ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1132
Data Encoding
MalwareLinux Rabbit

Linux Rabbit sends the payload from the C2 server as an encoded URL parameter.

T1132
Data Encoding
MalwareUrsnif

Ursnif has used encoded data in HTTP URLs for C2.

T1132
Data Encoding
MalwareLAMEHUG

LAMEHUG can encode queries sent to LLMs.

T1132
Data Encoding
MalwareBADNEWS

After encrypting C2 data, BADNEWS converts it into a hexadecimal representation and then encodes it into base64.

T1132
Data Encoding
MalwareH1N1

H1N1 obfuscates C2 traffic with an altered version of base64.

T1132
Data Encoding
Toolevilginx2

evilginx2 can randomly generate and Base64 encode parameters in phishing links to defeat static detection.

T1132
Data Encoding
ToolMythic

Mythic provides various transform functions to encode and/or randomize C2 data.

T1132.001
Standard Encoding
CampaignJuicy Mix

During Juicy Mix, OilRig used a VBS script to send the Base64-encoded name of the compromised computer to C2.

T1132.001
Standard Encoding
GroupPatchwork

Patchwork used Base64 to encode C2 traffic.

T1132.001
Standard Encoding
GroupHAFNIUM

HAFNIUM has used ASCII encoding for C2 traffic.

T1132.001
Standard Encoding
GroupMuddyWater

MuddyWater has used tools to encode C2 communications including Base64 encoding.

T1132.001
Standard Encoding
GroupSandworm Team

Sandworm Team's BCS-server tool uses base64 encoding and HTML tags for the communication traffic between the C2 server.

T1132.001
Standard Encoding
GroupTropic Trooper

Tropic Trooper has used base64 encoding to hide command strings delivered from the C2.

T1132.001
Standard Encoding
GroupBRONZE BUTLER

Several BRONZE BUTLER tools encode data with base64 when posting it to a C2 server.

T1132.001
Standard Encoding
GroupTA551

TA551 has used encoded ASCII text for initial C2 communications.

T1132.001
Standard Encoding
GroupAPT42

APT42 has encoded C2 traffic with Base64.

T1132.001
Standard Encoding
GroupLazarus Group

A Lazarus Group malware sample encodes data with base64.

T1132.001
Standard Encoding
GroupAPT33

APT33 has used base64 to encode command and control traffic.

T1132.001
Standard Encoding
GroupAPT19

An APT19 HTTP malware variant used Base64 to encode communications to the C2 server.

T1132.001
Standard Encoding
MalwareTrickBot

TrickBot can Base64-encode C2 commands.

T1132.001
Standard Encoding
MalwareBLINDINGCAN

BLINDINGCAN has encoded its C2 traffic with Base64.

T1132.001
Standard Encoding
MalwarePikabot

Pikabot uses base64 encoding in conjunction with symmetric encryption mechanisms to obfuscate command and control communications.

T1132.001
Standard Encoding
MalwareSpark

Spark has encoded communications with the C2 server with base64.

T1132.001
Standard Encoding
MalwareBumblebee

Bumblebee has the ability to base64 encode C2 server responses.

T1132.001
Standard Encoding
MalwareBRICKSTORM

BRICKSTORM has leveraged Base64 to encode C2 communications.

T1132.001
Standard Encoding
MalwareTorisma

Torisma has encoded C2 communications with Base64.

T1132.001
Standard Encoding
MalwareBackdoor.Oldrea

Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers.

T1132.001
Standard Encoding
MalwareStuxnet

Stuxnet transforms encrypted binary data into an ASCII string in order to use it as a URL parameter value.

T1132.001
Standard Encoding
MalwareRotaJakiro

RotaJakiro uses ZLIB Compression to compresses data sent to the C2 server in the `payload` section network communication packet.

T1132.001
Standard Encoding
MalwarePOWRUNER

POWRUNER can use base64 encoded C2 communications.

T1132.001
Standard Encoding
MalwareSardonic

Sardonic can encode client ID data in 32 uppercase hex characters and transfer to the actor-controlled C2 server.

T1132.001
Standard Encoding
MalwareMisdat

Misdat network traffic is Base64-encoded plaintext.

T1132.001
Standard Encoding
MalwareTAMECAT

TAMECAT has encoded C2 traffic with Base64.

T1132.001
Standard Encoding
MalwareFelismus

Some Felismus samples use a custom method for C2 traffic that utilizes Base64.

T1132.001
Standard Encoding
MalwarexCaon

xCaon has used Base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwareGomir

Gomir uses Base64-encoded content in HTTP communications to command and control infrastructure.

T1132.001
Standard Encoding
MalwareEmotet

Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Additionally, Emotet has used Base64 to encode data before sending to the C2 server.

T1132.001
Standard Encoding
MalwareMachete

Machete has used base64 encoding.

T1132.001
Standard Encoding
MalwarePrikormka

Prikormka encodes C2 traffic with Base64.

T1132.001
Standard Encoding
MalwareGootloader

Gootloader can retrieve a Base64 encoded stager from C2.

T1132.001
Standard Encoding
MalwarePingPull

PingPull can encode C2 traffic with Base64.

T1132.001
Standard Encoding
MalwareWellMess

WellMess has used Base64 encoding to uniquely identify communication to and from the C2.

T1132.001
Standard Encoding
MalwareMafalda

Mafalda can encode data using Base64 prior to exfiltration.

T1132.001
Standard Encoding
MalwareSquirrelwaffle

Squirrelwaffle has encoded its communications to C2 servers using Base64.

T1132.001
Standard Encoding
MalwareHOPLIGHT

HOPLIGHT has utilized Zlib compression to obfuscate the communications payload.

T1132.001
Standard Encoding
MalwareRDAT

RDAT can communicate with the C2 via base32-encoded subdomains.

T1132.001
Standard Encoding
MalwareOkrum

Okrum has used base64 to encode C2 communication.

T1132.001
Standard Encoding
MalwareRustyWater

RustyWater has encoded collected data with Base64.

T1132.001
Standard Encoding
MalwareFysbis

Fysbis can use Base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwarePowerShower

PowerShower has the ability to encode C2 communications with base64 encoding.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.