Real-world descriptions of how a group, tool or campaign used a technique.
167 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.001 Symmetric Cryptography |
MalwareUBoatRAT | UBoatRAT encrypts instructions in its C2 network payloads using a simple XOR cipher. |
| T1573.001 Symmetric Cryptography |
MalwareHTTPTroy | HTTPTroy has obfuscated request communications utilizing XOR encryption. |
| T1573.001 Symmetric Cryptography |
MalwareNETEAGLE | NETEAGLE will decrypt resources it downloads with HTTP requests by using RC4 with the key "ScoutEagle." |
| T1573.001 Symmetric Cryptography |
MalwareFatDuke | FatDuke can AES encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareLucifer | Lucifer can perform a decremental-xor encryption on the initial C2 request before sending it over the wire. |
| T1573.001 Symmetric Cryptography |
MalwareHi-Zor | Hi-Zor encrypts C2 traffic with a double XOR using two distinct single-byte keys. |
| T1573.001 Symmetric Cryptography |
MalwareChaos | Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES. |
| T1573.001 Symmetric Cryptography |
MalwareLIGHTWIRE | LIGHTWIRE can RC4 encrypt C2 commands. |
| T1573.001 Symmetric Cryptography |
MalwareCORESHELL | CORESHELL C2 messages are encrypted with custom stream ciphers using six-byte or eight-byte keys. |
| T1573.001 Symmetric Cryptography |
MalwareBBSRAT | BBSRAT uses a custom encryption algorithm on data sent back to the C2 server over HTTP. |
| T1573.001 Symmetric Cryptography |
MalwarePlugX | PlugX can use RC4 encryption in C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareBisonal | Bisonal variants reported on in 2014 and 2015 used a simple XOR cipher for C2. Some Bisonal samples encrypt C2 communications with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareSeaDuke | SeaDuke C2 traffic has been encrypted with RC4 and AES. |
| T1573.001 Symmetric Cryptography |
MalwareExplosive | Explosive has encrypted communications with the RC4 method. |
| T1573.001 Symmetric Cryptography |
MalwareEpic | Epic encrypts commands from the C2 server using a hardcoded key. |
| T1573.001 Symmetric Cryptography |
MalwareLightNeuron | LightNeuron uses AES to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwarePureCrypter | PureCrypter can use AES to encrypt system information sent to the C2. |
| T1573.001 Symmetric Cryptography |
MalwareMongall | Mongall has the ability to RC4 encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareLockBit 3.0 | LockBit 3.0 can encrypt C2 communications with AES. |
| T1573.001 Symmetric Cryptography |
MalwareFoggyWeb | FoggyWeb has used a dynamic XOR key and custom XOR methodology for C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareNGLite | NGLite will use an AES encrypted channel for command and control purposes, in one case using the key |
| T1573.001 Symmetric Cryptography |
MalwareCarbanak | Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode). Carbanak also uses XOR with random keys for its communications. |
| T1573.001 Symmetric Cryptography |
MalwareHydraq | Hydraq C2 traffic is encrypted using bitwise NOT and XOR operations. |
| T1573.001 Symmetric Cryptography |
MalwareElise | Elise encrypts exfiltrated data with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareGazer | Gazer uses custom encryption for C2 that uses 3DES. |
| T1573.001 Symmetric Cryptography |
MalwareTSCookie | TSCookie has encrypted network communications with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareLatrodectus | Latrodectus can send RC4 encrypted data over C2 channels. |
| T1573.001 Symmetric Cryptography |
MalwareLODEINFO | LODEINFO can encrypt C2 communication with a hardcoded (NV4HDOeOVyL) Vigenere cipher key. |
| T1573.001 Symmetric Cryptography |
MalwareCharmPower | CharmPower can send additional modules over C2 encrypted with a simple substitution cipher. |
| T1573.001 Symmetric Cryptography |
MalwareMuddyViper | MuddyViper has the ability to encrypt C2 communication using AES-CBC using the CNG API, the key `0608101047106453101617106423101013101012101083109710108585106969`, and the initialization vector `0`. |
| T1573.001 Symmetric Cryptography |
Malware3PARA RAT | 3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode with a key derived from the MD5 hash of the string HYF54&%9&jkMCXuiS. 3PARA RAT will use an 8-byte XOR key derived from the string HYF54&%9&jkMCXuiS if the DES decoding fails |
| T1573.001 Symmetric Cryptography |
MalwareVIRTUALPIE | VIRTUALPIE can use a custom RC4 encrypted protocol for C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareSMOKEDHAM | SMOKEDHAM has encrypted its C2 traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE uses a Linear Feedback Shift Register (LFSR) algorithm for network encryption. |
| T1573.001 Symmetric Cryptography |
MalwareSys10 | Sys10 uses an XOR 0x1 loop to encrypt its C2 domain. |
| T1573.001 Symmetric Cryptography |
MalwareBendyBear | BendyBear communicates to a C2 server over port 443 using modified RC4 and XOR-encrypted chunks. |
| T1573.001 Symmetric Cryptography |
MalwareUroburos | Uroburos can encrypt the data beneath its http2 or tcp encryption at the session layer with CAST-128, using a different key for incoming and outgoing data. |
| T1573.001 Symmetric Cryptography |
MalwareMetamorfo | Metamorfo has encrypted C2 commands with AES-256. |
| T1573.001 Symmetric Cryptography |
MalwareBandook | Bandook has used AES encryption for C2 communication. |
| T1573.001 Symmetric Cryptography |
MalwarePipeMon | PipeMon communications are RC4 encrypted. |
| T1573.001 Symmetric Cryptography |
MalwareKONNI | KONNI has used AES to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareWinnti for Linux | Winnti for Linux has used a custom TCP protocol with four-byte XOR for command and control (C2). |
| T1573.001 Symmetric Cryptography |
Malwaregh0st RAT | gh0st RAT uses RC4 and XOR to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
Malwaredown_new | down_new has the ability to AES encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
Malware4H RAT | 4H RAT obfuscates C2 communication using a 1-byte XOR with the key 0xBE. |
| T1573.001 Symmetric Cryptography |
MalwareAttor | Attor has encrypted data symmetrically using a randomly generated Blowfish (OFB) key which is encrypted with a public RSA key. |
| T1573.001 Symmetric Cryptography |
MalwareMosquito | Mosquito uses a custom encryption algorithm, which consists of XOR and a stream that is similar to the Blum Blum Shub algorithm. |
| T1573.001 Symmetric Cryptography |
MalwareRTM | RTM encrypts C2 traffic with a custom RC4 variant. |
| T1573.001 Symmetric Cryptography |
MalwareQUIETCANARY | QUIETCANARY can RC4 encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareDerusbi | Derusbi obfuscates C2 traffic with variable 4-byte XOR keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.