Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560.001 Archive via Utility |
MalwareIceApple | IceApple can encrypt and compress files using Gzip prior to exfiltration. |
| T1560.001 Archive via Utility |
MalwareLunarWeb | LunarWeb can create a ZIP archive with specified files and directories. |
| T1560.001 Archive via Utility |
MalwareOctopus | Octopus has compressed data before exfiltrating it using a tool called Abbrevia. |
| T1560.001 Archive via Utility |
Toolcertutil | certutil may be used to Base64 encode collected data. |
| T1560.001 Archive via Utility |
ToolPoshC2 | PoshC2 contains a module for compressing data using ZIP. |
| T1560.001 Archive via Utility |
ToolRclone | Rclone can compress files using `gzip` prior to exfiltration. |
| T1560.001 Archive via Utility |
ToolRemcos | Remcos can zip files and folders for upload. |
| T1560.001 Archive via Utility |
ToolPupy | Pupy can compress data with Zip before sending it over C2. |
| T1560.001 Archive via Utility |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has bundled collected data into a file named tpcp.tar.gz for exfiltration. |
| T1560.001 Archive via Utility |
MalwareMini Shai-Hulud | Mini Shai-Hulud has compressed collected credentials and data within tar archive files prior to exfiltration. |
| T1560.002 Archive via Library |
MalwareZLib | The ZLib backdoor compresses communications using the standard Zlib compression library. |
| T1560.002 Archive via Library |
MalwareInvisiMole | InvisiMole can use zlib to compress and decompress data. |
| T1560.002 Archive via Library |
MalwareBBSRAT | BBSRAT can compress data with ZLIB prior to sending it back to the C2 server. |
| T1560.002 Archive via Library |
MalwareSeaDuke | SeaDuke compressed data with zlib prior to sending it over C2. |
| T1560.002 Archive via Library |
MalwareEpic | Epic compresses the collected data with bzip2 before sending it to the C2 server. |
| T1560.002 Archive via Library |
MalwareFoggyWeb | FoggyWeb can invoke the `Common.Compress` method to compress data with the C# GZipStream compression class. |
| T1560.002 Archive via Library |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D scrambles and encrypts data using AES256 before sending it to the C2 server. |
| T1560.002 Archive via Library |
MalwareTajMahal | TajMahal has the ability to use the open source libraries XZip/Xunzip and zlib to compress files. |
| T1560.002 Archive via Library |
MalwareCardinal RAT | Cardinal RAT applies compression to C2 traffic using the ZLIB library. |
| T1560.002 Archive via Library |
MalwareFunnyDream | FunnyDream has compressed collected files with zLib. |
| T1560.002 Archive via Library |
MalwareLunarWeb | LunarWeb can zlib-compress data prior to exfiltration. |
| T1560.002 Archive via Library |
MalwareDenis | Denis compressed collected data using zlib. |
| T1560.002 Archive via Library |
MalwareBADFLICK | BADFLICK has compressed data using the aPLib compression library. |
| T1560.003 Archive via Custom Method |
MalwareStuxnet | Stuxnet encrypts exfiltrated data via C2 with static 31-byte long XOR keys. |
| T1560.003 Archive via Custom Method |
MalwareHAWKBALL | HAWKBALL has encrypted data with XOR before sending it over the C2 channel. |
| T1560.003 Archive via Custom Method |
MalwareFrameworkPOS | FrameworkPOS can XOR credit card information before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareStrongPity | StrongPity can compress and encrypt archived files into multiple .sft files with a repeated xor encryption scheme. |
| T1560.003 Archive via Custom Method |
MalwareNETWIRE | NETWIRE has used a custom encryption algorithm to encrypt collected data. |
| T1560.003 Archive via Custom Method |
MalwareMachete | Machete's collected data is encrypted with AES before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareSquirrelwaffle | Squirrelwaffle has encrypted collected data using a XOR-based algorithm. |
| T1560.003 Archive via Custom Method |
MalwareAgent.btz | Agent.btz saves system information into an XML file that is then XOR-encoded. |
| T1560.003 Archive via Custom Method |
MalwareSombRAT | SombRAT has encrypted collected data with AES-256 using a hardcoded key. |
| T1560.003 Archive via Custom Method |
MalwareFLASHFLOOD | FLASHFLOOD employs the same encoding scheme as SPACESHIP for data it stages. Data is compressed with zlib, and bytes are rotated four times before being XOR'ed with 0x23. |
| T1560.003 Archive via Custom Method |
MalwareInvisiMole | InvisiMole uses a variation of the XOR cipher to encrypt files before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareOkrum | Okrum has used a custom implementation of AES encryption to encrypt collected data. |
| T1560.003 Archive via Custom Method |
MalwareRising Sun | Rising Sun can archive data using RC4 encryption and Base64 encoding prior to exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareReaver | Reaver encrypts collected data with an incremental XOR key prior to exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareFoggyWeb | FoggyWeb can use a dynamic XOR key and a custom XOR methodology to encode data before exfiltration. Also, FoggyWeb can encode C2 command output within a legitimate WebP file. |
| T1560.003 Archive via Custom Method |
MalwareT9000 | T9000 encrypts collected data using a single byte XOR key. |
| T1560.003 Archive via Custom Method |
MalwareSPACESHIP | Data SPACESHIP copies to the staging area is compressed with zlib. Bytes are rotated by four positions and XOR'ed with 0x23. |
| T1560.003 Archive via Custom Method |
MalwareBLUELIGHT | BLUELIGHT has encoded data into a binary blob using XOR. |
| T1560.003 Archive via Custom Method |
MalwareOopsIE | OopsIE compresses collected files with a simple character replacement scheme before sending them to its C2 server. |
| T1560.003 Archive via Custom Method |
MalwareAttor | Attor encrypts collected data with a custom implementation of Blowfish and RSA ciphers. |
| T1560.003 Archive via Custom Method |
MalwareRawPOS | RawPOS encodes credit card data it collected from the victim with XOR. |
| T1560.003 Archive via Custom Method |
MalwareMESSAGETAP | MESSAGETAP has XOR-encrypted and stored contents of SMS messages that matched its target list. |
| T1560.003 Archive via Custom Method |
MalwareSUGARDUMP | SUGARDUMP has encrypted collected data using AES CBC mode and encoded it using Base64. |
| T1560.003 Archive via Custom Method |
MalwareOwaAuth | OwaAuth DES-encrypts captured credentials using the key 12345678 before writing the credentials to a log file. |
| T1560.003 Archive via Custom Method |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used AES in CBC mode to encrypt collected data when saving that data to disk. |
| T1560.003 Archive via Custom Method |
MalwareRGDoor | RGDoor encrypts files with XOR before sending them back to the C2 server. |
| T1560.003 Archive via Custom Method |
MalwareRamsay | Ramsay can store collected documents in a custom container after encrypting and compressing them using RC4 and WinRAR. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.