ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1573.001
Symmetric Cryptography
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D encrypts data sent back to the C2 using AES in CBC mode with a null initialization vector (IV) and a key sent from the server that is padded to 32 bytes.

T1573.001
Symmetric Cryptography
MalwareTaidoor

Taidoor uses RC4 to encrypt the message body of HTTP content.

T1573.001
Symmetric Cryptography
MalwarePoisonIvy

PoisonIvy uses the Camellia cipher to encrypt communications.

T1573.001
Symmetric Cryptography
MalwareNanoCore

NanoCore uses DES to encrypt the C2 traffic.

T1573.001
Symmetric Cryptography
MalwarePLEAD

PLEAD has used RC4 encryption to download modules.

T1573.001
Symmetric Cryptography
MalwareDaserf

Daserf uses RC4 encryption to obfuscate HTTP traffic.

T1573.001
Symmetric Cryptography
MalwareCardinal RAT

Cardinal RAT uses a secret key with a series of XOR and addition operations to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareSolar

Solar can XOR encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareFakeM

The original variant of FakeM encrypts C2 traffic using a custom encryption cipher that uses an XOR key of “YHCRA” and bit rotation between each XOR operation. Some variants of FakeM use RC4 to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareMore_eggs

More_eggs has used an RC4-based encryption method for its C2 communications.

T1573.001
Symmetric Cryptography
MalwareSysUpdate

SysUpdate has used DES to encrypt all C2 communications.

T1573.001
Symmetric Cryptography
MalwareMango

Mango can receive XOR-encrypted commands from C2.

T1573.001
Symmetric Cryptography
MalwareWIREFIRE

WIREFIRE can AES encrypt process output sent from compromised devices to C2.

T1573.001
Symmetric Cryptography
MalwareGrimAgent

GrimAgent can use an AES key to encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareLookBack

LookBack uses a modified version of RC4 for data transfer.

T1573.001
Symmetric Cryptography
MalwareCallMe

CallMe uses AES to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareCHOPSTICK

CHOPSTICK encrypts C2 communications with RC4.

T1573.001
Symmetric Cryptography
MalwareRIFLESPINE

RIFLESPINE can use the AES algorithm to encrypt C2 data.

T1573.001
Symmetric Cryptography
MalwareSLIGHTPULSE

SLIGHTPULSE can RC4 encrypt all incoming and outgoing C2 messages.

T1573.001
Symmetric Cryptography
MalwareNDiskMonitor

NDiskMonitor uses AES to encrypt certain information sent over its C2 channel.

T1573.001
Symmetric Cryptography
MalwareWinnti for Windows

Winnti for Windows can XOR encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareTroll Stealer

Troll Stealer encrypts data sent to command and control infrastructure using a combination of RC4 and RSA-4096 algorithms.

T1573.001
Symmetric Cryptography
MalwareEbury

Ebury has encrypted C2 traffic using the client IP address, then encoded it as a hexadecimal string.

T1573.001
Symmetric Cryptography
MalwareZIPLINE

ZIPLINE can use AES-128-CBC to encrypt data for both upload and download.

T1573.001
Symmetric Cryptography
MalwareChChes

ChChes can encrypt C2 traffic with AES or RC4.

T1573.001
Symmetric Cryptography
MalwareIceApple

The IceApple Result Retriever module can AES encrypt C2 responses.

T1573.001
Symmetric Cryptography
MalwaremetaMain

metaMain can encrypt the data that it sends and receives from the C2 server using an RC4 encryption algorithm.

T1573.001
Symmetric Cryptography
MalwareSideTwist

SideTwist can encrypt C2 communications with a randomly generated key.

T1573.001
Symmetric Cryptography
MalwareLunarWeb

LunarWeb can send AES encrypted C2 commands.

T1573.001
Symmetric Cryptography
MalwareXCSSET

XCSSET uses RC4 encryption over TCP to communicate with its C2 server.

T1573.001
Symmetric Cryptography
MalwareDipsind

Dipsind encrypts C2 data with AES256 in ECB mode.

T1573.001
Symmetric Cryptography
Malwarehttpclient

httpclient encrypts C2 content with XOR using a single byte, 0x12.

T1573.001
Symmetric Cryptography
MalwarePOWERTON

POWERTON has used AES for encrypting C2 traffic.

T1573.001
Symmetric Cryptography
MalwareStarProxy

StarProxy has leveraged two 256-byte XOR keys to encrypt and decrypt network packets using a custom algorithm.

T1573.001
Symmetric Cryptography
MalwareBADNEWS

BADNEWS encrypts C2 data with a ROR by 3 and an XOR by 0x23.

T1573.001
Symmetric Cryptography
MalwareQakBot

QakBot can RC4 encrypt strings in C2 communication.

T1573.001
Symmetric Cryptography
MalwareHelminth

Helminth encrypts data sent to its C2 server over HTTP with RC4.

T1573.001
Symmetric Cryptography
MalwareDridex

Dridex has encrypted traffic with RC4.

T1573.001
Symmetric Cryptography
MalwareKomplex

The Komplex C2 channel uses an 11-byte XOR algorithm to hide data.

T1573.001
Symmetric Cryptography
MalwareComnie

Comnie encrypts command and control communications with RC4.

T1573.001
Symmetric Cryptography
MalwareH1N1

H1N1 encrypts C2 traffic using an RC4 key.

T1573.001
Symmetric Cryptography
MalwareAzorult

Azorult can encrypt C2 traffic using XOR.

T1573.001
Symmetric Cryptography
MalwareUPPERCUT

Some versions of UPPERCUT have used the hard-coded string “this is the encrypt key” for Blowfish encryption when communicating with a C2. Later versions have hard-coded keys uniquely for each C2 address. UPPERCUT has also used custom ChaCha20, XOR, and LZO algorithms for C2 communication.

T1573.001
Symmetric Cryptography
MalwareADVSTORESHELL

A variant of ADVSTORESHELL encrypts some C2 with 3DES.

T1573.001
Symmetric Cryptography
MalwareStrifeWater

StrifeWater can encrypt C2 traffic using XOR with a hard coded key.

T1573.001
Symmetric Cryptography
MalwareHiddenWasp

HiddenWasp uses an RC4-like algorithm with an already computed PRGA generated key-stream for network communication.

T1573.001
Symmetric Cryptography
MalwareWarzoneRAT

WarzoneRAT can encrypt its C2 with RC4 with the password `warzone160\x00`.

T1573.001
Symmetric Cryptography
MalwareFALLCHILL

FALLCHILL encrypts C2 data with RC4 encryption.

T1573.001
Symmetric Cryptography
ToolSliver

Sliver can use AES-GCM-256 to encrypt a session key for C2 message exchange.

T1573.001
Symmetric Cryptography
ToolFRP

FRP can use STCP (Secret TCP) with a preshared key to encrypt services exposed to public networks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.