Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1132 Data Encoding |
MalwareLinux Rabbit | Linux Rabbit sends the payload from the C2 server as an encoded URL parameter. |
| T1132 Data Encoding |
MalwareUrsnif | Ursnif has used encoded data in HTTP URLs for C2. |
| T1132 Data Encoding |
MalwareLAMEHUG | LAMEHUG can encode queries sent to LLMs. |
| T1132 Data Encoding |
MalwareBADNEWS | After encrypting C2 data, BADNEWS converts it into a hexadecimal representation and then encodes it into base64. |
| T1132 Data Encoding |
MalwareH1N1 | H1N1 obfuscates C2 traffic with an altered version of base64. |
| T1132 Data Encoding |
Toolevilginx2 | evilginx2 can randomly generate and Base64 encode parameters in phishing links to defeat static detection. |
| T1132 Data Encoding |
ToolMythic | Mythic provides various transform functions to encode and/or randomize C2 data. |
| T1132.001 Standard Encoding |
CampaignJuicy Mix | During Juicy Mix, OilRig used a VBS script to send the Base64-encoded name of the compromised computer to C2. |
| T1132.001 Standard Encoding |
GroupPatchwork | Patchwork used Base64 to encode C2 traffic. |
| T1132.001 Standard Encoding |
GroupHAFNIUM | HAFNIUM has used ASCII encoding for C2 traffic. |
| T1132.001 Standard Encoding |
GroupMuddyWater | MuddyWater has used tools to encode C2 communications including Base64 encoding. |
| T1132.001 Standard Encoding |
GroupSandworm Team | Sandworm Team's BCS-server tool uses base64 encoding and HTML tags for the communication traffic between the C2 server. |
| T1132.001 Standard Encoding |
GroupTropic Trooper | Tropic Trooper has used base64 encoding to hide command strings delivered from the C2. |
| T1132.001 Standard Encoding |
GroupBRONZE BUTLER | Several BRONZE BUTLER tools encode data with base64 when posting it to a C2 server. |
| T1132.001 Standard Encoding |
GroupTA551 | TA551 has used encoded ASCII text for initial C2 communications. |
| T1132.001 Standard Encoding |
GroupAPT42 | APT42 has encoded C2 traffic with Base64. |
| T1132.001 Standard Encoding |
GroupLazarus Group | A Lazarus Group malware sample encodes data with base64. |
| T1132.001 Standard Encoding |
GroupAPT33 | APT33 has used base64 to encode command and control traffic. |
| T1132.001 Standard Encoding |
GroupAPT19 | An APT19 HTTP malware variant used Base64 to encode communications to the C2 server. |
| T1132.001 Standard Encoding |
MalwareTrickBot | TrickBot can Base64-encode C2 commands. |
| T1132.001 Standard Encoding |
MalwareBLINDINGCAN | BLINDINGCAN has encoded its C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwarePikabot | Pikabot uses base64 encoding in conjunction with symmetric encryption mechanisms to obfuscate command and control communications. |
| T1132.001 Standard Encoding |
MalwareSpark | Spark has encoded communications with the C2 server with base64. |
| T1132.001 Standard Encoding |
MalwareBumblebee | Bumblebee has the ability to base64 encode C2 server responses. |
| T1132.001 Standard Encoding |
MalwareBRICKSTORM | BRICKSTORM has leveraged Base64 to encode C2 communications. |
| T1132.001 Standard Encoding |
MalwareTorisma | Torisma has encoded C2 communications with Base64. |
| T1132.001 Standard Encoding |
MalwareBackdoor.Oldrea | Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers. |
| T1132.001 Standard Encoding |
MalwareStuxnet | Stuxnet transforms encrypted binary data into an ASCII string in order to use it as a URL parameter value. |
| T1132.001 Standard Encoding |
MalwareRotaJakiro | RotaJakiro uses ZLIB Compression to compresses data sent to the C2 server in the `payload` section network communication packet. |
| T1132.001 Standard Encoding |
MalwarePOWRUNER | POWRUNER can use base64 encoded C2 communications. |
| T1132.001 Standard Encoding |
MalwareSardonic | Sardonic can encode client ID data in 32 uppercase hex characters and transfer to the actor-controlled C2 server. |
| T1132.001 Standard Encoding |
MalwareMisdat | Misdat network traffic is Base64-encoded plaintext. |
| T1132.001 Standard Encoding |
MalwareTAMECAT | TAMECAT has encoded C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareFelismus | Some Felismus samples use a custom method for C2 traffic that utilizes Base64. |
| T1132.001 Standard Encoding |
MalwarexCaon | xCaon has used Base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareGomir | Gomir uses Base64-encoded content in HTTP communications to command and control infrastructure. |
| T1132.001 Standard Encoding |
MalwareEmotet | Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Additionally, Emotet has used Base64 to encode data before sending to the C2 server. |
| T1132.001 Standard Encoding |
MalwareMachete | Machete has used base64 encoding. |
| T1132.001 Standard Encoding |
MalwarePrikormka | Prikormka encodes C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareGootloader | Gootloader can retrieve a Base64 encoded stager from C2. |
| T1132.001 Standard Encoding |
MalwarePingPull | PingPull can encode C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareWellMess | WellMess has used Base64 encoding to uniquely identify communication to and from the C2. |
| T1132.001 Standard Encoding |
MalwareMafalda | Mafalda can encode data using Base64 prior to exfiltration. |
| T1132.001 Standard Encoding |
MalwareSquirrelwaffle | Squirrelwaffle has encoded its communications to C2 servers using Base64. |
| T1132.001 Standard Encoding |
MalwareHOPLIGHT | HOPLIGHT has utilized Zlib compression to obfuscate the communications payload. |
| T1132.001 Standard Encoding |
MalwareRDAT | RDAT can communicate with the C2 via base32-encoded subdomains. |
| T1132.001 Standard Encoding |
MalwareOkrum | Okrum has used base64 to encode C2 communication. |
| T1132.001 Standard Encoding |
MalwareRustyWater | RustyWater has encoded collected data with Base64. |
| T1132.001 Standard Encoding |
MalwareFysbis | Fysbis can use Base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwarePowerShower | PowerShower has the ability to encode C2 communications with base64 encoding. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.