Real-world descriptions of how a group, tool or campaign used a technique.
114 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1132.001 Standard Encoding |
MalwareQUADAGENT | QUADAGENT encodes C2 communications with base64. |
| T1132.001 Standard Encoding |
MalwareKONNI | KONNI has used a custom base64 key to encode stolen data before exfiltration. |
| T1132.001 Standard Encoding |
Malwaregh0st RAT | gh0st RAT has used Zlib to compress C2 communications data before encrypting it. |
| T1132.001 Standard Encoding |
MalwareDnsSystem | DnsSystem can Base64 encode data sent to C2. |
| T1132.001 Standard Encoding |
MalwareJHUHUGIT | A JHUHUGIT variant encodes C2 POST data base64. |
| T1132.001 Standard Encoding |
Malwaredown_new | down_new has the ability to base64 encode C2 communications. |
| T1132.001 Standard Encoding |
MalwareIxeshe | Ixeshe uses custom Base64 encoding schemes to obfuscate command and control traffic in the message body of HTTP requests. |
| T1132.001 Standard Encoding |
MalwareRedLine Stealer | RedLine Stealer has used Base64 to encode command and control traffic. |
| T1132.001 Standard Encoding |
MalwareOopsIE | OopsIE encodes data in hexadecimal format over the C2 channel. |
| T1132.001 Standard Encoding |
MalwareRogueRobin | RogueRobin base64 encodes strings that are sent to the C2 over its DNS tunnel. |
| T1132.001 Standard Encoding |
MalwareQUIETCANARY | QUIETCANARY can base64 encode C2 communications. |
| T1132.001 Standard Encoding |
MalwarePHPsert | PHPsert can use Base64-encoded values in C2 communications. |
| T1132.001 Standard Encoding |
MalwareStrelaStealer | StrelaStealer utilizes a hard-coded XOR key to encrypt the content of HTTP POST requests to command and control infrastructure. |
| T1132.001 Standard Encoding |
MalwarePULSECHECK | PULSECHECK can base-64 encode encrypted data sent through C2. |
| T1132.001 Standard Encoding |
MalwareKapeka | Kapeka utilizes JSON objects to send and receive information from command and control nodes. |
| T1132.001 Standard Encoding |
MalwareZebrocy | Zebrocy has used URL/Percent Encoding on data exfiltrated via HTTP POST requests. |
| T1132.001 Standard Encoding |
MalwareSpeakUp | SpeakUp encodes C&C communication using Base64. |
| T1132.001 Standard Encoding |
MalwareWARPWIRE | WARPWIRE can Base64 encode captured credentials with `btoa()` prior to sending to C2. |
| T1132.001 Standard Encoding |
MalwareCobalt Strike | Cobalt Strike can use Base64, URL-safe Base64, or NetBIOS encoding in its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareSUNBURST | SUNBURST used Base64 encoding in its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareCobian RAT | Cobian RAT obfuscates communications with the C2 server using Base64 encoding. |
| T1132.001 Standard Encoding |
MalwareValak | Valak has returned C2 data as encoded ASCII. |
| T1132.001 Standard Encoding |
MalwareSamurai | Samurai can base64 encode data sent in C2 communications prior to its encryption. |
| T1132.001 Standard Encoding |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used `zlib` to compress all data after 0x52 for the custom TCP C2 protocol. |
| T1132.001 Standard Encoding |
MalwareDaserf | Daserf uses custom base64 encoding to obfuscate HTTP traffic. |
| T1132.001 Standard Encoding |
MalwareSolar | Solar can Base64-encode and gzip compress C2 communications including command outputs. |
| T1132.001 Standard Encoding |
MalwarePisloader | Responses from the Pisloader C2 server are base32-encoded. |
| T1132.001 Standard Encoding |
MalwareRamsay | Ramsay has used base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareRevenge RAT | Revenge RAT uses Base64 to encode information sent to the C2 server. |
| T1132.001 Standard Encoding |
MalwareMore_eggs | More_eggs has used basE91 encoding, along with encryption, for C2 communication. |
| T1132.001 Standard Encoding |
MalwareSysUpdate | SysUpdate has used Base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareMango | Mango can receive Base64-encoded commands from C2. |
| T1132.001 Standard Encoding |
MalwareWIREFIRE | WIREFIRE can Base64 encode process output sent to C2. |
| T1132.001 Standard Encoding |
MalwareKessel | Kessel has exfiltrated data via hexadecimal-encoded subdomain fields of DNS queries. |
| T1132.001 Standard Encoding |
MalwareGrimAgent | GrimAgent can base64 encode C2 replies. |
| T1132.001 Standard Encoding |
MalwareSTEADYPULSE | STEADYPULSE can transmit URL encoded data over C2. |
| T1132.001 Standard Encoding |
MalwareSLIGHTPULSE | SLIGHTPULSE can base64 encode all incoming and outgoing C2 messages. |
| T1132.001 Standard Encoding |
MalwareBabyShark | BabyShark has encoded data using certutil before exfiltration. |
| T1132.001 Standard Encoding |
MalwareCreepySnail | CreepySnail can use Base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareTroll Stealer | Troll Stealer performs XOR encryption and Base64 encoding of data prior to sending to command and control infrastructure. |
| T1132.001 Standard Encoding |
MalwareEbury | Ebury has encoded C2 traffic in hexadecimal format. |
| T1132.001 Standard Encoding |
MalwarenjRAT | njRAT uses Base64 encoding for C2 traffic. |
| T1132.001 Standard Encoding |
MalwareChChes | ChChes can encode C2 data with a custom technique that utilizes Base64. |
| T1132.001 Standard Encoding |
MalwareManjusaka | Manjusaka communication includes a client-created session cookie with base64-encoded information representing information from the victim system. |
| T1132.001 Standard Encoding |
MalwareSideTwist | SideTwist has used Base64 for encoded C2 traffic. |
| T1132.001 Standard Encoding |
MalwareMechaFlounder | MechaFlounder has the ability to use base16 encoded strings in C2. |
| T1132.001 Standard Encoding |
MalwareMis-Type | Mis-Type uses Base64 encoding for C2 traffic. |
| T1132.001 Standard Encoding |
MalwareLunarWeb | LunarWeb can use Base64 encoding to obfuscate C2 commands. |
| T1132.001 Standard Encoding |
MalwareDipsind | Dipsind encodes C2 traffic with base64. |
| T1132.001 Standard Encoding |
MalwareOctopus | Octopus has encoded C2 communications in Base64. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.