ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1132.001
Standard Encoding
MalwareMango

Mango can receive Base64-encoded commands from C2.

T1132.001
Standard Encoding
MalwareWIREFIRE

WIREFIRE can Base64 encode process output sent to C2.

T1132.001
Standard Encoding
MalwareKessel

Kessel has exfiltrated data via hexadecimal-encoded subdomain fields of DNS queries.

T1132.001
Standard Encoding
MalwareGrimAgent

GrimAgent can base64 encode C2 replies.

T1132.001
Standard Encoding
MalwareSTEADYPULSE

STEADYPULSE can transmit URL encoded data over C2.

T1132.001
Standard Encoding
MalwareSLIGHTPULSE

SLIGHTPULSE can base64 encode all incoming and outgoing C2 messages.

T1132.001
Standard Encoding
MalwareBabyShark

BabyShark has encoded data using certutil before exfiltration.

T1132.001
Standard Encoding
MalwareCreepySnail

CreepySnail can use Base64 to encode its C2 traffic.

T1132.001
Standard Encoding
MalwareTroll Stealer

Troll Stealer performs XOR encryption and Base64 encoding of data prior to sending to command and control infrastructure.

T1132.001
Standard Encoding
MalwareEbury

Ebury has encoded C2 traffic in hexadecimal format.

T1132.001
Standard Encoding
MalwarenjRAT

njRAT uses Base64 encoding for C2 traffic.

T1132.001
Standard Encoding
MalwareChChes

ChChes can encode C2 data with a custom technique that utilizes Base64.

T1132.001
Standard Encoding
MalwareManjusaka

Manjusaka communication includes a client-created session cookie with base64-encoded information representing information from the victim system.

T1132.001
Standard Encoding
MalwareSideTwist

SideTwist has used Base64 for encoded C2 traffic.

T1132.001
Standard Encoding
MalwareMechaFlounder

MechaFlounder has the ability to use base16 encoded strings in C2.

T1132.001
Standard Encoding
MalwareMis-Type

Mis-Type uses Base64 encoding for C2 traffic.

T1132.001
Standard Encoding
MalwareLunarWeb

LunarWeb can use Base64 encoding to obfuscate C2 commands.

T1132.001
Standard Encoding
MalwareDipsind

Dipsind encodes C2 traffic with base64.

T1132.001
Standard Encoding
MalwareOctopus

Octopus has encoded C2 communications in Base64.

T1132.001
Standard Encoding
MalwareSTARWHALE

STARWHALE has the ability to hex-encode collected data from an infected host.

T1132.001
Standard Encoding
MalwareKevin

Kevin can Base32 encode chunks of output files during exfiltration.

T1132.001
Standard Encoding
MalwarePOWERSTATS

POWERSTATS encoded C2 traffic with base64.

T1132.001
Standard Encoding
MalwareBADNEWS

BADNEWS encodes C2 traffic with base64.

T1132.001
Standard Encoding
MalwareAstaroth

Astaroth encodes data using Base64 before sending it to the C2 server.

T1132.001
Standard Encoding
MalwareQakBot

QakBot can Base64 encode system information sent to C2.

T1132.001
Standard Encoding
MalwareHelminth

For C2 over HTTP, Helminth encodes data with base64 and sends it via the "Cookie" field of HTTP requests. For C2 over DNS, Helminth converts ASCII characters into their hexadecimal values and sends the data in cleartext.

T1132.001
Standard Encoding
MalwareDenis

Denis encodes the data sent to the server in Base64.

T1132.001
Standard Encoding
MalwareAutoIt backdoor

AutoIt backdoor has sent a C2 response that was base64-encoded.

T1132.001
Standard Encoding
MalwareUPPERCUT

UPPERCUT can base64 encode C2 communications.

T1132.001
Standard Encoding
MalwareADVSTORESHELL

C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding.

T1132.001
Standard Encoding
ToolSliver

Sliver can use standard encoding techniques like gzip and hex to ASCII to encode the C2 communication payload.

T1132.001
Standard Encoding
ToolRemcos

Remcos can serialize collected data with Protobuf.

T1132.001
Standard Encoding
MalwareMini Shai-Hulud

Mini Shai-Hulud has used base64 encoding to obfuscate URLs used for C2.

T1132.002
Non-Standard Encoding
GroupKimsuky

Kimsuky has obfuscated HTTP Post request communications utilizing XOR with a designated key, followed by Base64 encoding.

T1132.002
Non-Standard Encoding
MalwareNinja

Ninja can encode C2 communications with a base64 algorithm using a custom alphabet.

T1132.002
Non-Standard Encoding
MalwareBankshot

Bankshot encodes commands from the control server using a range of characters and gzip.

T1132.002
Non-Standard Encoding
MalwareTONESHELL

TONESHELL has encoded a payload with a random 32-byte key using XOR. TONESHELL has also encoded payloads with a 256-byte key using XOR.

T1132.002
Non-Standard Encoding
MalwareOceanSalt

OceanSalt can encode data with a NOT operation before sending the data to the control server.

T1132.002
Non-Standard Encoding
MalwareInvisiMole

InvisiMole can use a modified base32 encoding to encode data within the subdomain of C2 requests.

T1132.002
Non-Standard Encoding
MalwareRDAT

RDAT can communicate with the C2 via subdomains that utilize base64 with character substitutions.

T1132.002
Non-Standard Encoding
MalwareHTTPTroy

HTTPTroy has obfuscated HTTP POST request communications utilizing XOR with a designated key of 0x56, followed by Base64 encoding.

T1132.002
Non-Standard Encoding
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use a custom Base64 alphabet for encoding C2.

T1132.002
Non-Standard Encoding
MalwareUroburos

Uroburos can use a custom base62 and a de-facto base32 encoding that uses digits 0-9 and lowercase letters a-z in C2 communications.

T1132.002
Non-Standard Encoding
MalwareNightClub

NightClub has used a non-standard encoding in DNS tunneling removing any `=` from the result of base64 encoding, and replacing `/` characters with `-s` and `+` characters with `-p`.

T1132.002
Non-Standard Encoding
MalwareCyclops Blink

Cyclops Blink can use a custom binary scheme to encode messages with specific commands and parameters to be executed.

T1132.002
Non-Standard Encoding
MalwareNeo-reGeorg

Neo-reGeorg can use modified Base64 encoding to obfuscate communications.

T1132.002
Non-Standard Encoding
MalwarePowGoop

PowGoop can use a modified Base64 encoding mechanism to send data to and from the C2 server.

T1132.002
Non-Standard Encoding
MalwareShadowPad

ShadowPad has encoded data as readable Latin characters.

T1132.002
Non-Standard Encoding
MalwareLizar

Lizar has used a complex XOR operation to obfuscate C2 communications.

T1132.002
Non-Standard Encoding
MalwareBACKSPACE

Newer variants of BACKSPACE will encode C2 communications with a custom system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.