Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1132.001 Standard Encoding |
MalwareSquirrelwaffle | Squirrelwaffle has encoded its communications to C2 servers using Base64. |
| T1132.001 Standard Encoding |
MalwareHOPLIGHT | HOPLIGHT has utilized Zlib compression to obfuscate the communications payload. |
| T1132.001 Standard Encoding |
MalwareRDAT | RDAT can communicate with the C2 via base32-encoded subdomains. |
| T1132.001 Standard Encoding |
MalwareOkrum | Okrum has used base64 to encode C2 communication. |
| T1132.001 Standard Encoding |
MalwareRustyWater | RustyWater has encoded collected data with Base64. |
| T1132.001 Standard Encoding |
MalwareFysbis | Fysbis can use Base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwarePowerShower | PowerShower has the ability to encode C2 communications with base64 encoding. |
| T1132.001 Standard Encoding |
MalwareKazuar | Kazuar encodes communications to the C2 server in Base64. |
| T1132.001 Standard Encoding |
MalwareGLASSTOKEN | GLASSTOKEN has hexadecimal and Base64 encoded C2 content. |
| T1132.001 Standard Encoding |
MalwareFlagpro | Flagpro has encoded bidirectional data communications between a target system and C2 server using Base64. |
| T1132.001 Standard Encoding |
MalwareCORESHELL | CORESHELL C2 messages are Base64-encoded. |
| T1132.001 Standard Encoding |
MalwareDarkWatchman | DarkWatchman encodes data using hexadecimal representation before sending it to the C2 server. |
| T1132.001 Standard Encoding |
MalwareBisonal | Bisonal has encoded binary data with Base64 and ASCII. |
| T1132.001 Standard Encoding |
MalwareS-Type | S-Type uses Base64 encoding for C2 traffic. |
| T1132.001 Standard Encoding |
MalwareSeaDuke | SeaDuke C2 traffic is base64-encoded. |
| T1132.001 Standard Encoding |
MalwareBS2005 | BS2005 uses Base64 encoding for communication in the message body of an HTTP request. |
| T1132.001 Standard Encoding |
MalwareMongall | Mongall can use Base64 to encode information sent to its C2. |
| T1132.001 Standard Encoding |
MalwareLockBit 3.0 | LockBit 3.0 can Base64-encode C2 communication. |
| T1132.001 Standard Encoding |
MalwareCarbanak | Carbanak encodes the message body of HTTP traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareElise | Elise exfiltrates data using cookie values that are Base64-encoded. |
| T1132.001 Standard Encoding |
MalwareLatrodectus | Latrodectus has Base64-encoded the message body of a HTTP request sent to C2. |
| T1132.001 Standard Encoding |
MalwareSaint Bot | Saint Bot has used Base64 to encode its C2 communications. |
| T1132.001 Standard Encoding |
MalwareChaes | Chaes has used Base64 to encode C2 communications. |
| T1132.001 Standard Encoding |
MalwareCharmPower | CharmPower can send additional modules over C2 encoded with base64. |
| T1132.001 Standard Encoding |
MalwareSMOKEDHAM | SMOKEDHAM has encoded its C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareMori | Mori can use Base64 encoded JSON libraries used in C2. |
| T1132.001 Standard Encoding |
MalwareQUADAGENT | QUADAGENT encodes C2 communications with base64. |
| T1132.001 Standard Encoding |
MalwareKONNI | KONNI has used a custom base64 key to encode stolen data before exfiltration. |
| T1132.001 Standard Encoding |
Malwaregh0st RAT | gh0st RAT has used Zlib to compress C2 communications data before encrypting it. |
| T1132.001 Standard Encoding |
MalwareDnsSystem | DnsSystem can Base64 encode data sent to C2. |
| T1132.001 Standard Encoding |
MalwareJHUHUGIT | A JHUHUGIT variant encodes C2 POST data base64. |
| T1132.001 Standard Encoding |
Malwaredown_new | down_new has the ability to base64 encode C2 communications. |
| T1132.001 Standard Encoding |
MalwareIxeshe | Ixeshe uses custom Base64 encoding schemes to obfuscate command and control traffic in the message body of HTTP requests. |
| T1132.001 Standard Encoding |
MalwareRedLine Stealer | RedLine Stealer has used Base64 to encode command and control traffic. |
| T1132.001 Standard Encoding |
MalwareOopsIE | OopsIE encodes data in hexadecimal format over the C2 channel. |
| T1132.001 Standard Encoding |
MalwareRogueRobin | RogueRobin base64 encodes strings that are sent to the C2 over its DNS tunnel. |
| T1132.001 Standard Encoding |
MalwareQUIETCANARY | QUIETCANARY can base64 encode C2 communications. |
| T1132.001 Standard Encoding |
MalwarePHPsert | PHPsert can use Base64-encoded values in C2 communications. |
| T1132.001 Standard Encoding |
MalwareStrelaStealer | StrelaStealer utilizes a hard-coded XOR key to encrypt the content of HTTP POST requests to command and control infrastructure. |
| T1132.001 Standard Encoding |
MalwarePULSECHECK | PULSECHECK can base-64 encode encrypted data sent through C2. |
| T1132.001 Standard Encoding |
MalwareKapeka | Kapeka utilizes JSON objects to send and receive information from command and control nodes. |
| T1132.001 Standard Encoding |
MalwareZebrocy | Zebrocy has used URL/Percent Encoding on data exfiltrated via HTTP POST requests. |
| T1132.001 Standard Encoding |
MalwareSpeakUp | SpeakUp encodes C&C communication using Base64. |
| T1132.001 Standard Encoding |
MalwareWARPWIRE | WARPWIRE can Base64 encode captured credentials with `btoa()` prior to sending to C2. |
| T1132.001 Standard Encoding |
MalwareCobalt Strike | Cobalt Strike can use Base64, URL-safe Base64, or NetBIOS encoding in its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareSUNBURST | SUNBURST used Base64 encoding in its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareCobian RAT | Cobian RAT obfuscates communications with the C2 server using Base64 encoding. |
| T1132.001 Standard Encoding |
MalwareValak | Valak has returned C2 data as encoded ASCII. |
| T1132.001 Standard Encoding |
MalwareSamurai | Samurai can base64 encode data sent in C2 communications prior to its encryption. |
| T1132.001 Standard Encoding |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used `zlib` to compress all data after 0x52 for the custom TCP C2 protocol. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.