ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1132.001×

114 examples

TechniqueUsed byProcedure example
T1132.001
Standard Encoding
MalwareQUADAGENT

QUADAGENT encodes C2 communications with base64.

T1132.001
Standard Encoding
MalwareKONNI

KONNI has used a custom base64 key to encode stolen data before exfiltration.

T1132.001
Standard Encoding
Malwaregh0st RAT

gh0st RAT has used Zlib to compress C2 communications data before encrypting it.

T1132.001
Standard Encoding
MalwareDnsSystem

DnsSystem can Base64 encode data sent to C2.

T1132.001
Standard Encoding
MalwareJHUHUGIT

A JHUHUGIT variant encodes C2 POST data base64.

T1132.001
Standard Encoding
Malwaredown_new

down_new has the ability to base64 encode C2 communications.

T1132.001
Standard Encoding
MalwareIxeshe

Ixeshe uses custom Base64 encoding schemes to obfuscate command and control traffic in the message body of HTTP requests.

T1132.001
Standard Encoding
MalwareRedLine Stealer

RedLine Stealer has used Base64 to encode command and control traffic.

T1132.001
Standard Encoding
MalwareOopsIE

OopsIE encodes data in hexadecimal format over the C2 channel.

T1132.001
Standard Encoding
MalwareRogueRobin

RogueRobin base64 encodes strings that are sent to the C2 over its DNS tunnel.

T1132.001
Standard Encoding
MalwareQUIETCANARY

QUIETCANARY can base64 encode C2 communications.

T1132.001
Standard Encoding
MalwarePHPsert

PHPsert can use Base64-encoded values in C2 communications.

T1132.001
Standard Encoding
MalwareStrelaStealer

StrelaStealer utilizes a hard-coded XOR key to encrypt the content of HTTP POST requests to command and control infrastructure.

T1132.001
Standard Encoding
MalwarePULSECHECK

PULSECHECK can base-64 encode encrypted data sent through C2.

T1132.001
Standard Encoding
MalwareKapeka

Kapeka utilizes JSON objects to send and receive information from command and control nodes.

T1132.001
Standard Encoding
MalwareZebrocy

Zebrocy has used URL/Percent Encoding on data exfiltrated via HTTP POST requests.

T1132.001
Standard Encoding
MalwareSpeakUp

SpeakUp encodes C&C communication using Base64.

T1132.001
Standard Encoding
MalwareWARPWIRE

WARPWIRE can Base64 encode captured credentials with `btoa()` prior to sending to C2.

T1132.001
Standard Encoding
MalwareCobalt Strike

Cobalt Strike can use Base64, URL-safe Base64, or NetBIOS encoding in its C2 traffic.

T1132.001
Standard Encoding
MalwareSUNBURST

SUNBURST used Base64 encoding in its C2 traffic.

T1132.001
Standard Encoding
MalwareCobian RAT

Cobian RAT obfuscates communications with the C2 server using Base64 encoding.

T1132.001
Standard Encoding
MalwareValak

Valak has returned C2 data as encoded ASCII.

T1132.001
Standard Encoding
MalwareSamurai

Samurai can base64 encode data sent in C2 communications prior to its encryption.

T1132.001
Standard Encoding
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used `zlib` to compress all data after 0x52 for the custom TCP C2 protocol.

T1132.001
Standard Encoding
MalwareDaserf

Daserf uses custom base64 encoding to obfuscate HTTP traffic.

T1132.001
Standard Encoding
MalwareSolar

Solar can Base64-encode and gzip compress C2 communications including command outputs.

T1132.001
Standard Encoding
MalwarePisloader

Responses from the Pisloader C2 server are base32-encoded.

T1132.001
Standard Encoding
MalwareRamsay

Ramsay has used base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwareRevenge RAT

Revenge RAT uses Base64 to encode information sent to the C2 server.

T1132.001
Standard Encoding
MalwareMore_eggs

More_eggs has used basE91 encoding, along with encryption, for C2 communication.

T1132.001
Standard Encoding
MalwareSysUpdate

SysUpdate has used Base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwareMango

Mango can receive Base64-encoded commands from C2.

T1132.001
Standard Encoding
MalwareWIREFIRE

WIREFIRE can Base64 encode process output sent to C2.

T1132.001
Standard Encoding
MalwareKessel

Kessel has exfiltrated data via hexadecimal-encoded subdomain fields of DNS queries.

T1132.001
Standard Encoding
MalwareGrimAgent

GrimAgent can base64 encode C2 replies.

T1132.001
Standard Encoding
MalwareSTEADYPULSE

STEADYPULSE can transmit URL encoded data over C2.

T1132.001
Standard Encoding
MalwareSLIGHTPULSE

SLIGHTPULSE can base64 encode all incoming and outgoing C2 messages.

T1132.001
Standard Encoding
MalwareBabyShark

BabyShark has encoded data using certutil before exfiltration.

T1132.001
Standard Encoding
MalwareCreepySnail

CreepySnail can use Base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwareTroll Stealer

Troll Stealer performs XOR encryption and Base64 encoding of data prior to sending to command and control infrastructure.

T1132.001
Standard Encoding
MalwareEbury

Ebury has encoded C2 traffic in hexadecimal format.

T1132.001
Standard Encoding
MalwarenjRAT

njRAT uses Base64 encoding for C2 traffic.

T1132.001
Standard Encoding
MalwareChChes

ChChes can encode C2 data with a custom technique that utilizes Base64.

T1132.001
Standard Encoding
MalwareManjusaka

Manjusaka communication includes a client-created session cookie with base64-encoded information representing information from the victim system.

T1132.001
Standard Encoding
MalwareSideTwist

SideTwist has used Base64 for encoded C2 traffic.

T1132.001
Standard Encoding
MalwareMechaFlounder

MechaFlounder has the ability to use base16 encoded strings in C2.

T1132.001
Standard Encoding
MalwareMis-Type

Mis-Type uses Base64 encoding for C2 traffic.

T1132.001
Standard Encoding
MalwareLunarWeb

LunarWeb can use Base64 encoding to obfuscate C2 commands.

T1132.001
Standard Encoding
MalwareDipsind

Dipsind encodes C2 traffic with base64.

T1132.001
Standard Encoding
MalwareOctopus

Octopus has encoded C2 communications in Base64.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.