ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1573.001×

167 examples

TechniqueUsed byProcedure example
T1573.001
Symmetric Cryptography
MalwareUBoatRAT

UBoatRAT encrypts instructions in its C2 network payloads using a simple XOR cipher.

T1573.001
Symmetric Cryptography
MalwareHTTPTroy

HTTPTroy has obfuscated request communications utilizing XOR encryption.

T1573.001
Symmetric Cryptography
MalwareNETEAGLE

NETEAGLE will decrypt resources it downloads with HTTP requests by using RC4 with the key "ScoutEagle."

T1573.001
Symmetric Cryptography
MalwareFatDuke

FatDuke can AES encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareLucifer

Lucifer can perform a decremental-xor encryption on the initial C2 request before sending it over the wire.

T1573.001
Symmetric Cryptography
MalwareHi-Zor

Hi-Zor encrypts C2 traffic with a double XOR using two distinct single-byte keys.

T1573.001
Symmetric Cryptography
MalwareChaos

Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES.

T1573.001
Symmetric Cryptography
MalwareLIGHTWIRE

LIGHTWIRE can RC4 encrypt C2 commands.

T1573.001
Symmetric Cryptography
MalwareCORESHELL

CORESHELL C2 messages are encrypted with custom stream ciphers using six-byte or eight-byte keys.

T1573.001
Symmetric Cryptography
MalwareBBSRAT

BBSRAT uses a custom encryption algorithm on data sent back to the C2 server over HTTP.

T1573.001
Symmetric Cryptography
MalwarePlugX

PlugX can use RC4 encryption in C2 communications.

T1573.001
Symmetric Cryptography
MalwareBisonal

Bisonal variants reported on in 2014 and 2015 used a simple XOR cipher for C2. Some Bisonal samples encrypt C2 communications with RC4.

T1573.001
Symmetric Cryptography
MalwareSeaDuke

SeaDuke C2 traffic has been encrypted with RC4 and AES.

T1573.001
Symmetric Cryptography
MalwareExplosive

Explosive has encrypted communications with the RC4 method.

T1573.001
Symmetric Cryptography
MalwareEpic

Epic encrypts commands from the C2 server using a hardcoded key.

T1573.001
Symmetric Cryptography
MalwareLightNeuron

LightNeuron uses AES to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwarePureCrypter

PureCrypter can use AES to encrypt system information sent to the C2.

T1573.001
Symmetric Cryptography
MalwareMongall

Mongall has the ability to RC4 encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareLockBit 3.0

LockBit 3.0 can encrypt C2 communications with AES.

T1573.001
Symmetric Cryptography
MalwareFoggyWeb

FoggyWeb has used a dynamic XOR key and custom XOR methodology for C2 communications.

T1573.001
Symmetric Cryptography
MalwareNGLite

NGLite will use an AES encrypted channel for command and control purposes, in one case using the key WHATswrongwithUu.

T1573.001
Symmetric Cryptography
MalwareCarbanak

Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode). Carbanak also uses XOR with random keys for its communications.

T1573.001
Symmetric Cryptography
MalwareHydraq

Hydraq C2 traffic is encrypted using bitwise NOT and XOR operations.

T1573.001
Symmetric Cryptography
MalwareElise

Elise encrypts exfiltrated data with RC4.

T1573.001
Symmetric Cryptography
MalwareGazer

Gazer uses custom encryption for C2 that uses 3DES.

T1573.001
Symmetric Cryptography
MalwareTSCookie

TSCookie has encrypted network communications with RC4.

T1573.001
Symmetric Cryptography
MalwareLatrodectus

Latrodectus can send RC4 encrypted data over C2 channels.

T1573.001
Symmetric Cryptography
MalwareLODEINFO

LODEINFO can encrypt C2 communication with a hardcoded (NV4HDOeOVyL) Vigenere cipher key.

T1573.001
Symmetric Cryptography
MalwareCharmPower

CharmPower can send additional modules over C2 encrypted with a simple substitution cipher.

T1573.001
Symmetric Cryptography
MalwareMuddyViper

MuddyViper has the ability to encrypt C2 communication using AES-CBC using the CNG API, the key `0608101047106453101617106423101013101012101083109710108585106969`, and the initialization vector `0`.

T1573.001
Symmetric Cryptography
Malware3PARA RAT

3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode with a key derived from the MD5 hash of the string HYF54&%9&jkMCXuiS. 3PARA RAT will use an 8-byte XOR key derived from the string HYF54&%9&jkMCXuiS if the DES decoding fails

T1573.001
Symmetric Cryptography
MalwareVIRTUALPIE

VIRTUALPIE can use a custom RC4 encrypted protocol for C2 communications.

T1573.001
Symmetric Cryptography
MalwareSMOKEDHAM

SMOKEDHAM has encrypted its C2 traffic with RC4.

T1573.001
Symmetric Cryptography
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE uses a Linear Feedback Shift Register (LFSR) algorithm for network encryption.

T1573.001
Symmetric Cryptography
MalwareSys10

Sys10 uses an XOR 0x1 loop to encrypt its C2 domain.

T1573.001
Symmetric Cryptography
MalwareBendyBear

BendyBear communicates to a C2 server over port 443 using modified RC4 and XOR-encrypted chunks.

T1573.001
Symmetric Cryptography
MalwareUroburos

Uroburos can encrypt the data beneath its http2 or tcp encryption at the session layer with CAST-128, using a different key for incoming and outgoing data.

T1573.001
Symmetric Cryptography
MalwareMetamorfo

Metamorfo has encrypted C2 commands with AES-256.

T1573.001
Symmetric Cryptography
MalwareBandook

Bandook has used AES encryption for C2 communication.

T1573.001
Symmetric Cryptography
MalwarePipeMon

PipeMon communications are RC4 encrypted.

T1573.001
Symmetric Cryptography
MalwareKONNI

KONNI has used AES to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareWinnti for Linux

Winnti for Linux has used a custom TCP protocol with four-byte XOR for command and control (C2).

T1573.001
Symmetric Cryptography
Malwaregh0st RAT

gh0st RAT uses RC4 and XOR to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
Malwaredown_new

down_new has the ability to AES encrypt C2 communications.

T1573.001
Symmetric Cryptography
Malware4H RAT

4H RAT obfuscates C2 communication using a 1-byte XOR with the key 0xBE.

T1573.001
Symmetric Cryptography
MalwareAttor

Attor has encrypted data symmetrically using a randomly generated Blowfish (OFB) key which is encrypted with a public RSA key.

T1573.001
Symmetric Cryptography
MalwareMosquito

Mosquito uses a custom encryption algorithm, which consists of XOR and a stream that is similar to the Blum Blum Shub algorithm.

T1573.001
Symmetric Cryptography
MalwareRTM

RTM encrypts C2 traffic with a custom RC4 variant.

T1573.001
Symmetric Cryptography
MalwareQUIETCANARY

QUIETCANARY can RC4 encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareDerusbi

Derusbi obfuscates C2 traffic with variable 4-byte XOR keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.