Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1559.002 Dynamic Data Exchange |
MalwareRamsay | Ramsay has been delivered using OLE objects in malicious documents. |
| T1559.002 Dynamic Data Exchange |
MalwarePoetRAT | PoetRAT was delivered with documents using DDE to execute malicious code. |
| T1559.002 Dynamic Data Exchange |
MalwarePOWERSTATS | POWERSTATS can use DDE to execute additional payloads on compromised hosts. |
| T1560 Archive Collected Data |
GroupBlackByte | BlackByte compressed data collected from victim environments prior to exfiltration. |
| T1560 Archive Collected Data |
GroupPatchwork | Patchwork encrypted the collected files' path with AES and then encoded them with base64. |
| T1560 Archive Collected Data |
GroupDragonfly | Dragonfly has compressed data into .zip files prior to exfiltration. |
| T1560 Archive Collected Data |
GroupmenuPass | menuPass has encrypted files and information before exfiltration. |
| T1560 Archive Collected Data |
GroupAPT32 | APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration. |
| T1560 Archive Collected Data |
GroupFIN6 | Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration. |
| T1560 Archive Collected Data |
GroupKe3chang | The Ke3chang group has been known to compress data before exfiltration. |
| T1560 Archive Collected Data |
GroupLeviathan | Leviathan has archived victim's data prior to exfiltration. |
| T1560 Archive Collected Data |
GroupAxiom | Axiom has compressed and encrypted data prior to exfiltration. |
| T1560 Archive Collected Data |
GroupEmber Bear | Ember Bear has compressed collected data prior to exfiltration. |
| T1560 Archive Collected Data |
GroupLuminousMoth | LuminousMoth has manually archived stolen files from victim machines before exfiltration. |
| T1560 Archive Collected Data |
GroupAPT28 | APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. |
| T1560 Archive Collected Data |
GroupLazarus Group | Lazarus Group has compressed exfiltrated data with RAR and used RomeoDelta malware to archive specified directories in .zip format, encrypt the .zip file, and upload it to C2. |
| T1560 Archive Collected Data |
MalwareBumblebee | Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration. |
| T1560 Archive Collected Data |
MalwareExaramel for Windows | Exaramel for Windows automatically encrypts files before sending them to the C2 server. |
| T1560 Archive Collected Data |
MalwareJumbledPath | JumbledPath can compress and encrypt exfiltrated packet captures from targeted devices. |
| T1560 Archive Collected Data |
MalwareBackdoor.Oldrea | Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server. |
| T1560 Archive Collected Data |
MalwareLurid | Lurid can compress data before sending it. |
| T1560 Archive Collected Data |
MalwareAppleSeed | AppleSeed has compressed collected data before exfiltration. |
| T1560 Archive Collected Data |
MalwareNETWIRE | NETWIRE has the ability to compress archived screenshots. |
| T1560 Archive Collected Data |
MalwareAria-body | Aria-body has used ZIP to compress data gathered on a compromised host. |
| T1560 Archive Collected Data |
MalwareMachete | Machete stores zipped files with profile data from installed web browsers. |
| T1560 Archive Collected Data |
MalwarePowerLess | PowerLess can encrypt browser database files prior to exfiltration. |
| T1560 Archive Collected Data |
MalwarePrikormka | After collecting documents from removable media, Prikormka compresses the collected files, and encrypts it with Blowfish. |
| T1560 Archive Collected Data |
MalwareLoFiSe | LoFiSe can collect files into password-protected ZIP-archives for exfiltration. |
| T1560 Archive Collected Data |
MalwareVERMIN | VERMIN encrypts the collected files using 3-DES. |
| T1560 Archive Collected Data |
MalwareChrommme | Chrommme can encrypt and store on disk collected data before exfiltration. |
| T1560 Archive Collected Data |
MalwareRunningRAT | RunningRAT contains code to compress files. |
| T1560 Archive Collected Data |
MalwareEpic | Epic encrypts collected data using a public key framework before sending it over the C2 channel. Some variants encrypt the collected data with AES and encode it with base64 before transmitting it to the C2 server. |
| T1560 Archive Collected Data |
MalwareLightNeuron | LightNeuron contains a function to encrypt and store emails that it collects. |
| T1560 Archive Collected Data |
MalwareMuddyViper | MuddyViper has archived collected web browser data into a file named CacheDump.zip. |
| T1560 Archive Collected Data |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE has used |
| T1560 Archive Collected Data |
MalwareLP-Notes | LP-Notes has encrypted collected credentials using AES-CBC from the CNG API and the key ED15C8344B45DAED1E0578F8BC1A32411812C61F4CB45D89B107287DE0E09FFC |
| T1560 Archive Collected Data |
MalwareSpica | Spica can archive collected documents for exfiltration. |
| T1560 Archive Collected Data |
MalwareKONNI | KONNI has encrypted data and files prior to exfiltration. |
| T1560 Archive Collected Data |
MalwareBLUELIGHT | BLUELIGHT can zip files before exfiltration. |
| T1560 Archive Collected Data |
MalwareWellMail | WellMail can archive files on the compromised host. |
| T1560 Archive Collected Data |
MalwareZebrocy | Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration. |
| T1560 Archive Collected Data |
MalwareCadelspy | Cadelspy has the ability to compress stolen data into a .cab file. |
| T1560 Archive Collected Data |
MalwareRaccoon Stealer | Raccoon Stealer archives collected system information in a text f ile, `System info.txt`, prior to exfiltration. |
| T1560 Archive Collected Data |
MalwareDaserf | Daserf hides collected data in password-protected .rar archives. |
| T1560 Archive Collected Data |
MalwareGold Dragon | Gold Dragon encrypts data using Base64 before being sent to the command and control server. |
| T1560 Archive Collected Data |
MalwarePillowmint | Pillowmint has encrypted stolen credit card information with AES and further encoded it with Base64. |
| T1560 Archive Collected Data |
MalwareProton | Proton zips up files before exfiltrating them. |
| T1560 Archive Collected Data |
MalwareKessel | Kessel can RC4-encrypt credentials before sending to the C2. |
| T1560 Archive Collected Data |
MalwareFELIXROOT | FELIXROOT encrypts collected data with AES and Base64 and then sends it to the C2 server. |
| T1560 Archive Collected Data |
MalwareTroll Stealer | Troll Stealer compresses stolen data prior to exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.