ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1559.002
Dynamic Data Exchange
MalwareRamsay

Ramsay has been delivered using OLE objects in malicious documents.

T1559.002
Dynamic Data Exchange
MalwarePoetRAT

PoetRAT was delivered with documents using DDE to execute malicious code.

T1559.002
Dynamic Data Exchange
MalwarePOWERSTATS

POWERSTATS can use DDE to execute additional payloads on compromised hosts.

T1560
Archive Collected Data
GroupBlackByte

BlackByte compressed data collected from victim environments prior to exfiltration.

T1560
Archive Collected Data
GroupPatchwork

Patchwork encrypted the collected files' path with AES and then encoded them with base64.

T1560
Archive Collected Data
GroupDragonfly

Dragonfly has compressed data into .zip files prior to exfiltration.

T1560
Archive Collected Data
GroupmenuPass

menuPass has encrypted files and information before exfiltration.

T1560
Archive Collected Data
GroupAPT32

APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration.

T1560
Archive Collected Data
GroupFIN6

Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration.

T1560
Archive Collected Data
GroupKe3chang

The Ke3chang group has been known to compress data before exfiltration.

T1560
Archive Collected Data
GroupLeviathan

Leviathan has archived victim's data prior to exfiltration.

T1560
Archive Collected Data
GroupAxiom

Axiom has compressed and encrypted data prior to exfiltration.

T1560
Archive Collected Data
GroupEmber Bear

Ember Bear has compressed collected data prior to exfiltration.

T1560
Archive Collected Data
GroupLuminousMoth

LuminousMoth has manually archived stolen files from victim machines before exfiltration.

T1560
Archive Collected Data
GroupAPT28

APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks.

T1560
Archive Collected Data
GroupLazarus Group

Lazarus Group has compressed exfiltrated data with RAR and used RomeoDelta malware to archive specified directories in .zip format, encrypt the .zip file, and upload it to C2.

T1560
Archive Collected Data
MalwareBumblebee

Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration.

T1560
Archive Collected Data
MalwareExaramel for Windows

Exaramel for Windows automatically encrypts files before sending them to the C2 server.

T1560
Archive Collected Data
MalwareJumbledPath

JumbledPath can compress and encrypt exfiltrated packet captures from targeted devices.

T1560
Archive Collected Data
MalwareBackdoor.Oldrea

Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server.

T1560
Archive Collected Data
MalwareLurid

Lurid can compress data before sending it.

T1560
Archive Collected Data
MalwareAppleSeed

AppleSeed has compressed collected data before exfiltration.

T1560
Archive Collected Data
MalwareNETWIRE

NETWIRE has the ability to compress archived screenshots.

T1560
Archive Collected Data
MalwareAria-body

Aria-body has used ZIP to compress data gathered on a compromised host.

T1560
Archive Collected Data
MalwareMachete

Machete stores zipped files with profile data from installed web browsers.

T1560
Archive Collected Data
MalwarePowerLess

PowerLess can encrypt browser database files prior to exfiltration.

T1560
Archive Collected Data
MalwarePrikormka

After collecting documents from removable media, Prikormka compresses the collected files, and encrypts it with Blowfish.

T1560
Archive Collected Data
MalwareLoFiSe

LoFiSe can collect files into password-protected ZIP-archives for exfiltration.

T1560
Archive Collected Data
MalwareVERMIN

VERMIN encrypts the collected files using 3-DES.

T1560
Archive Collected Data
MalwareChrommme

Chrommme can encrypt and store on disk collected data before exfiltration.

T1560
Archive Collected Data
MalwareRunningRAT

RunningRAT contains code to compress files.

T1560
Archive Collected Data
MalwareEpic

Epic encrypts collected data using a public key framework before sending it over the C2 channel. Some variants encrypt the collected data with AES and encode it with base64 before transmitting it to the C2 server.

T1560
Archive Collected Data
MalwareLightNeuron

LightNeuron contains a function to encrypt and store emails that it collects.

T1560
Archive Collected Data
MalwareMuddyViper

MuddyViper has archived collected web browser data into a file named CacheDump.zip.

T1560
Archive Collected Data
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE has used FileReadZipSend to compress a file and send to C2.

T1560
Archive Collected Data
MalwareLP-Notes

LP-Notes has encrypted collected credentials using AES-CBC from the CNG API and the key ED15C8344B45DAED1E0578F8BC1A32411812C61F4CB45D89B107287DE0E09FFC
and the initialization vector 91A4E6F6D51DAEE773A8F00279792578.

T1560
Archive Collected Data
MalwareSpica

Spica can archive collected documents for exfiltration.

T1560
Archive Collected Data
MalwareKONNI

KONNI has encrypted data and files prior to exfiltration.

T1560
Archive Collected Data
MalwareBLUELIGHT

BLUELIGHT can zip files before exfiltration.

T1560
Archive Collected Data
MalwareWellMail

WellMail can archive files on the compromised host.

T1560
Archive Collected Data
MalwareZebrocy

Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration.

T1560
Archive Collected Data
MalwareCadelspy

Cadelspy has the ability to compress stolen data into a .cab file.

T1560
Archive Collected Data
MalwareRaccoon Stealer

Raccoon Stealer archives collected system information in a text f ile, `System info.txt`, prior to exfiltration.

T1560
Archive Collected Data
MalwareDaserf

Daserf hides collected data in password-protected .rar archives.

T1560
Archive Collected Data
MalwareGold Dragon

Gold Dragon encrypts data using Base64 before being sent to the command and control server.

T1560
Archive Collected Data
MalwarePillowmint

Pillowmint has encrypted stolen credit card information with AES and further encoded it with Base64.

T1560
Archive Collected Data
MalwareProton

Proton zips up files before exfiltrating them.

T1560
Archive Collected Data
MalwareKessel

Kessel can RC4-encrypt credentials before sending to the C2.

T1560
Archive Collected Data
MalwareFELIXROOT

FELIXROOT encrypts collected data with AES and Base64 and then sends it to the C2 server.

T1560
Archive Collected Data
MalwareTroll Stealer

Troll Stealer compresses stolen data prior to exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.