Real-world descriptions of how a group, tool or campaign used a technique.
80 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.002 Asymmetric Cryptography |
MalwareServHelper | ServHelper may set up a reverse SSH tunnel to give the attacker access to services running on the victim, such as RDP. |
| T1573.002 Asymmetric Cryptography |
MalwareREvil | REvil has encrypted C2 communications with the ECIES algorithm. |
| T1573.002 Asymmetric Cryptography |
MalwareOilBooster | OilBooster can use the OpenSSL library to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareCyclops Blink | Cyclops Blink can encrypt C2 messages with AES-256-CBC sent underneath TLS. OpenSSL library functions are also used to encrypt each message using a randomly generated key and IV, which are then encrypted using a hard-coded RSA public key. |
| T1573.002 Asymmetric Cryptography |
MalwareCarbon | Carbon has used RSA encryption for C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareBISCUIT | BISCUIT uses SSL for encrypting C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareLAMEHUG | LAMEHUG can use SSH to transfer information to C2. |
| T1573.002 Asymmetric Cryptography |
MalwareMango | Mango can use TLS to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareGrimAgent | GrimAgent can use a hardcoded server public RSA key to encrypt the first request to C2. |
| T1573.002 Asymmetric Cryptography |
MalwarePoetRAT | PoetRAT used TLS to encrypt command and control (C2) communications. |
| T1573.002 Asymmetric Cryptography |
MalwareCHOPSTICK | CHOPSTICK encrypts C2 communications with TLS. |
| T1573.002 Asymmetric Cryptography |
MalwarePenquin | Penquin can encrypt communications using the BlowFish algorithm and a symmetric key exchanged with Diffie Hellman. |
| T1573.002 Asymmetric Cryptography |
MalwarePITSTOP | PITSTOP has the ability to communicate over TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareComRAT | ComRAT can use SSL/TLS encryption for its HTTP-based C2 channel. ComRAT has used public key cryptography with RSA and AES encrypted email attachments for its Gmail C2 channel. |
| T1573.002 Asymmetric Cryptography |
MalwareLunarWeb | LunarWeb can send short C2 commands, up to 512 bytes, encrypted with RSA-4096. |
| T1573.002 Asymmetric Cryptography |
MalwarePOWERSTATS | POWERSTATS has encrypted C2 traffic with RSA. |
| T1573.002 Asymmetric Cryptography |
MalwareDridex | Dridex has encrypted traffic with RSA. |
| T1573.002 Asymmetric Cryptography |
MalwareADVSTORESHELL | A variant of ADVSTORESHELL encrypts some C2 with RSA. |
| T1573.002 Asymmetric Cryptography |
MalwareSmall Sieve | Small Sieve can use SSL/TLS for its HTTPS Telegram Bot API-based C2 channel. |
| T1573.002 Asymmetric Cryptography |
ToolCovenant | Covenant can utilize SSL to encrypt command and control traffic. |
| T1573.002 Asymmetric Cryptography |
ToolSliver | Sliver can use mutual TLS and RSA cryptography to exchange a session key. |
| T1573.002 Asymmetric Cryptography |
ToolDCRAT | DCRAT can use certificate-based authentication for C2 servers. |
| T1573.002 Asymmetric Cryptography |
ToolEmpire | Empire can use TLS to encrypt its C2 channel. |
| T1573.002 Asymmetric Cryptography |
ToolFRP | FRP can be configured to only accept TLS connections. |
| T1573.002 Asymmetric Cryptography |
ToolRemcos | Remcos can use TLS to encrypt C2 communication. |
| T1573.002 Asymmetric Cryptography |
ToolKoadic | Koadic can use SSL and TLS for communications. |
| T1573.002 Asymmetric Cryptography |
ToolPupy | Pupy's default encryption for its C2 communication channel is SSL, but it also has transport options for RSA and AES. |
| T1573.002 Asymmetric Cryptography |
ToolMythic | Mythic supports SSL encrypted C2. |
| T1573.002 Asymmetric Cryptography |
ToolTor | Tor encapsulates traffic in multiple layers of encryption, using TLS by default. |
| T1573.002 Asymmetric Cryptography |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has encrypted collected data using a hybrid RSA-4096 and AES-256-encryption prior to exfiltration over 'curl`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.