ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1573.001
Symmetric Cryptography
MalwareRedLeaves

RedLeaves has encrypted C2 traffic with RC4, previously using keys of 88888888 and babybear.

T1573.001
Symmetric Cryptography
MalwareFelismus

Some Felismus samples use a custom encryption method for C2 traffic that utilizes AES and multiple keys.

T1573.001
Symmetric Cryptography
MalwareHavoc

Havoc can send an AES encrypted check-in request to the C2 server.

T1573.001
Symmetric Cryptography
MalwarexCaon

xCaon has encrypted data sent to the C2 server using a XOR key.

T1573.001
Symmetric Cryptography
MalwarePLAINTEE

PLAINTEE encodes C2 beacons using XOR.

T1573.001
Symmetric Cryptography
MalwareNebulae

Nebulae can use RC4 and XOR to encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareLurid

Lurid performs XOR encryption.

T1573.001
Symmetric Cryptography
MalwareTONESHELL

TONESHELL has used RC4 encryption in C2 communications. TONESHELL variants used a randomly generated variable length (0x20 - 0x200 bytes) rolling XOR key to encrypt and decrypt network packets.

T1573.001
Symmetric Cryptography
MalwareRainyDay

RainyDay can use RC4 to encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareNETWIRE

NETWIRE can use AES encryption for C2 data transferred.

T1573.001
Symmetric Cryptography
MalwareBOOKWORM

BOOKWORM has used encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO.

T1573.001
Symmetric Cryptography
MalwareHyperStack

HyperStack has used RSA encryption for C2 communications.

T1573.001
Symmetric Cryptography
MalwareHAMMERTOSS

Before being appended to image files, HAMMERTOSS commands are encrypted with a key composed of both a hard-coded value and a string contained on that day's tweet. To decrypt the commands, an investigator would need access to the intended malware sample, the day's tweet, and the image file containing the command.

T1573.001
Symmetric Cryptography
MalwareCosmicDuke

CosmicDuke contains a custom version of the RC4 algorithm that includes a programming error.

T1573.001
Symmetric Cryptography
MalwareGreyEnergy

GreyEnergy encrypts communications using AES256.

T1573.001
Symmetric Cryptography
MalwareEmotet

Emotet is known to use RSA keys for encrypting C2 traffic.

T1573.001
Symmetric Cryptography
MalwareSNUGRIDE

SNUGRIDE encrypts C2 traffic using AES with a static key.

T1573.001
Symmetric Cryptography
MalwareTHINCRUST

THINCRUST can process RSA encryted C2 commands.

T1573.001
Symmetric Cryptography
MalwareMachete

Machete has used AES to exfiltrate documents.

T1573.001
Symmetric Cryptography
MalwarePrikormka

Prikormka encrypts some C2 traffic with the Blowfish cipher.

T1573.001
Symmetric Cryptography
MalwarePUBLOAD

PUBLOAD has used RC4 encryption in C2 communications.

T1573.001
Symmetric Cryptography
MalwareSystemBC

SystemBC has encrypted its C2 traffic with RC4.

T1573.001
Symmetric Cryptography
MalwarePingPull

PingPull can use AES, in cipher block chaining (CBC) mode padded with PKCS5, to encrypt C2 server communications.

T1573.001
Symmetric Cryptography
MalwareWellMess

WellMess can encrypt HTTP POST data using RC6 and a dynamically generated AES key encrypted with a hard coded RSA public key.

T1573.001
Symmetric Cryptography
MalwareWoody RAT

Woody RAT can use AES-CBC to encrypt data sent to its C2 server.

T1573.001
Symmetric Cryptography
MalwareMafalda

Mafalda can encrypt its C2 traffic with RC4.

T1573.001
Symmetric Cryptography
MalwareSombRAT

SombRAT has encrypted its C2 communications with AES.

T1573.001
Symmetric Cryptography
MalwareFlawedAmmyy

FlawedAmmyy has used SEAL encryption during the initial C2 handshake.

T1573.001
Symmetric Cryptography
MalwareRifdoor

Rifdoor has encrypted command and control (C2) communications with a stream cipher.

T1573.001
Symmetric Cryptography
MalwareInvisiMole

InvisiMole uses variations of a simple XOR encryption routine for C&C communications.

T1573.001
Symmetric Cryptography
MalwareVolgmer

Volgmer uses a simple XOR cipher to encrypt traffic and files.

T1573.001
Symmetric Cryptography
MalwareZeroT

ZeroT has used RC4 to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareRDAT

RDAT has used AES ciphertext to encode C2 communications.

T1573.001
Symmetric Cryptography
MalwareOkrum

Okrum uses AES to encrypt network traffic. The key can be hardcoded or negotiated with the C2 server in the registration phase.

T1573.001
Symmetric Cryptography
MalwareBonadan

Bonadan can XOR-encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareRustyWater

RustyWater has encrypted encoded data with XOR before sending it to the C2 server.

T1573.001
Symmetric Cryptography
MalwareUBoatRAT

UBoatRAT encrypts instructions in its C2 network payloads using a simple XOR cipher.

T1573.001
Symmetric Cryptography
MalwareHTTPTroy

HTTPTroy has obfuscated request communications utilizing XOR encryption.

T1573.001
Symmetric Cryptography
MalwareNETEAGLE

NETEAGLE will decrypt resources it downloads with HTTP requests by using RC4 with the key "ScoutEagle."

T1573.001
Symmetric Cryptography
MalwareFatDuke

FatDuke can AES encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareLucifer

Lucifer can perform a decremental-xor encryption on the initial C2 request before sending it over the wire.

T1573.001
Symmetric Cryptography
MalwareHi-Zor

Hi-Zor encrypts C2 traffic with a double XOR using two distinct single-byte keys.

T1573.001
Symmetric Cryptography
MalwareChaos

Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES.

T1573.001
Symmetric Cryptography
MalwareLIGHTWIRE

LIGHTWIRE can RC4 encrypt C2 commands.

T1573.001
Symmetric Cryptography
MalwareCORESHELL

CORESHELL C2 messages are encrypted with custom stream ciphers using six-byte or eight-byte keys.

T1573.001
Symmetric Cryptography
MalwareBBSRAT

BBSRAT uses a custom encryption algorithm on data sent back to the C2 server over HTTP.

T1573.001
Symmetric Cryptography
MalwarePlugX

PlugX can use RC4 encryption in C2 communications.

T1573.001
Symmetric Cryptography
MalwareBisonal

Bisonal variants reported on in 2014 and 2015 used a simple XOR cipher for C2. Some Bisonal samples encrypt C2 communications with RC4.

T1573.001
Symmetric Cryptography
MalwareSeaDuke

SeaDuke C2 traffic has been encrypted with RC4 and AES.

T1573.001
Symmetric Cryptography
MalwareExplosive

Explosive has encrypted communications with the RC4 method.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.