Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.001 Symmetric Cryptography |
MalwareRedLeaves | RedLeaves has encrypted C2 traffic with RC4, previously using keys of 88888888 and babybear. |
| T1573.001 Symmetric Cryptography |
MalwareFelismus | Some Felismus samples use a custom encryption method for C2 traffic that utilizes AES and multiple keys. |
| T1573.001 Symmetric Cryptography |
MalwareHavoc | Havoc can send an AES encrypted check-in request to the C2 server. |
| T1573.001 Symmetric Cryptography |
MalwarexCaon | xCaon has encrypted data sent to the C2 server using a XOR key. |
| T1573.001 Symmetric Cryptography |
MalwarePLAINTEE | PLAINTEE encodes C2 beacons using XOR. |
| T1573.001 Symmetric Cryptography |
MalwareNebulae | Nebulae can use RC4 and XOR to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareLurid | Lurid performs XOR encryption. |
| T1573.001 Symmetric Cryptography |
MalwareTONESHELL | TONESHELL has used RC4 encryption in C2 communications. TONESHELL variants used a randomly generated variable length (0x20 - 0x200 bytes) rolling XOR key to encrypt and decrypt network packets. |
| T1573.001 Symmetric Cryptography |
MalwareRainyDay | RainyDay can use RC4 to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareNETWIRE | NETWIRE can use AES encryption for C2 data transferred. |
| T1573.001 Symmetric Cryptography |
MalwareBOOKWORM | BOOKWORM has used encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO. |
| T1573.001 Symmetric Cryptography |
MalwareHyperStack | HyperStack has used RSA encryption for C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareHAMMERTOSS | Before being appended to image files, HAMMERTOSS commands are encrypted with a key composed of both a hard-coded value and a string contained on that day's tweet. To decrypt the commands, an investigator would need access to the intended malware sample, the day's tweet, and the image file containing the command. |
| T1573.001 Symmetric Cryptography |
MalwareCosmicDuke | CosmicDuke contains a custom version of the RC4 algorithm that includes a programming error. |
| T1573.001 Symmetric Cryptography |
MalwareGreyEnergy | GreyEnergy encrypts communications using AES256. |
| T1573.001 Symmetric Cryptography |
MalwareEmotet | Emotet is known to use RSA keys for encrypting C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareSNUGRIDE | SNUGRIDE encrypts C2 traffic using AES with a static key. |
| T1573.001 Symmetric Cryptography |
MalwareTHINCRUST | THINCRUST can process RSA encryted C2 commands. |
| T1573.001 Symmetric Cryptography |
MalwareMachete | Machete has used AES to exfiltrate documents. |
| T1573.001 Symmetric Cryptography |
MalwarePrikormka | Prikormka encrypts some C2 traffic with the Blowfish cipher. |
| T1573.001 Symmetric Cryptography |
MalwarePUBLOAD | PUBLOAD has used RC4 encryption in C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareSystemBC | SystemBC has encrypted its C2 traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwarePingPull | PingPull can use AES, in cipher block chaining (CBC) mode padded with PKCS5, to encrypt C2 server communications. |
| T1573.001 Symmetric Cryptography |
MalwareWellMess | WellMess can encrypt HTTP POST data using RC6 and a dynamically generated AES key encrypted with a hard coded RSA public key. |
| T1573.001 Symmetric Cryptography |
MalwareWoody RAT | Woody RAT can use AES-CBC to encrypt data sent to its C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareMafalda | Mafalda can encrypt its C2 traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareSombRAT | SombRAT has encrypted its C2 communications with AES. |
| T1573.001 Symmetric Cryptography |
MalwareFlawedAmmyy | FlawedAmmyy has used SEAL encryption during the initial C2 handshake. |
| T1573.001 Symmetric Cryptography |
MalwareRifdoor | Rifdoor has encrypted command and control (C2) communications with a stream cipher. |
| T1573.001 Symmetric Cryptography |
MalwareInvisiMole | InvisiMole uses variations of a simple XOR encryption routine for C&C communications. |
| T1573.001 Symmetric Cryptography |
MalwareVolgmer | Volgmer uses a simple XOR cipher to encrypt traffic and files. |
| T1573.001 Symmetric Cryptography |
MalwareZeroT | ZeroT has used RC4 to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareRDAT | RDAT has used AES ciphertext to encode C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareOkrum | Okrum uses AES to encrypt network traffic. The key can be hardcoded or negotiated with the C2 server in the registration phase. |
| T1573.001 Symmetric Cryptography |
MalwareBonadan | Bonadan can XOR-encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareRustyWater | RustyWater has encrypted encoded data with XOR before sending it to the C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareUBoatRAT | UBoatRAT encrypts instructions in its C2 network payloads using a simple XOR cipher. |
| T1573.001 Symmetric Cryptography |
MalwareHTTPTroy | HTTPTroy has obfuscated request communications utilizing XOR encryption. |
| T1573.001 Symmetric Cryptography |
MalwareNETEAGLE | NETEAGLE will decrypt resources it downloads with HTTP requests by using RC4 with the key "ScoutEagle." |
| T1573.001 Symmetric Cryptography |
MalwareFatDuke | FatDuke can AES encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareLucifer | Lucifer can perform a decremental-xor encryption on the initial C2 request before sending it over the wire. |
| T1573.001 Symmetric Cryptography |
MalwareHi-Zor | Hi-Zor encrypts C2 traffic with a double XOR using two distinct single-byte keys. |
| T1573.001 Symmetric Cryptography |
MalwareChaos | Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES. |
| T1573.001 Symmetric Cryptography |
MalwareLIGHTWIRE | LIGHTWIRE can RC4 encrypt C2 commands. |
| T1573.001 Symmetric Cryptography |
MalwareCORESHELL | CORESHELL C2 messages are encrypted with custom stream ciphers using six-byte or eight-byte keys. |
| T1573.001 Symmetric Cryptography |
MalwareBBSRAT | BBSRAT uses a custom encryption algorithm on data sent back to the C2 server over HTTP. |
| T1573.001 Symmetric Cryptography |
MalwarePlugX | PlugX can use RC4 encryption in C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareBisonal | Bisonal variants reported on in 2014 and 2015 used a simple XOR cipher for C2. Some Bisonal samples encrypt C2 communications with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareSeaDuke | SeaDuke C2 traffic has been encrypted with RC4 and AES. |
| T1573.001 Symmetric Cryptography |
MalwareExplosive | Explosive has encrypted communications with the RC4 method. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.