ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1573.001×

167 examples

TechniqueUsed byProcedure example
T1573.001
Symmetric Cryptography
MalwareSodaMaster

SodaMaster can use RC4 to encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareHikit

Hikit performs XOR encryption.

T1573.001
Symmetric Cryptography
MalwareSakula

Sakula encodes C2 traffic with single-byte XOR keys.

T1573.001
Symmetric Cryptography
MalwareBazar

Bazar can send C2 communications with XOR encryption.

T1573.001
Symmetric Cryptography
MalwareKobalos

Kobalos's post-authentication communication channel uses a 32-byte-long password with RC4 for inbound and outbound traffic.

T1573.001
Symmetric Cryptography
MalwareBADCALL

BADCALL encrypts C2 traffic using an XOR/ADD cipher.

T1573.001
Symmetric Cryptography
MalwareMoonWind

MoonWind encrypts C2 traffic using RC4 with a static key.

T1573.001
Symmetric Cryptography
MalwareHiddenFace

HiddenFace can use a randomly selected symmetric encryption algorithm for C2.

T1573.001
Symmetric Cryptography
MalwarePandora

Pandora has the ability to encrypt communications with D3DES.

T1573.001
Symmetric Cryptography
MalwareCobalt Strike

Cobalt Strike has the ability to use AES-256 symmetric encryption in CBC mode with HMAC-SHA-256 to encrypt task commands and XOR to encrypt shell code and configuration data.

T1573.001
Symmetric Cryptography
MalwareSUNBURST

SUNBURST encrypted C2 traffic using a single-byte-XOR cipher.

T1573.001
Symmetric Cryptography
MalwareHotCroissant

HotCroissant has compressed network communications and encrypted them with a custom stream cipher.

T1573.001
Symmetric Cryptography
MalwareRIPTIDE

APT12 has used the RIPTIDE RAT, which communicates over HTTP with a payload encrypted with RC4.

T1573.001
Symmetric Cryptography
MalwareSamurai

Samurai can encrypt C2 communications with AES.

T1573.001
Symmetric Cryptography
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D encrypts data sent back to the C2 using AES in CBC mode with a null initialization vector (IV) and a key sent from the server that is padded to 32 bytes.

T1573.001
Symmetric Cryptography
MalwareTaidoor

Taidoor uses RC4 to encrypt the message body of HTTP content.

T1573.001
Symmetric Cryptography
MalwarePoisonIvy

PoisonIvy uses the Camellia cipher to encrypt communications.

T1573.001
Symmetric Cryptography
MalwareNanoCore

NanoCore uses DES to encrypt the C2 traffic.

T1573.001
Symmetric Cryptography
MalwarePLEAD

PLEAD has used RC4 encryption to download modules.

T1573.001
Symmetric Cryptography
MalwareDaserf

Daserf uses RC4 encryption to obfuscate HTTP traffic.

T1573.001
Symmetric Cryptography
MalwareCardinal RAT

Cardinal RAT uses a secret key with a series of XOR and addition operations to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareSolar

Solar can XOR encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareFakeM

The original variant of FakeM encrypts C2 traffic using a custom encryption cipher that uses an XOR key of “YHCRA” and bit rotation between each XOR operation. Some variants of FakeM use RC4 to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareMore_eggs

More_eggs has used an RC4-based encryption method for its C2 communications.

T1573.001
Symmetric Cryptography
MalwareSysUpdate

SysUpdate has used DES to encrypt all C2 communications.

T1573.001
Symmetric Cryptography
MalwareMango

Mango can receive XOR-encrypted commands from C2.

T1573.001
Symmetric Cryptography
MalwareWIREFIRE

WIREFIRE can AES encrypt process output sent from compromised devices to C2.

T1573.001
Symmetric Cryptography
MalwareGrimAgent

GrimAgent can use an AES key to encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareLookBack

LookBack uses a modified version of RC4 for data transfer.

T1573.001
Symmetric Cryptography
MalwareCallMe

CallMe uses AES to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareCHOPSTICK

CHOPSTICK encrypts C2 communications with RC4.

T1573.001
Symmetric Cryptography
MalwareRIFLESPINE

RIFLESPINE can use the AES algorithm to encrypt C2 data.

T1573.001
Symmetric Cryptography
MalwareSLIGHTPULSE

SLIGHTPULSE can RC4 encrypt all incoming and outgoing C2 messages.

T1573.001
Symmetric Cryptography
MalwareNDiskMonitor

NDiskMonitor uses AES to encrypt certain information sent over its C2 channel.

T1573.001
Symmetric Cryptography
MalwareWinnti for Windows

Winnti for Windows can XOR encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareTroll Stealer

Troll Stealer encrypts data sent to command and control infrastructure using a combination of RC4 and RSA-4096 algorithms.

T1573.001
Symmetric Cryptography
MalwareEbury

Ebury has encrypted C2 traffic using the client IP address, then encoded it as a hexadecimal string.

T1573.001
Symmetric Cryptography
MalwareZIPLINE

ZIPLINE can use AES-128-CBC to encrypt data for both upload and download.

T1573.001
Symmetric Cryptography
MalwareChChes

ChChes can encrypt C2 traffic with AES or RC4.

T1573.001
Symmetric Cryptography
MalwareIceApple

The IceApple Result Retriever module can AES encrypt C2 responses.

T1573.001
Symmetric Cryptography
MalwaremetaMain

metaMain can encrypt the data that it sends and receives from the C2 server using an RC4 encryption algorithm.

T1573.001
Symmetric Cryptography
MalwareSideTwist

SideTwist can encrypt C2 communications with a randomly generated key.

T1573.001
Symmetric Cryptography
MalwareLunarWeb

LunarWeb can send AES encrypted C2 commands.

T1573.001
Symmetric Cryptography
MalwareXCSSET

XCSSET uses RC4 encryption over TCP to communicate with its C2 server.

T1573.001
Symmetric Cryptography
MalwareDipsind

Dipsind encrypts C2 data with AES256 in ECB mode.

T1573.001
Symmetric Cryptography
Malwarehttpclient

httpclient encrypts C2 content with XOR using a single byte, 0x12.

T1573.001
Symmetric Cryptography
MalwarePOWERTON

POWERTON has used AES for encrypting C2 traffic.

T1573.001
Symmetric Cryptography
MalwareStarProxy

StarProxy has leveraged two 256-byte XOR keys to encrypt and decrypt network packets using a custom algorithm.

T1573.001
Symmetric Cryptography
MalwareBADNEWS

BADNEWS encrypts C2 data with a ROR by 3 and an XOR by 0x23.

T1573.001
Symmetric Cryptography
MalwareQakBot

QakBot can RC4 encrypt strings in C2 communication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.