ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1560
Archive Collected Data
MalwareSpica

Spica can archive collected documents for exfiltration.

T1560
Archive Collected Data
MalwareKONNI

KONNI has encrypted data and files prior to exfiltration.

T1560
Archive Collected Data
MalwareBLUELIGHT

BLUELIGHT can zip files before exfiltration.

T1560
Archive Collected Data
MalwareWellMail

WellMail can archive files on the compromised host.

T1560
Archive Collected Data
MalwareZebrocy

Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration.

T1560
Archive Collected Data
MalwareCadelspy

Cadelspy has the ability to compress stolen data into a .cab file.

T1560
Archive Collected Data
MalwareRaccoon Stealer

Raccoon Stealer archives collected system information in a text f ile, `System info.txt`, prior to exfiltration.

T1560
Archive Collected Data
MalwareDaserf

Daserf hides collected data in password-protected .rar archives.

T1560
Archive Collected Data
MalwareGold Dragon

Gold Dragon encrypts data using Base64 before being sent to the command and control server.

T1560
Archive Collected Data
MalwarePillowmint

Pillowmint has encrypted stolen credit card information with AES and further encoded it with Base64.

T1560
Archive Collected Data
MalwareProton

Proton zips up files before exfiltrating them.

T1560
Archive Collected Data
MalwareKessel

Kessel can RC4-encrypt credentials before sending to the C2.

T1560
Archive Collected Data
MalwareFELIXROOT

FELIXROOT encrypts collected data with AES and Base64 and then sends it to the C2 server.

T1560
Archive Collected Data
MalwareTroll Stealer

Troll Stealer compresses stolen data prior to exfiltration.

T1560
Archive Collected Data
MalwareXCSSET

XCSSET will compress entire ~/Desktop folders excluding all .git folders, but only if the total data size is under 200MB.

T1560
Archive Collected Data
MalwareAgent Tesla

Agent Tesla can encrypt data with 3DES before sending it over to a C2 server.

T1560
Archive Collected Data
MalwareRemexi

Remexi encrypts and adds all gathered browser data into files for upload to C2.

T1560
Archive Collected Data
MalwareLizar

Lizar has encrypted data before sending it to the server.

T1560
Archive Collected Data
MalwareDtrack

Dtrack packs collected data into a password protected archive.

T1560
Archive Collected Data
MalwareADVSTORESHELL

ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration.

T1560
Archive Collected Data
ToolBloodHound

BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk.

T1560
Archive Collected Data
ToolShimRatReporter

ShimRatReporter used LZ compression to compress initial reconnaissance reports before sending to the C2.

T1560
Archive Collected Data
ToolEmpire

Empire can ZIP directories on the target system.

T1560
Archive Collected Data
MalwareMini Shai-Hulud

Mini Shai-Hulud has compressed collected credentials to reduce transmission size and to make string content harder to detect in memory forensics captures.

T1560.001
Archive via Utility
MalwareWindTail

WindTail has the ability to use the macOS built-in zip utility to archive files.

T1560.001
Archive via Utility
MalwareInvisibleFerret

InvisibleFerret has used 7zip, RAR and zip files to archive collected data for exfiltration.

T1560.001
Archive via Utility
MalwareTONESHELL

TONESHELL used WinRAR rar.exe to archive files for exfiltration. TONESHELL has also utilized a unique 13-character password consisting of upper lower case and digits to protect RAR archives.

T1560.001
Archive via Utility
MalwareAppleSeed

AppleSeed can zip and encrypt data collected on a target system.

T1560.001
Archive via Utility
MalwareiKitten

iKitten will zip up the /Library/Keychains directory before exfiltrating it.

T1560.001
Archive via Utility
MalwareTurian

Turian can use WinRAR to create a password-protected archive for files of interest.

T1560.001
Archive via Utility
MalwarePUBLOAD

PUBLOAD has used utilities such as `WinRAR` to archive data prior to exfiltration.

T1560.001
Archive via Utility
MalwareInvisiMole

InvisiMole uses WinRAR to compress data that is intended to be exfiltrated.

T1560.001
Archive via Utility
MalwareOkrum

Okrum was seen using a RAR archiver tool to compress/decompress data.

T1560.001
Archive via Utility
MalwarePowerShower

PowerShower has used 7Zip to compress .txt, .pdf, .xls or .doc files prior to exfiltration.

T1560.001
Archive via Utility
MalwarePUNCHBUGGY

PUNCHBUGGY has Gzipped information and saved it to a random temp file before exfil.

T1560.001
Archive via Utility
MalwareBeaverTail

BeaverTail has collected and archived sensitive data in a zip file.

T1560.001
Archive via Utility
MalwareDustySky

DustySky can compress files via RAR while staging data to be exfiltrated.

T1560.001
Archive via Utility
MalwareSagerunex

Sagerunex has archived collected materials in RAR format.

T1560.001
Archive via Utility
MalwareGlassWorm

GlassWorm has archived collected files within a zip file prior to exfiltration to include `/tmp/out.zip`.

T1560.001
Archive via Utility
MalwareCORALDECK

CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated.

T1560.001
Archive via Utility
MalwareMicropsia

Micropsia creates a RAR archive based on collected files on the victim's machine.

T1560.001
Archive via Utility
MalwareOopsIE

OopsIE compresses collected files with GZipStream before sending them to its C2 server.

T1560.001
Archive via Utility
MalwareCrutch

Crutch has used the WinRAR utility to compress and encrypt stolen files.

T1560.001
Archive via Utility
Malwareccf32

ccf32 has used `xcopy \\<target_host>\c$\users\public\path.7z c:\users\public\bin\<target_host>.7z /H /Y` to archive collected files.

T1560.001
Archive via Utility
MalwareSampleCheck5000

SampleCheck5000 can gzip compress files uploaded to a shared mailbox used for C2 and exfiltration.

T1560.001
Archive via Utility
MalwareDaserf

Daserf hides collected data in password-protected .rar archives.

T1560.001
Archive via Utility
MalwareCalisto

Calisto uses the zip -r command to compress the data collected on the local system.

T1560.001
Archive via Utility
MalwareRamsay

Ramsay can compress and archive collected files using WinRAR.

T1560.001
Archive via Utility
MalwareLAMEHUG

LAMEHUG can xcopy for file collection on targeted systems.

T1560.001
Archive via Utility
MalwarePoetRAT

PoetRAT has the ability to compress files with zip.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.