Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1129 Shared Modules |
MalwareStuxnet | Stuxnet calls LoadLibrary then executes exports from a DLL. |
| T1129 Shared Modules |
MalwareRotaJakiro | RotaJakiro uses dynamically linked shared libraries (`.so` files) to execute additional functionality using `dlopen()` and `dlsym()`. |
| T1129 Shared Modules |
MalwareVersaMem | VersaMem relied on the Java Instrumentation API and Javassist to dynamically modify Java code existing in memory. |
| T1129 Shared Modules |
MalwareBOOSTWRITE | BOOSTWRITE has used the DWriteCreateFactory() function to load additional modules. |
| T1129 Shared Modules |
MalwareLightSpy | LightSpy's main executable and module `.dylib` binaries are loaded using a combination of `dlopen()` to load the library, `_objc_getClass()` to retrieve the class definition, and `_objec_msgSend()` to invoke/execute the specified method in the loaded class. |
| T1129 Shared Modules |
MalwarePUNCHBUGGY | PUNCHBUGGY can load a DLL using the LoadLibrary API. |
| T1129 Shared Modules |
MalwareDarkWatchman | DarkWatchman can load DLLs. |
| T1129 Shared Modules |
MalwareFoggyWeb | FoggyWeb's loader can call the |
| T1129 Shared Modules |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can load and call DLL functions. |
| T1129 Shared Modules |
MalwareMetamorfo | Metamorfo had used AutoIt to load and execute the DLL payload. |
| T1129 Shared Modules |
MalwarePipeMon | PipeMon has used call to |
| T1129 Shared Modules |
Malwaregh0st RAT | gh0st RAT can load DLLs into memory. |
| T1129 Shared Modules |
MalwareAttor | Attor's dispatcher can execute additional plugins by loading the respective DLLs. |
| T1129 Shared Modules |
MalwareOSX_OCEANLOTUS.D | For network communications, OSX_OCEANLOTUS.D loads a dynamic library (`.dylib` file) using `dlopen()` and obtains a function pointer to execute within that shared library using `dlsym()`. |
| T1129 Shared Modules |
MalwareTajMahal | TajMahal has the ability to inject the |
| T1129 Shared Modules |
MalwareEbury | Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`. |
| T1129 Shared Modules |
MalwareKillDisk | KillDisk loads and executes functions from a DLL. |
| T1129 Shared Modules |
MalwareAstaroth | Astaroth uses the LoadLibraryExW() function to load additional modules. |
| T1129 Shared Modules |
MalwareDtrack | Dtrack contains a function that calls |
| T1132 Data Encoding |
MalwareLinux Rabbit | Linux Rabbit sends the payload from the C2 server as an encoded URL parameter. |
| T1132 Data Encoding |
MalwareUrsnif | Ursnif has used encoded data in HTTP URLs for C2. |
| T1132 Data Encoding |
MalwareLAMEHUG | LAMEHUG can encode queries sent to LLMs. |
| T1132 Data Encoding |
MalwareBADNEWS | After encrypting C2 data, BADNEWS converts it into a hexadecimal representation and then encodes it into base64. |
| T1132 Data Encoding |
MalwareH1N1 | H1N1 obfuscates C2 traffic with an altered version of base64. |
| T1132 Data Encoding |
Toolevilginx2 | evilginx2 can randomly generate and Base64 encode parameters in phishing links to defeat static detection. |
| T1132 Data Encoding |
ToolMythic | Mythic provides various transform functions to encode and/or randomize C2 data. |
| T1132.001 Standard Encoding |
MalwareTrickBot | TrickBot can Base64-encode C2 commands. |
| T1132.001 Standard Encoding |
MalwareBLINDINGCAN | BLINDINGCAN has encoded its C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwarePikabot | Pikabot uses base64 encoding in conjunction with symmetric encryption mechanisms to obfuscate command and control communications. |
| T1132.001 Standard Encoding |
MalwareSpark | Spark has encoded communications with the C2 server with base64. |
| T1132.001 Standard Encoding |
MalwareBumblebee | Bumblebee has the ability to base64 encode C2 server responses. |
| T1132.001 Standard Encoding |
MalwareBRICKSTORM | BRICKSTORM has leveraged Base64 to encode C2 communications. |
| T1132.001 Standard Encoding |
MalwareTorisma | Torisma has encoded C2 communications with Base64. |
| T1132.001 Standard Encoding |
MalwareBackdoor.Oldrea | Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers. |
| T1132.001 Standard Encoding |
MalwareStuxnet | Stuxnet transforms encrypted binary data into an ASCII string in order to use it as a URL parameter value. |
| T1132.001 Standard Encoding |
MalwareRotaJakiro | RotaJakiro uses ZLIB Compression to compresses data sent to the C2 server in the `payload` section network communication packet. |
| T1132.001 Standard Encoding |
MalwarePOWRUNER | POWRUNER can use base64 encoded C2 communications. |
| T1132.001 Standard Encoding |
MalwareSardonic | Sardonic can encode client ID data in 32 uppercase hex characters and transfer to the actor-controlled C2 server. |
| T1132.001 Standard Encoding |
MalwareMisdat | Misdat network traffic is Base64-encoded plaintext. |
| T1132.001 Standard Encoding |
MalwareTAMECAT | TAMECAT has encoded C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareFelismus | Some Felismus samples use a custom method for C2 traffic that utilizes Base64. |
| T1132.001 Standard Encoding |
MalwarexCaon | xCaon has used Base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareGomir | Gomir uses Base64-encoded content in HTTP communications to command and control infrastructure. |
| T1132.001 Standard Encoding |
MalwareEmotet | Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Additionally, Emotet has used Base64 to encode data before sending to the C2 server. |
| T1132.001 Standard Encoding |
MalwareMachete | Machete has used base64 encoding. |
| T1132.001 Standard Encoding |
MalwarePrikormka | Prikormka encodes C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareGootloader | Gootloader can retrieve a Base64 encoded stager from C2. |
| T1132.001 Standard Encoding |
MalwarePingPull | PingPull can encode C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareWellMess | WellMess has used Base64 encoding to uniquely identify communication to and from the C2. |
| T1132.001 Standard Encoding |
MalwareMafalda | Mafalda can encode data using Base64 prior to exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.