Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.001 Symmetric Cryptography |
ToolQuasarRAT | QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication. |
| T1573.001 Symmetric Cryptography |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has encrypted collected data using a hybrid AES-256 and RSA-4096 encryption prior to exfiltration over 'curl`. |
| T1573.001 Symmetric Cryptography |
MalwareDuqu | The Duqu command and control protocol's data stream can be encrypted with AES-CBC. |
| T1573.002 Asymmetric Cryptography |
MalwareBRICKSTORM | BRICKSTORM has communicated with C2 infrastructure via TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareNICECURL | NICECURL has used HTTPS for C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareCOATHANGER | COATHANGER connects to command and control infrastructure using SSL. |
| T1573.002 Asymmetric Cryptography |
MalwareSardonic | Sardonic has the ability to send a random 64-byte RC4 key to communicate with actor-controlled C2 servers by using an RSA public key. |
| T1573.002 Asymmetric Cryptography |
Malwareadbupd | adbupd contains a copy of the OpenSSL library to encrypt C2 traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareCASTLETAP | CASTLETAP can initiate a C2 connection over an SSL socket. |
| T1573.002 Asymmetric Cryptography |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can communicate over SSL using the private key from the Ivanti Connect Secure web server. |
| T1573.002 Asymmetric Cryptography |
MalwareStrongPity | StrongPity has encrypted C2 traffic using SSL/TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareTinyTurla | TinyTurla has the ability to encrypt C2 traffic with SSL/TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareJ-magic | J-magic can communicate back to send a challenge to C2 infrastructure over SSL. |
| T1573.002 Asymmetric Cryptography |
MalwareGreyEnergy | GreyEnergy encrypts communications using RSA-2048. |
| T1573.002 Asymmetric Cryptography |
MalwareGomir | Gomir uses reverse proxy functionality that employs SSL to encrypt communications. |
| T1573.002 Asymmetric Cryptography |
MalwareBOLDMOVE | BOLDMOVE uses the WolfSSL library to implement SSL encryption for command and control communication. |
| T1573.002 Asymmetric Cryptography |
MalwareBADHATCH | BADHATCH can beacon to a hardcoded C2 IP address using TLS encryption every 5 minutes. |
| T1573.002 Asymmetric Cryptography |
MalwareMachete | Machete has used TLS-encrypted FTP to exfiltrate data. |
| T1573.002 Asymmetric Cryptography |
MalwareWellMess | WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates. |
| T1573.002 Asymmetric Cryptography |
MalwareWoody RAT | Woody RAT can use RSA-4096 to encrypt data sent to its C2 server. |
| T1573.002 Asymmetric Cryptography |
MalwareSombRAT | SombRAT can SSL encrypt C2 traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareVolgmer | Some Volgmer variants use SSL to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareMispadu | Mispadu contains a copy of the OpenSSL library to encrypt C2 traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareREPTILE | REPTILE can use TLS over raw TCP for secure C2. |
| T1573.002 Asymmetric Cryptography |
MalwareDoki | Doki has used the embedTLS library for network communications. |
| T1573.002 Asymmetric Cryptography |
MalwareIcedID | IcedID has used SSL and TLS in communications with C2. |
| T1573.002 Asymmetric Cryptography |
MalwareRising Sun | Rising Sun variants can use SSL for encrypting C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareHi-Zor | Hi-Zor encrypts C2 traffic with TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareSnappyTCP | SnappyTCP can use OpenSSL and TLS certificates to encrypt traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareGoldMax | GoldMax has RSA-encrypted its communication with the C2 server. |
| T1573.002 Asymmetric Cryptography |
MalwarePOSHSPY | POSHSPY encrypts C2 traffic with AES and RSA. |
| T1573.002 Asymmetric Cryptography |
MalwareDarkWatchman | DarkWatchman can use TLS to encrypt its C2 channel. |
| T1573.002 Asymmetric Cryptography |
MalwareLumma Stealer | Lumma Stealer has used HTTPS for command and control purposes. |
| T1573.002 Asymmetric Cryptography |
MalwareSykipot | Sykipot uses SSL for encrypting C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareKEYPLUG | KEYPLUG can use TLS-encrypted WebSocket Protocol (WSS) for C2. |
| T1573.002 Asymmetric Cryptography |
MalwarePureCrypter | PureCrypter can send a TLS 1.2 encrypted infection message via Discord webhook. |
| T1573.002 Asymmetric Cryptography |
MalwareXTunnel | XTunnel uses SSL/TLS and RC4 to encrypt traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareWannaCry | WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit. |
| T1573.002 Asymmetric Cryptography |
MalwareGazer | Gazer uses custom encryption for C2 that uses RSA. |
| T1573.002 Asymmetric Cryptography |
MalwarePay2Key | Pay2Key has used RSA encrypted communications with C2. |
| T1573.002 Asymmetric Cryptography |
MalwareSagerunex | Sagerunex uses HTTPS for command and control communication. |
| T1573.002 Asymmetric Cryptography |
MalwareUroburos | Uroburos has used a combination of a Diffie-Hellman key exchange mixed with a pre-shared key (PSK) to encrypt its top layer of C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareMetamorfo | Metamorfo's C2 communication has been encrypted using OpenSSL. |
| T1573.002 Asymmetric Cryptography |
MalwareTrojan.Karagany | Trojan.Karagany can secure C2 communications with SSL and TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareAttor | Attor's Blowfish key is encrypted with a public RSA key. |
| T1573.002 Asymmetric Cryptography |
MalwareSodaMaster | SodaMaster can use a hardcoded RSA key to encrypt some of its C2 traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareGrandoreiro | Grandoreiro can use SSL in C2 communication. |
| T1573.002 Asymmetric Cryptography |
MalwareWellMail | WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareBazar | Bazar can use TLS in C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareKobalos | Kobalos's authentication and key exchange is performed using RSA-512. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.