ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1132.001
Standard Encoding
MalwareDaserf

Daserf uses custom base64 encoding to obfuscate HTTP traffic.

T1132.001
Standard Encoding
MalwareSolar

Solar can Base64-encode and gzip compress C2 communications including command outputs.

T1132.001
Standard Encoding
MalwarePisloader

Responses from the Pisloader C2 server are base32-encoded.

T1132.001
Standard Encoding
MalwareRamsay

Ramsay has used base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwareRevenge RAT

Revenge RAT uses Base64 to encode information sent to the C2 server.

T1132.001
Standard Encoding
MalwareMore_eggs

More_eggs has used basE91 encoding, along with encryption, for C2 communication.

T1132.001
Standard Encoding
MalwareSysUpdate

SysUpdate has used Base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwareMango

Mango can receive Base64-encoded commands from C2.

T1132.001
Standard Encoding
MalwareWIREFIRE

WIREFIRE can Base64 encode process output sent to C2.

T1132.001
Standard Encoding
MalwareKessel

Kessel has exfiltrated data via hexadecimal-encoded subdomain fields of DNS queries.

T1132.001
Standard Encoding
MalwareGrimAgent

GrimAgent can base64 encode C2 replies.

T1132.001
Standard Encoding
MalwareSTEADYPULSE

STEADYPULSE can transmit URL encoded data over C2.

T1132.001
Standard Encoding
MalwareSLIGHTPULSE

SLIGHTPULSE can base64 encode all incoming and outgoing C2 messages.

T1132.001
Standard Encoding
MalwareBabyShark

BabyShark has encoded data using certutil before exfiltration.

T1132.001
Standard Encoding
MalwareCreepySnail

CreepySnail can use Base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwareTroll Stealer

Troll Stealer performs XOR encryption and Base64 encoding of data prior to sending to command and control infrastructure.

T1132.001
Standard Encoding
MalwareEbury

Ebury has encoded C2 traffic in hexadecimal format.

T1132.001
Standard Encoding
MalwarenjRAT

njRAT uses Base64 encoding for C2 traffic.

T1132.001
Standard Encoding
MalwareChChes

ChChes can encode C2 data with a custom technique that utilizes Base64.

T1132.001
Standard Encoding
MalwareManjusaka

Manjusaka communication includes a client-created session cookie with base64-encoded information representing information from the victim system.

T1132.001
Standard Encoding
MalwareSideTwist

SideTwist has used Base64 for encoded C2 traffic.

T1132.001
Standard Encoding
MalwareMechaFlounder

MechaFlounder has the ability to use base16 encoded strings in C2.

T1132.001
Standard Encoding
MalwareMis-Type

Mis-Type uses Base64 encoding for C2 traffic.

T1132.001
Standard Encoding
MalwareLunarWeb

LunarWeb can use Base64 encoding to obfuscate C2 commands.

T1132.001
Standard Encoding
MalwareDipsind

Dipsind encodes C2 traffic with base64.

T1132.001
Standard Encoding
MalwareOctopus

Octopus has encoded C2 communications in Base64.

T1132.001
Standard Encoding
MalwareSTARWHALE

STARWHALE has the ability to hex-encode collected data from an infected host.

T1132.001
Standard Encoding
MalwareKevin

Kevin can Base32 encode chunks of output files during exfiltration.

T1132.001
Standard Encoding
MalwarePOWERSTATS

POWERSTATS encoded C2 traffic with base64.

T1132.001
Standard Encoding
MalwareBADNEWS

BADNEWS encodes C2 traffic with base64.

T1132.001
Standard Encoding
MalwareAstaroth

Astaroth encodes data using Base64 before sending it to the C2 server.

T1132.001
Standard Encoding
MalwareQakBot

QakBot can Base64 encode system information sent to C2.

T1132.001
Standard Encoding
MalwareHelminth

For C2 over HTTP, Helminth encodes data with base64 and sends it via the "Cookie" field of HTTP requests. For C2 over DNS, Helminth converts ASCII characters into their hexadecimal values and sends the data in cleartext.

T1132.001
Standard Encoding
MalwareDenis

Denis encodes the data sent to the server in Base64.

T1132.001
Standard Encoding
MalwareAutoIt backdoor

AutoIt backdoor has sent a C2 response that was base64-encoded.

T1132.001
Standard Encoding
MalwareUPPERCUT

UPPERCUT can base64 encode C2 communications.

T1132.001
Standard Encoding
MalwareADVSTORESHELL

C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding.

T1132.001
Standard Encoding
ToolSliver

Sliver can use standard encoding techniques like gzip and hex to ASCII to encode the C2 communication payload.

T1132.001
Standard Encoding
ToolRemcos

Remcos can serialize collected data with Protobuf.

T1132.001
Standard Encoding
MalwareMini Shai-Hulud

Mini Shai-Hulud has used base64 encoding to obfuscate URLs used for C2.

T1132.002
Non-Standard Encoding
MalwareNinja

Ninja can encode C2 communications with a base64 algorithm using a custom alphabet.

T1132.002
Non-Standard Encoding
MalwareBankshot

Bankshot encodes commands from the control server using a range of characters and gzip.

T1132.002
Non-Standard Encoding
MalwareTONESHELL

TONESHELL has encoded a payload with a random 32-byte key using XOR. TONESHELL has also encoded payloads with a 256-byte key using XOR.

T1132.002
Non-Standard Encoding
MalwareOceanSalt

OceanSalt can encode data with a NOT operation before sending the data to the control server.

T1132.002
Non-Standard Encoding
MalwareInvisiMole

InvisiMole can use a modified base32 encoding to encode data within the subdomain of C2 requests.

T1132.002
Non-Standard Encoding
MalwareRDAT

RDAT can communicate with the C2 via subdomains that utilize base64 with character substitutions.

T1132.002
Non-Standard Encoding
MalwareHTTPTroy

HTTPTroy has obfuscated HTTP POST request communications utilizing XOR with a designated key of 0x56, followed by Base64 encoding.

T1132.002
Non-Standard Encoding
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use a custom Base64 alphabet for encoding C2.

T1132.002
Non-Standard Encoding
MalwareUroburos

Uroburos can use a custom base62 and a de-facto base32 encoding that uses digits 0-9 and lowercase letters a-z in C2 communications.

T1132.002
Non-Standard Encoding
MalwareNightClub

NightClub has used a non-standard encoding in DNS tunneling removing any `=` from the result of base64 encoding, and replacing `/` characters with `-s` and `+` characters with `-p`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.