Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560.002 Archive via Library |
MalwareBBSRAT | BBSRAT can compress data with ZLIB prior to sending it back to the C2 server. |
| T1560.002 Archive via Library |
MalwareSeaDuke | SeaDuke compressed data with zlib prior to sending it over C2. |
| T1560.002 Archive via Library |
MalwareEpic | Epic compresses the collected data with bzip2 before sending it to the C2 server. |
| T1560.002 Archive via Library |
MalwareFoggyWeb | FoggyWeb can invoke the `Common.Compress` method to compress data with the C# GZipStream compression class. |
| T1560.002 Archive via Library |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D scrambles and encrypts data using AES256 before sending it to the C2 server. |
| T1560.002 Archive via Library |
MalwareTajMahal | TajMahal has the ability to use the open source libraries XZip/Xunzip and zlib to compress files. |
| T1560.002 Archive via Library |
MalwareCardinal RAT | Cardinal RAT applies compression to C2 traffic using the ZLIB library. |
| T1560.002 Archive via Library |
MalwareFunnyDream | FunnyDream has compressed collected files with zLib. |
| T1560.002 Archive via Library |
MalwareLunarWeb | LunarWeb can zlib-compress data prior to exfiltration. |
| T1560.002 Archive via Library |
MalwareDenis | Denis compressed collected data using zlib. |
| T1560.002 Archive via Library |
GroupShinyHunters | ShinyHunters has used the following command to compress collected data: ` pv -s "$(du -sb exfil | awk '{print $1}')" | zstd -3 -T0 -o exfil.tar.zst `. |
| T1560.002 Archive via Library |
MalwareBADFLICK | BADFLICK has compressed data using the aPLib compression library. |
| T1560.003 Archive via Custom Method |
CampaignC0017 | During C0017, APT41 hex-encoded PII data prior to exfiltration. |
| T1560.003 Archive via Custom Method |
GroupKimsuky | Kimsuky has used RC4 encryption before exfil. |
| T1560.003 Archive via Custom Method |
GroupFIN6 | FIN6 has encoded data gathered from the victim with a simple substitution cipher and single-byte XOR using the 0xAA key, and Base64 with character permutation. |
| T1560.003 Archive via Custom Method |
GroupMustang Panda | Mustang Panda has encrypted documents with RC4 prior to exfiltration. |
| T1560.003 Archive via Custom Method |
GroupUNC3886 | UNC3886 has XOR encrypted and Gzip compressed captured credentials. |
| T1560.003 Archive via Custom Method |
GroupLotus Blossom | Lotus Blossom has used custom tools to compress and archive data on victim systems. |
| T1560.003 Archive via Custom Method |
GroupLazarus Group | A Lazarus Group malware sample encrypts data using a simple byte based XOR operation prior to exfiltration. |
| T1560.003 Archive via Custom Method |
GroupCopyKittens | CopyKittens encrypts data with a substitute cipher prior to exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareStuxnet | Stuxnet encrypts exfiltrated data via C2 with static 31-byte long XOR keys. |
| T1560.003 Archive via Custom Method |
MalwareHAWKBALL | HAWKBALL has encrypted data with XOR before sending it over the C2 channel. |
| T1560.003 Archive via Custom Method |
MalwareFrameworkPOS | FrameworkPOS can XOR credit card information before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareStrongPity | StrongPity can compress and encrypt archived files into multiple .sft files with a repeated xor encryption scheme. |
| T1560.003 Archive via Custom Method |
MalwareNETWIRE | NETWIRE has used a custom encryption algorithm to encrypt collected data. |
| T1560.003 Archive via Custom Method |
MalwareMachete | Machete's collected data is encrypted with AES before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareSquirrelwaffle | Squirrelwaffle has encrypted collected data using a XOR-based algorithm. |
| T1560.003 Archive via Custom Method |
MalwareAgent.btz | Agent.btz saves system information into an XML file that is then XOR-encoded. |
| T1560.003 Archive via Custom Method |
MalwareSombRAT | SombRAT has encrypted collected data with AES-256 using a hardcoded key. |
| T1560.003 Archive via Custom Method |
MalwareFLASHFLOOD | FLASHFLOOD employs the same encoding scheme as SPACESHIP for data it stages. Data is compressed with zlib, and bytes are rotated four times before being XOR'ed with 0x23. |
| T1560.003 Archive via Custom Method |
MalwareInvisiMole | InvisiMole uses a variation of the XOR cipher to encrypt files before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareOkrum | Okrum has used a custom implementation of AES encryption to encrypt collected data. |
| T1560.003 Archive via Custom Method |
MalwareRising Sun | Rising Sun can archive data using RC4 encryption and Base64 encoding prior to exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareReaver | Reaver encrypts collected data with an incremental XOR key prior to exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareFoggyWeb | FoggyWeb can use a dynamic XOR key and a custom XOR methodology to encode data before exfiltration. Also, FoggyWeb can encode C2 command output within a legitimate WebP file. |
| T1560.003 Archive via Custom Method |
MalwareT9000 | T9000 encrypts collected data using a single byte XOR key. |
| T1560.003 Archive via Custom Method |
MalwareSPACESHIP | Data SPACESHIP copies to the staging area is compressed with zlib. Bytes are rotated by four positions and XOR'ed with 0x23. |
| T1560.003 Archive via Custom Method |
MalwareBLUELIGHT | BLUELIGHT has encoded data into a binary blob using XOR. |
| T1560.003 Archive via Custom Method |
MalwareOopsIE | OopsIE compresses collected files with a simple character replacement scheme before sending them to its C2 server. |
| T1560.003 Archive via Custom Method |
MalwareAttor | Attor encrypts collected data with a custom implementation of Blowfish and RSA ciphers. |
| T1560.003 Archive via Custom Method |
MalwareRawPOS | RawPOS encodes credit card data it collected from the victim with XOR. |
| T1560.003 Archive via Custom Method |
MalwareMESSAGETAP | MESSAGETAP has XOR-encrypted and stored contents of SMS messages that matched its target list. |
| T1560.003 Archive via Custom Method |
MalwareSUGARDUMP | SUGARDUMP has encrypted collected data using AES CBC mode and encoded it using Base64. |
| T1560.003 Archive via Custom Method |
MalwareOwaAuth | OwaAuth DES-encrypts captured credentials using the key 12345678 before writing the credentials to a log file. |
| T1560.003 Archive via Custom Method |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has used AES in CBC mode to encrypt collected data when saving that data to disk. |
| T1560.003 Archive via Custom Method |
MalwareRGDoor | RGDoor encrypts files with XOR before sending them back to the C2 server. |
| T1560.003 Archive via Custom Method |
MalwareRamsay | Ramsay can store collected documents in a custom container after encrypting and compressing them using RC4 and WinRAR. |
| T1560.003 Archive via Custom Method |
MalwareFunnyDream | FunnyDream has compressed collected files with zLib and encrypted them using an XOR operation with the string key from the command line or `qwerasdf` if the command line argument doesn’t contain the key. File names are obfuscated using XOR with the same key as the compressed file content. |
| T1560.003 Archive via Custom Method |
MalwaremetaMain | metaMain has used XOR-based encryption for collected files before exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareADVSTORESHELL | ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.