ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1132.001
Standard Encoding
MalwareSquirrelwaffle

Squirrelwaffle has encoded its communications to C2 servers using Base64.

T1132.001
Standard Encoding
MalwareHOPLIGHT

HOPLIGHT has utilized Zlib compression to obfuscate the communications payload.

T1132.001
Standard Encoding
MalwareRDAT

RDAT can communicate with the C2 via base32-encoded subdomains.

T1132.001
Standard Encoding
MalwareOkrum

Okrum has used base64 to encode C2 communication.

T1132.001
Standard Encoding
MalwareRustyWater

RustyWater has encoded collected data with Base64.

T1132.001
Standard Encoding
MalwareFysbis

Fysbis can use Base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwarePowerShower

PowerShower has the ability to encode C2 communications with base64 encoding.

T1132.001
Standard Encoding
MalwareKazuar

Kazuar encodes communications to the C2 server in Base64.

T1132.001
Standard Encoding
MalwareGLASSTOKEN

GLASSTOKEN has hexadecimal and Base64 encoded C2 content.

T1132.001
Standard Encoding
MalwareFlagpro

Flagpro has encoded bidirectional data communications between a target system and C2 server using Base64.

T1132.001
Standard Encoding
MalwareCORESHELL

CORESHELL C2 messages are Base64-encoded.

T1132.001
Standard Encoding
MalwareDarkWatchman

DarkWatchman encodes data using hexadecimal representation before sending it to the C2 server.

T1132.001
Standard Encoding
MalwareBisonal

Bisonal has encoded binary data with Base64 and ASCII.

T1132.001
Standard Encoding
MalwareS-Type

S-Type uses Base64 encoding for C2 traffic.

T1132.001
Standard Encoding
MalwareSeaDuke

SeaDuke C2 traffic is base64-encoded.

T1132.001
Standard Encoding
MalwareBS2005

BS2005 uses Base64 encoding for communication in the message body of an HTTP request.

T1132.001
Standard Encoding
MalwareMongall

Mongall can use Base64 to encode information sent to its C2.

T1132.001
Standard Encoding
MalwareLockBit 3.0

LockBit 3.0 can Base64-encode C2 communication.

T1132.001
Standard Encoding
MalwareCarbanak

Carbanak encodes the message body of HTTP traffic with Base64.

T1132.001
Standard Encoding
MalwareElise

Elise exfiltrates data using cookie values that are Base64-encoded.

T1132.001
Standard Encoding
MalwareLatrodectus

Latrodectus has Base64-encoded the message body of a HTTP request sent to C2.

T1132.001
Standard Encoding
MalwareSaint Bot

Saint Bot has used Base64 to encode its C2 communications.

T1132.001
Standard Encoding
MalwareChaes

Chaes has used Base64 to encode C2 communications.

T1132.001
Standard Encoding
MalwareCharmPower

CharmPower can send additional modules over C2 encoded with base64.

T1132.001
Standard Encoding
MalwareSMOKEDHAM

SMOKEDHAM has encoded its C2 traffic with Base64.

T1132.001
Standard Encoding
MalwareMori

Mori can use Base64 encoded JSON libraries used in C2.

T1132.001
Standard Encoding
MalwareQUADAGENT

QUADAGENT encodes C2 communications with base64.

T1132.001
Standard Encoding
MalwareKONNI

KONNI has used a custom base64 key to encode stolen data before exfiltration.

T1132.001
Standard Encoding
Malwaregh0st RAT

gh0st RAT has used Zlib to compress C2 communications data before encrypting it.

T1132.001
Standard Encoding
MalwareDnsSystem

DnsSystem can Base64 encode data sent to C2.

T1132.001
Standard Encoding
MalwareJHUHUGIT

A JHUHUGIT variant encodes C2 POST data base64.

T1132.001
Standard Encoding
Malwaredown_new

down_new has the ability to base64 encode C2 communications.

T1132.001
Standard Encoding
MalwareIxeshe

Ixeshe uses custom Base64 encoding schemes to obfuscate command and control traffic in the message body of HTTP requests.

T1132.001
Standard Encoding
MalwareRedLine Stealer

RedLine Stealer has used Base64 to encode command and control traffic.

T1132.001
Standard Encoding
MalwareOopsIE

OopsIE encodes data in hexadecimal format over the C2 channel.

T1132.001
Standard Encoding
MalwareRogueRobin

RogueRobin base64 encodes strings that are sent to the C2 over its DNS tunnel.

T1132.001
Standard Encoding
MalwareQUIETCANARY

QUIETCANARY can base64 encode C2 communications.

T1132.001
Standard Encoding
MalwarePHPsert

PHPsert can use Base64-encoded values in C2 communications.

T1132.001
Standard Encoding
MalwareStrelaStealer

StrelaStealer utilizes a hard-coded XOR key to encrypt the content of HTTP POST requests to command and control infrastructure.

T1132.001
Standard Encoding
MalwarePULSECHECK

PULSECHECK can base-64 encode encrypted data sent through C2.

T1132.001
Standard Encoding
MalwareKapeka

Kapeka utilizes JSON objects to send and receive information from command and control nodes.

T1132.001
Standard Encoding
MalwareZebrocy

Zebrocy has used URL/Percent Encoding on data exfiltrated via HTTP POST requests.

T1132.001
Standard Encoding
MalwareSpeakUp

SpeakUp encodes C&C communication using Base64.

T1132.001
Standard Encoding
MalwareWARPWIRE

WARPWIRE can Base64 encode captured credentials with `btoa()` prior to sending to C2.

T1132.001
Standard Encoding
MalwareCobalt Strike

Cobalt Strike can use Base64, URL-safe Base64, or NetBIOS encoding in its C2 traffic.

T1132.001
Standard Encoding
MalwareSUNBURST

SUNBURST used Base64 encoding in its C2 traffic.

T1132.001
Standard Encoding
MalwareCobian RAT

Cobian RAT obfuscates communications with the C2 server using Base64 encoding.

T1132.001
Standard Encoding
MalwareValak

Valak has returned C2 data as encoded ASCII.

T1132.001
Standard Encoding
MalwareSamurai

Samurai can base64 encode data sent in C2 communications prior to its encryption.

T1132.001
Standard Encoding
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used `zlib` to compress all data after 0x52 for the custom TCP C2 protocol.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.