XOR and VEST-32. |
| T1573.001 Symmetric Cryptography |
MalwareStuxnet | Stuxnet encodes the payload of system information sent to the command and control servers using a one byte 0xFF XOR key. Stuxnet also uses a 31-byte long static byte string to XOR data sent to command and control servers. The servers use a different static key to encrypt replies to the implant. |
| T1573.001 Symmetric Cryptography |
MalwareDowndelph | Downdelph uses RC4 to encrypt C2 responses. |
| T1573.001 Symmetric Cryptography |
MalwareRotaJakiro | RotaJakiro encrypts C2 communication using a combination of AES, XOR, ROTATE encryption, and ZLIB compression. |
| T1573.001 Symmetric Cryptography |
MalwareSardonic | Sardonic has the ability to use an RC4 key to encrypt communications to and from actor-controlled C2 servers. |
| T1573.001 Symmetric Cryptography |
MalwareEmissary | The C2 server response to a beacon sent by a variant of Emissary contains a 36-character GUID value that is used as an encryption key for subsequent network communications. Some variants of Emissary use various XOR operations to encrypt C2 data. |
| T1573.001 Symmetric Cryptography |
MalwareKEYMARBLE | KEYMARBLE uses a customized XOR algorithm to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareTAMECAT | TAMECAT has used AES to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareCASTLETAP | CASTLETAP can receive a 9-byte XOR encrypted activation string in the payload of an ICMP echo request packet. |
| T1573.001 Symmetric Cryptography |
MalwareRedLeaves | RedLeaves has encrypted C2 traffic with RC4, previously using keys of 88888888 and babybear. |
| T1573.001 Symmetric Cryptography |
MalwareFelismus | Some Felismus samples use a custom encryption method for C2 traffic that utilizes AES and multiple keys. |
| T1573.001 Symmetric Cryptography |
MalwareHavoc | Havoc can send an AES encrypted check-in request to the C2 server. |
| T1573.001 Symmetric Cryptography |
MalwarexCaon | xCaon has encrypted data sent to the C2 server using a XOR key. |
| T1573.001 Symmetric Cryptography |
MalwarePLAINTEE | PLAINTEE encodes C2 beacons using XOR. |
| T1573.001 Symmetric Cryptography |
MalwareNebulae | Nebulae can use RC4 and XOR to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareLurid | Lurid performs XOR encryption. |
| T1573.001 Symmetric Cryptography |
MalwareTONESHELL | TONESHELL has used RC4 encryption in C2 communications. TONESHELL variants used a randomly generated variable length (0x20 - 0x200 bytes) rolling XOR key to encrypt and decrypt network packets. |
| T1573.001 Symmetric Cryptography |
MalwareRainyDay | RainyDay can use RC4 to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareNETWIRE | NETWIRE can use AES encryption for C2 data transferred. |
| T1573.001 Symmetric Cryptography |
MalwareBOOKWORM | BOOKWORM has used encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO. |
| T1573.001 Symmetric Cryptography |
MalwareHyperStack | HyperStack has used RSA encryption for C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareHAMMERTOSS | Before being appended to image files, HAMMERTOSS commands are encrypted with a key composed of both a hard-coded value and a string contained on that day's tweet. To decrypt the commands, an investigator would need access to the intended malware sample, the day's tweet, and the image file containing the command. |
| T1573.001 Symmetric Cryptography |
MalwareCosmicDuke | CosmicDuke contains a custom version of the RC4 algorithm that includes a programming error. |
| T1573.001 Symmetric Cryptography |
MalwareGreyEnergy | GreyEnergy encrypts communications using AES256. |
| T1573.001 Symmetric Cryptography |
MalwareEmotet | Emotet is known to use RSA keys for encrypting C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareSNUGRIDE | SNUGRIDE encrypts C2 traffic using AES with a static key. |
| T1573.001 Symmetric Cryptography |
MalwareTHINCRUST | THINCRUST can process RSA encryted C2 commands. |
| T1573.001 Symmetric Cryptography |
MalwareMachete | Machete has used AES to exfiltrate documents. |
| T1573.001 Symmetric Cryptography |
MalwarePrikormka | Prikormka encrypts some C2 traffic with the Blowfish cipher. |
| T1573.001 Symmetric Cryptography |
MalwarePUBLOAD | PUBLOAD has used RC4 encryption in C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareSystemBC | SystemBC has encrypted its C2 traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwarePingPull | PingPull can use AES, in cipher block chaining (CBC) mode padded with PKCS5, to encrypt C2 server communications. |
| T1573.001 Symmetric Cryptography |
MalwareWellMess | WellMess can encrypt HTTP POST data using RC6 and a dynamically generated AES key encrypted with a hard coded RSA public key. |
| T1573.001 Symmetric Cryptography |
MalwareWoody RAT | Woody RAT can use AES-CBC to encrypt data sent to its C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareMafalda | Mafalda can encrypt its C2 traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareSombRAT | SombRAT has encrypted its C2 communications with AES. |
| T1573.001 Symmetric Cryptography |
MalwareFlawedAmmyy | FlawedAmmyy has used SEAL encryption during the initial C2 handshake. |
| T1573.001 Symmetric Cryptography |
MalwareRifdoor | Rifdoor has encrypted command and control (C2) communications with a stream cipher. |
| T1573.001 Symmetric Cryptography |
MalwareInvisiMole | InvisiMole uses variations of a simple XOR encryption routine for C&C communications. |
| T1573.001 Symmetric Cryptography |
MalwareVolgmer | Volgmer uses a simple XOR cipher to encrypt traffic and files. |
| T1573.001 Symmetric Cryptography |
MalwareZeroT | ZeroT has used RC4 to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareRDAT | RDAT has used AES ciphertext to encode C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareOkrum | Okrum uses AES to encrypt network traffic. The key can be hardcoded or negotiated with the C2 server in the registration phase. |
| T1573.001 Symmetric Cryptography |
MalwareBonadan | Bonadan can XOR-encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareRustyWater | RustyWater has encrypted encoded data with XOR before sending it to the C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.