Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.001 Symmetric Cryptography |
MalwareEpic | Epic encrypts commands from the C2 server using a hardcoded key. |
| T1573.001 Symmetric Cryptography |
MalwareLightNeuron | LightNeuron uses AES to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwarePureCrypter | PureCrypter can use AES to encrypt system information sent to the C2. |
| T1573.001 Symmetric Cryptography |
MalwareMongall | Mongall has the ability to RC4 encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareLockBit 3.0 | LockBit 3.0 can encrypt C2 communications with AES. |
| T1573.001 Symmetric Cryptography |
MalwareFoggyWeb | FoggyWeb has used a dynamic XOR key and custom XOR methodology for C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareNGLite | NGLite will use an AES encrypted channel for command and control purposes, in one case using the key |
| T1573.001 Symmetric Cryptography |
MalwareCarbanak | Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode). Carbanak also uses XOR with random keys for its communications. |
| T1573.001 Symmetric Cryptography |
MalwareHydraq | Hydraq C2 traffic is encrypted using bitwise NOT and XOR operations. |
| T1573.001 Symmetric Cryptography |
MalwareElise | Elise encrypts exfiltrated data with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareGazer | Gazer uses custom encryption for C2 that uses 3DES. |
| T1573.001 Symmetric Cryptography |
MalwareTSCookie | TSCookie has encrypted network communications with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareLatrodectus | Latrodectus can send RC4 encrypted data over C2 channels. |
| T1573.001 Symmetric Cryptography |
MalwareLODEINFO | LODEINFO can encrypt C2 communication with a hardcoded (NV4HDOeOVyL) Vigenere cipher key. |
| T1573.001 Symmetric Cryptography |
MalwareCharmPower | CharmPower can send additional modules over C2 encrypted with a simple substitution cipher. |
| T1573.001 Symmetric Cryptography |
MalwareMuddyViper | MuddyViper has the ability to encrypt C2 communication using AES-CBC using the CNG API, the key `0608101047106453101617106423101013101012101083109710108585106969`, and the initialization vector `0`. |
| T1573.001 Symmetric Cryptography |
Malware3PARA RAT | 3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode with a key derived from the MD5 hash of the string HYF54&%9&jkMCXuiS. 3PARA RAT will use an 8-byte XOR key derived from the string HYF54&%9&jkMCXuiS if the DES decoding fails |
| T1573.001 Symmetric Cryptography |
MalwareVIRTUALPIE | VIRTUALPIE can use a custom RC4 encrypted protocol for C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareSMOKEDHAM | SMOKEDHAM has encrypted its C2 traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE uses a Linear Feedback Shift Register (LFSR) algorithm for network encryption. |
| T1573.001 Symmetric Cryptography |
MalwareSys10 | Sys10 uses an XOR 0x1 loop to encrypt its C2 domain. |
| T1573.001 Symmetric Cryptography |
MalwareBendyBear | BendyBear communicates to a C2 server over port 443 using modified RC4 and XOR-encrypted chunks. |
| T1573.001 Symmetric Cryptography |
MalwareUroburos | Uroburos can encrypt the data beneath its http2 or tcp encryption at the session layer with CAST-128, using a different key for incoming and outgoing data. |
| T1573.001 Symmetric Cryptography |
MalwareMetamorfo | Metamorfo has encrypted C2 commands with AES-256. |
| T1573.001 Symmetric Cryptography |
MalwareBandook | Bandook has used AES encryption for C2 communication. |
| T1573.001 Symmetric Cryptography |
MalwarePipeMon | PipeMon communications are RC4 encrypted. |
| T1573.001 Symmetric Cryptography |
MalwareKONNI | KONNI has used AES to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareWinnti for Linux | Winnti for Linux has used a custom TCP protocol with four-byte XOR for command and control (C2). |
| T1573.001 Symmetric Cryptography |
Malwaregh0st RAT | gh0st RAT uses RC4 and XOR to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
Malwaredown_new | down_new has the ability to AES encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
Malware4H RAT | 4H RAT obfuscates C2 communication using a 1-byte XOR with the key 0xBE. |
| T1573.001 Symmetric Cryptography |
MalwareAttor | Attor has encrypted data symmetrically using a randomly generated Blowfish (OFB) key which is encrypted with a public RSA key. |
| T1573.001 Symmetric Cryptography |
MalwareMosquito | Mosquito uses a custom encryption algorithm, which consists of XOR and a stream that is similar to the Blum Blum Shub algorithm. |
| T1573.001 Symmetric Cryptography |
MalwareRTM | RTM encrypts C2 traffic with a custom RC4 variant. |
| T1573.001 Symmetric Cryptography |
MalwareQUIETCANARY | QUIETCANARY can RC4 encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareDerusbi | Derusbi obfuscates C2 traffic with variable 4-byte XOR keys. |
| T1573.001 Symmetric Cryptography |
MalwareSodaMaster | SodaMaster can use RC4 to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareHikit | Hikit performs XOR encryption. |
| T1573.001 Symmetric Cryptography |
MalwareSakula | Sakula encodes C2 traffic with single-byte XOR keys. |
| T1573.001 Symmetric Cryptography |
MalwareBazar | Bazar can send C2 communications with XOR encryption. |
| T1573.001 Symmetric Cryptography |
MalwareKobalos | Kobalos's post-authentication communication channel uses a 32-byte-long password with RC4 for inbound and outbound traffic. |
| T1573.001 Symmetric Cryptography |
MalwareBADCALL | BADCALL encrypts C2 traffic using an XOR/ADD cipher. |
| T1573.001 Symmetric Cryptography |
MalwareMoonWind | MoonWind encrypts C2 traffic using RC4 with a static key. |
| T1573.001 Symmetric Cryptography |
MalwareHiddenFace | HiddenFace can use a randomly selected symmetric encryption algorithm for C2. |
| T1573.001 Symmetric Cryptography |
MalwarePandora | Pandora has the ability to encrypt communications with D3DES. |
| T1573.001 Symmetric Cryptography |
MalwareCobalt Strike | Cobalt Strike has the ability to use AES-256 symmetric encryption in CBC mode with HMAC-SHA-256 to encrypt task commands and XOR to encrypt shell code and configuration data. |
| T1573.001 Symmetric Cryptography |
MalwareSUNBURST | SUNBURST encrypted C2 traffic using a single-byte-XOR cipher. |
| T1573.001 Symmetric Cryptography |
MalwareHotCroissant | HotCroissant has compressed network communications and encrypted them with a custom stream cipher. |
| T1573.001 Symmetric Cryptography |
MalwareRIPTIDE | APT12 has used the RIPTIDE RAT, which communicates over HTTP with a payload encrypted with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareSamurai | Samurai can encrypt C2 communications with AES. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.