ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1573.001
Symmetric Cryptography
ToolQuasarRAT

QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication.

T1573.001
Symmetric Cryptography
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has encrypted collected data using a hybrid AES-256 and RSA-4096 encryption prior to exfiltration over 'curl`.

T1573.001
Symmetric Cryptography
MalwareDuqu

The Duqu command and control protocol's data stream can be encrypted with AES-CBC.

T1573.002
Asymmetric Cryptography
MalwareBRICKSTORM

BRICKSTORM has communicated with C2 infrastructure via TLS.

T1573.002
Asymmetric Cryptography
MalwareNICECURL

NICECURL has used HTTPS for C2 communications.

T1573.002
Asymmetric Cryptography
MalwareCOATHANGER

COATHANGER connects to command and control infrastructure using SSL.

T1573.002
Asymmetric Cryptography
MalwareSardonic

Sardonic has the ability to send a random 64-byte RC4 key to communicate with actor-controlled C2 servers by using an RSA public key.

T1573.002
Asymmetric Cryptography
Malwareadbupd

adbupd contains a copy of the OpenSSL library to encrypt C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareCASTLETAP

CASTLETAP can initiate a C2 connection over an SSL socket.

T1573.002
Asymmetric Cryptography
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can communicate over SSL using the private key from the Ivanti Connect Secure web server.

T1573.002
Asymmetric Cryptography
MalwareStrongPity

StrongPity has encrypted C2 traffic using SSL/TLS.

T1573.002
Asymmetric Cryptography
MalwareTinyTurla

TinyTurla has the ability to encrypt C2 traffic with SSL/TLS.

T1573.002
Asymmetric Cryptography
MalwareJ-magic

J-magic can communicate back to send a challenge to C2 infrastructure over SSL.

T1573.002
Asymmetric Cryptography
MalwareGreyEnergy

GreyEnergy encrypts communications using RSA-2048.

T1573.002
Asymmetric Cryptography
MalwareGomir

Gomir uses reverse proxy functionality that employs SSL to encrypt communications.

T1573.002
Asymmetric Cryptography
MalwareBOLDMOVE

BOLDMOVE uses the WolfSSL library to implement SSL encryption for command and control communication.

T1573.002
Asymmetric Cryptography
MalwareBADHATCH

BADHATCH can beacon to a hardcoded C2 IP address using TLS encryption every 5 minutes.

T1573.002
Asymmetric Cryptography
MalwareMachete

Machete has used TLS-encrypted FTP to exfiltrate data.

T1573.002
Asymmetric Cryptography
MalwareWellMess

WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates.

T1573.002
Asymmetric Cryptography
MalwareWoody RAT

Woody RAT can use RSA-4096 to encrypt data sent to its C2 server.

T1573.002
Asymmetric Cryptography
MalwareSombRAT

SombRAT can SSL encrypt C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareVolgmer

Some Volgmer variants use SSL to encrypt C2 communications.

T1573.002
Asymmetric Cryptography
MalwareMispadu

Mispadu contains a copy of the OpenSSL library to encrypt C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareREPTILE

REPTILE can use TLS over raw TCP for secure C2.

T1573.002
Asymmetric Cryptography
MalwareDoki

Doki has used the embedTLS library for network communications.

T1573.002
Asymmetric Cryptography
MalwareIcedID

IcedID has used SSL and TLS in communications with C2.

T1573.002
Asymmetric Cryptography
MalwareRising Sun

Rising Sun variants can use SSL for encrypting C2 communications.

T1573.002
Asymmetric Cryptography
MalwareHi-Zor

Hi-Zor encrypts C2 traffic with TLS.

T1573.002
Asymmetric Cryptography
MalwareSnappyTCP

SnappyTCP can use OpenSSL and TLS certificates to encrypt traffic.

T1573.002
Asymmetric Cryptography
MalwareGoldMax

GoldMax has RSA-encrypted its communication with the C2 server.

T1573.002
Asymmetric Cryptography
MalwarePOSHSPY

POSHSPY encrypts C2 traffic with AES and RSA.

T1573.002
Asymmetric Cryptography
MalwareDarkWatchman

DarkWatchman can use TLS to encrypt its C2 channel.

T1573.002
Asymmetric Cryptography
MalwareLumma Stealer

Lumma Stealer has used HTTPS for command and control purposes.

T1573.002
Asymmetric Cryptography
MalwareSykipot

Sykipot uses SSL for encrypting C2 communications.

T1573.002
Asymmetric Cryptography
MalwareKEYPLUG

KEYPLUG can use TLS-encrypted WebSocket Protocol (WSS) for C2.

T1573.002
Asymmetric Cryptography
MalwarePureCrypter

PureCrypter can send a TLS 1.2 encrypted infection message via Discord webhook.

T1573.002
Asymmetric Cryptography
MalwareXTunnel

XTunnel uses SSL/TLS and RC4 to encrypt traffic.

T1573.002
Asymmetric Cryptography
MalwareWannaCry

WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit.

T1573.002
Asymmetric Cryptography
MalwareGazer

Gazer uses custom encryption for C2 that uses RSA.

T1573.002
Asymmetric Cryptography
MalwarePay2Key

Pay2Key has used RSA encrypted communications with C2.

T1573.002
Asymmetric Cryptography
MalwareSagerunex

Sagerunex uses HTTPS for command and control communication.

T1573.002
Asymmetric Cryptography
MalwareUroburos

Uroburos has used a combination of a Diffie-Hellman key exchange mixed with a pre-shared key (PSK) to encrypt its top layer of C2 communications.

T1573.002
Asymmetric Cryptography
MalwareMetamorfo

Metamorfo's C2 communication has been encrypted using OpenSSL.

T1573.002
Asymmetric Cryptography
MalwareTrojan.Karagany

Trojan.Karagany can secure C2 communications with SSL and TLS.

T1573.002
Asymmetric Cryptography
MalwareAttor

Attor's Blowfish key is encrypted with a public RSA key.

T1573.002
Asymmetric Cryptography
MalwareSodaMaster

SodaMaster can use a hardcoded RSA key to encrypt some of its C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareGrandoreiro

Grandoreiro can use SSL in C2 communication.

T1573.002
Asymmetric Cryptography
MalwareWellMail

WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS.

T1573.002
Asymmetric Cryptography
MalwareBazar

Bazar can use TLS in C2 communications.

T1573.002
Asymmetric Cryptography
MalwareKobalos

Kobalos's authentication and key exchange is performed using RSA-512.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.