Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.002 Asymmetric Cryptography |
MalwareHiddenFace | HiddenFace can use RSA-2048 in addition to symmetric algorithms in C2. |
| T1573.002 Asymmetric Cryptography |
MalwareZebrocy | Zebrocy uses SSL and AES ECB for encrypting C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareCobalt Strike | Cobalt Strike can use RSA asymmetric encryption with PKCS1 padding to encrypt data sent to the C2 server. |
| T1573.002 Asymmetric Cryptography |
MalwareServHelper | ServHelper may set up a reverse SSH tunnel to give the attacker access to services running on the victim, such as RDP. |
| T1573.002 Asymmetric Cryptography |
MalwareREvil | REvil has encrypted C2 communications with the ECIES algorithm. |
| T1573.002 Asymmetric Cryptography |
MalwareOilBooster | OilBooster can use the OpenSSL library to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareCyclops Blink | Cyclops Blink can encrypt C2 messages with AES-256-CBC sent underneath TLS. OpenSSL library functions are also used to encrypt each message using a randomly generated key and IV, which are then encrypted using a hard-coded RSA public key. |
| T1573.002 Asymmetric Cryptography |
MalwareCarbon | Carbon has used RSA encryption for C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareBISCUIT | BISCUIT uses SSL for encrypting C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareLAMEHUG | LAMEHUG can use SSH to transfer information to C2. |
| T1573.002 Asymmetric Cryptography |
MalwareMango | Mango can use TLS to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareGrimAgent | GrimAgent can use a hardcoded server public RSA key to encrypt the first request to C2. |
| T1573.002 Asymmetric Cryptography |
MalwarePoetRAT | PoetRAT used TLS to encrypt command and control (C2) communications. |
| T1573.002 Asymmetric Cryptography |
MalwareCHOPSTICK | CHOPSTICK encrypts C2 communications with TLS. |
| T1573.002 Asymmetric Cryptography |
MalwarePenquin | Penquin can encrypt communications using the BlowFish algorithm and a symmetric key exchanged with Diffie Hellman. |
| T1573.002 Asymmetric Cryptography |
MalwarePITSTOP | PITSTOP has the ability to communicate over TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareComRAT | ComRAT can use SSL/TLS encryption for its HTTP-based C2 channel. ComRAT has used public key cryptography with RSA and AES encrypted email attachments for its Gmail C2 channel. |
| T1573.002 Asymmetric Cryptography |
MalwareLunarWeb | LunarWeb can send short C2 commands, up to 512 bytes, encrypted with RSA-4096. |
| T1573.002 Asymmetric Cryptography |
MalwarePOWERSTATS | POWERSTATS has encrypted C2 traffic with RSA. |
| T1573.002 Asymmetric Cryptography |
MalwareDridex | Dridex has encrypted traffic with RSA. |
| T1573.002 Asymmetric Cryptography |
MalwareADVSTORESHELL | A variant of ADVSTORESHELL encrypts some C2 with RSA. |
| T1573.002 Asymmetric Cryptography |
MalwareSmall Sieve | Small Sieve can use SSL/TLS for its HTTPS Telegram Bot API-based C2 channel. |
| T1573.002 Asymmetric Cryptography |
ToolCovenant | Covenant can utilize SSL to encrypt command and control traffic. |
| T1573.002 Asymmetric Cryptography |
ToolSliver | Sliver can use mutual TLS and RSA cryptography to exchange a session key. |
| T1573.002 Asymmetric Cryptography |
ToolDCRAT | DCRAT can use certificate-based authentication for C2 servers. |
| T1573.002 Asymmetric Cryptography |
ToolEmpire | Empire can use TLS to encrypt its C2 channel. |
| T1573.002 Asymmetric Cryptography |
ToolFRP | FRP can be configured to only accept TLS connections. |
| T1573.002 Asymmetric Cryptography |
ToolRemcos | Remcos can use TLS to encrypt C2 communication. |
| T1573.002 Asymmetric Cryptography |
ToolKoadic | Koadic can use SSL and TLS for communications. |
| T1573.002 Asymmetric Cryptography |
ToolPupy | Pupy's default encryption for its C2 communication channel is SSL, but it also has transport options for RSA and AES. |
| T1573.002 Asymmetric Cryptography |
ToolMythic | Mythic supports SSL encrypted C2. |
| T1573.002 Asymmetric Cryptography |
ToolTor | Tor encapsulates traffic in multiple layers of encryption, using TLS by default. |
| T1573.002 Asymmetric Cryptography |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has encrypted collected data using a hybrid RSA-4096 and AES-256-encryption prior to exfiltration over 'curl`. |
| T1574 Hijack Execution Flow |
MalwareCOATHANGER | COATHANGER will remove and write malicious shared objects associated with legitimate system functions such as `read(2)`. |
| T1574 Hijack Execution Flow |
MalwareRaspberry Robin | Raspberry Robin will drop a copy of itself to a subfolder in |
| T1574 Hijack Execution Flow |
MalwareNightdoor | Nightdoor uses a legitimate executable to load a malicious DLL file for installation. |
| T1574 Hijack Execution Flow |
MalwareShimRat | ShimRat can hijack the cryptbase.dll within migwiz.exe to escalate privileges and bypass UAC controls. |
| T1574 Hijack Execution Flow |
MalwareDarkGate | DarkGate edits the Registry key |
| T1574 Hijack Execution Flow |
MalwareSaint Bot | Saint Bot will use the malicious file |
| T1574 Hijack Execution Flow |
MalwareSPAWNCHIMERA | SPAWNCHIMERA can persist across system upgrades by hijacking the execution flow of dspkginstall, a binary used during the system upgrade process. |
| T1574 Hijack Execution Flow |
MalwareDenis | Denis replaces the nonexistent Windows DLL "msfte.dll" with its own malicious version, which is loaded by the SearchIndexer.exe and SearchProtocolHost.exe. |
| T1574 Hijack Execution Flow |
MalwareDtrack | One of Dtrack can replace the normal flow of a program execution with malicious code. |
| T1574.001 DLL |
MalwareNinja | Ninja loaders can be side-loaded with legitimate and signed executables including the VLC.exe media player. |
| T1574.001 DLL |
MalwareRCSession | RCSession can be installed via DLL side-loading. |
| T1574.001 DLL |
MalwareIronWind | IronWind has used DLL sideloading for execution. |
| T1574.001 DLL |
MalwareDowndelph | Downdelph uses search order hijacking of the Windows executable sysprep.exe to escalate privileges. |
| T1574.001 DLL |
MalwareChinoxy | Chinoxy can use a digitally signed binary ("Logitech Bluetooth Wizard Host Process") to load its dll into memory. |
| T1574.001 DLL |
MalwarePAKLOG | PAKLOG has leveraged legitimate binaries to conduct DLL side-loading. |
| T1574.001 DLL |
MalwareRedLeaves | RedLeaves is launched through use of DLL search order hijacking to load a malicious dll. |
| T1574.001 DLL |
MalwareHavoc | Havoc has leveraged legitimate executables to side-load malicious payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.