Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.001 Symmetric Cryptography |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D encrypts data sent back to the C2 using AES in CBC mode with a null initialization vector (IV) and a key sent from the server that is padded to 32 bytes. |
| T1573.001 Symmetric Cryptography |
MalwareTaidoor | Taidoor uses RC4 to encrypt the message body of HTTP content. |
| T1573.001 Symmetric Cryptography |
MalwarePoisonIvy | PoisonIvy uses the Camellia cipher to encrypt communications. |
| T1573.001 Symmetric Cryptography |
MalwareNanoCore | NanoCore uses DES to encrypt the C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwarePLEAD | PLEAD has used RC4 encryption to download modules. |
| T1573.001 Symmetric Cryptography |
MalwareDaserf | Daserf uses RC4 encryption to obfuscate HTTP traffic. |
| T1573.001 Symmetric Cryptography |
MalwareCardinal RAT | Cardinal RAT uses a secret key with a series of XOR and addition operations to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareSolar | Solar can XOR encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareFakeM | The original variant of FakeM encrypts C2 traffic using a custom encryption cipher that uses an XOR key of “YHCRA” and bit rotation between each XOR operation. Some variants of FakeM use RC4 to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareMore_eggs | More_eggs has used an RC4-based encryption method for its C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareSysUpdate | SysUpdate has used DES to encrypt all C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareMango | Mango can receive XOR-encrypted commands from C2. |
| T1573.001 Symmetric Cryptography |
MalwareWIREFIRE | WIREFIRE can AES encrypt process output sent from compromised devices to C2. |
| T1573.001 Symmetric Cryptography |
MalwareGrimAgent | GrimAgent can use an AES key to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareLookBack | LookBack uses a modified version of RC4 for data transfer. |
| T1573.001 Symmetric Cryptography |
MalwareCallMe | CallMe uses AES to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareCHOPSTICK | CHOPSTICK encrypts C2 communications with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareRIFLESPINE | RIFLESPINE can use the AES algorithm to encrypt C2 data. |
| T1573.001 Symmetric Cryptography |
MalwareSLIGHTPULSE | SLIGHTPULSE can RC4 encrypt all incoming and outgoing C2 messages. |
| T1573.001 Symmetric Cryptography |
MalwareNDiskMonitor | NDiskMonitor uses AES to encrypt certain information sent over its C2 channel. |
| T1573.001 Symmetric Cryptography |
MalwareWinnti for Windows | Winnti for Windows can XOR encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareTroll Stealer | Troll Stealer encrypts data sent to command and control infrastructure using a combination of RC4 and RSA-4096 algorithms. |
| T1573.001 Symmetric Cryptography |
MalwareEbury | Ebury has encrypted C2 traffic using the client IP address, then encoded it as a hexadecimal string. |
| T1573.001 Symmetric Cryptography |
MalwareZIPLINE | ZIPLINE can use AES-128-CBC to encrypt data for both upload and download. |
| T1573.001 Symmetric Cryptography |
MalwareChChes | ChChes can encrypt C2 traffic with AES or RC4. |
| T1573.001 Symmetric Cryptography |
MalwareIceApple | The IceApple Result Retriever module can AES encrypt C2 responses. |
| T1573.001 Symmetric Cryptography |
MalwaremetaMain | metaMain can encrypt the data that it sends and receives from the C2 server using an RC4 encryption algorithm. |
| T1573.001 Symmetric Cryptography |
MalwareSideTwist | SideTwist can encrypt C2 communications with a randomly generated key. |
| T1573.001 Symmetric Cryptography |
MalwareLunarWeb | LunarWeb can send AES encrypted C2 commands. |
| T1573.001 Symmetric Cryptography |
MalwareXCSSET | XCSSET uses RC4 encryption over TCP to communicate with its C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareDipsind | Dipsind encrypts C2 data with AES256 in ECB mode. |
| T1573.001 Symmetric Cryptography |
Malwarehttpclient | httpclient encrypts C2 content with XOR using a single byte, 0x12. |
| T1573.001 Symmetric Cryptography |
MalwarePOWERTON | POWERTON has used AES for encrypting C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareStarProxy | StarProxy has leveraged two 256-byte XOR keys to encrypt and decrypt network packets using a custom algorithm. |
| T1573.001 Symmetric Cryptography |
MalwareBADNEWS | BADNEWS encrypts C2 data with a ROR by 3 and an XOR by 0x23. |
| T1573.001 Symmetric Cryptography |
MalwareQakBot | QakBot can RC4 encrypt strings in C2 communication. |
| T1573.001 Symmetric Cryptography |
MalwareHelminth | Helminth encrypts data sent to its C2 server over HTTP with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareDridex | Dridex has encrypted traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareKomplex | The Komplex C2 channel uses an 11-byte XOR algorithm to hide data. |
| T1573.001 Symmetric Cryptography |
MalwareComnie | Comnie encrypts command and control communications with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareH1N1 | H1N1 encrypts C2 traffic using an RC4 key. |
| T1573.001 Symmetric Cryptography |
MalwareAzorult | Azorult can encrypt C2 traffic using XOR. |
| T1573.001 Symmetric Cryptography |
MalwareUPPERCUT | Some versions of UPPERCUT have used the hard-coded string “this is the encrypt key” for Blowfish encryption when communicating with a C2. Later versions have hard-coded keys uniquely for each C2 address. UPPERCUT has also used custom ChaCha20, XOR, and LZO algorithms for C2 communication. |
| T1573.001 Symmetric Cryptography |
MalwareADVSTORESHELL | A variant of ADVSTORESHELL encrypts some C2 with 3DES. |
| T1573.001 Symmetric Cryptography |
MalwareStrifeWater | StrifeWater can encrypt C2 traffic using XOR with a hard coded key. |
| T1573.001 Symmetric Cryptography |
MalwareHiddenWasp | HiddenWasp uses an RC4-like algorithm with an already computed PRGA generated key-stream for network communication. |
| T1573.001 Symmetric Cryptography |
MalwareWarzoneRAT | WarzoneRAT can encrypt its C2 with RC4 with the password `warzone160\x00`. |
| T1573.001 Symmetric Cryptography |
MalwareFALLCHILL | FALLCHILL encrypts C2 data with RC4 encryption. |
| T1573.001 Symmetric Cryptography |
ToolSliver | Sliver can use AES-GCM-256 to encrypt a session key for C2 message exchange. |
| T1573.001 Symmetric Cryptography |
ToolFRP | FRP can use STCP (Secret TCP) with a preshared key to encrypt services exposed to public networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.