Real-world descriptions of how a group, tool or campaign used a technique.
167 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.001 Symmetric Cryptography |
MalwareSodaMaster | SodaMaster can use RC4 to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareHikit | Hikit performs XOR encryption. |
| T1573.001 Symmetric Cryptography |
MalwareSakula | Sakula encodes C2 traffic with single-byte XOR keys. |
| T1573.001 Symmetric Cryptography |
MalwareBazar | Bazar can send C2 communications with XOR encryption. |
| T1573.001 Symmetric Cryptography |
MalwareKobalos | Kobalos's post-authentication communication channel uses a 32-byte-long password with RC4 for inbound and outbound traffic. |
| T1573.001 Symmetric Cryptography |
MalwareBADCALL | BADCALL encrypts C2 traffic using an XOR/ADD cipher. |
| T1573.001 Symmetric Cryptography |
MalwareMoonWind | MoonWind encrypts C2 traffic using RC4 with a static key. |
| T1573.001 Symmetric Cryptography |
MalwareHiddenFace | HiddenFace can use a randomly selected symmetric encryption algorithm for C2. |
| T1573.001 Symmetric Cryptography |
MalwarePandora | Pandora has the ability to encrypt communications with D3DES. |
| T1573.001 Symmetric Cryptography |
MalwareCobalt Strike | Cobalt Strike has the ability to use AES-256 symmetric encryption in CBC mode with HMAC-SHA-256 to encrypt task commands and XOR to encrypt shell code and configuration data. |
| T1573.001 Symmetric Cryptography |
MalwareSUNBURST | SUNBURST encrypted C2 traffic using a single-byte-XOR cipher. |
| T1573.001 Symmetric Cryptography |
MalwareHotCroissant | HotCroissant has compressed network communications and encrypted them with a custom stream cipher. |
| T1573.001 Symmetric Cryptography |
MalwareRIPTIDE | APT12 has used the RIPTIDE RAT, which communicates over HTTP with a payload encrypted with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareSamurai | Samurai can encrypt C2 communications with AES. |
| T1573.001 Symmetric Cryptography |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D encrypts data sent back to the C2 using AES in CBC mode with a null initialization vector (IV) and a key sent from the server that is padded to 32 bytes. |
| T1573.001 Symmetric Cryptography |
MalwareTaidoor | Taidoor uses RC4 to encrypt the message body of HTTP content. |
| T1573.001 Symmetric Cryptography |
MalwarePoisonIvy | PoisonIvy uses the Camellia cipher to encrypt communications. |
| T1573.001 Symmetric Cryptography |
MalwareNanoCore | NanoCore uses DES to encrypt the C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwarePLEAD | PLEAD has used RC4 encryption to download modules. |
| T1573.001 Symmetric Cryptography |
MalwareDaserf | Daserf uses RC4 encryption to obfuscate HTTP traffic. |
| T1573.001 Symmetric Cryptography |
MalwareCardinal RAT | Cardinal RAT uses a secret key with a series of XOR and addition operations to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareSolar | Solar can XOR encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareFakeM | The original variant of FakeM encrypts C2 traffic using a custom encryption cipher that uses an XOR key of “YHCRA” and bit rotation between each XOR operation. Some variants of FakeM use RC4 to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareMore_eggs | More_eggs has used an RC4-based encryption method for its C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareSysUpdate | SysUpdate has used DES to encrypt all C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareMango | Mango can receive XOR-encrypted commands from C2. |
| T1573.001 Symmetric Cryptography |
MalwareWIREFIRE | WIREFIRE can AES encrypt process output sent from compromised devices to C2. |
| T1573.001 Symmetric Cryptography |
MalwareGrimAgent | GrimAgent can use an AES key to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareLookBack | LookBack uses a modified version of RC4 for data transfer. |
| T1573.001 Symmetric Cryptography |
MalwareCallMe | CallMe uses AES to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareCHOPSTICK | CHOPSTICK encrypts C2 communications with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareRIFLESPINE | RIFLESPINE can use the AES algorithm to encrypt C2 data. |
| T1573.001 Symmetric Cryptography |
MalwareSLIGHTPULSE | SLIGHTPULSE can RC4 encrypt all incoming and outgoing C2 messages. |
| T1573.001 Symmetric Cryptography |
MalwareNDiskMonitor | NDiskMonitor uses AES to encrypt certain information sent over its C2 channel. |
| T1573.001 Symmetric Cryptography |
MalwareWinnti for Windows | Winnti for Windows can XOR encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareTroll Stealer | Troll Stealer encrypts data sent to command and control infrastructure using a combination of RC4 and RSA-4096 algorithms. |
| T1573.001 Symmetric Cryptography |
MalwareEbury | Ebury has encrypted C2 traffic using the client IP address, then encoded it as a hexadecimal string. |
| T1573.001 Symmetric Cryptography |
MalwareZIPLINE | ZIPLINE can use AES-128-CBC to encrypt data for both upload and download. |
| T1573.001 Symmetric Cryptography |
MalwareChChes | ChChes can encrypt C2 traffic with AES or RC4. |
| T1573.001 Symmetric Cryptography |
MalwareIceApple | The IceApple Result Retriever module can AES encrypt C2 responses. |
| T1573.001 Symmetric Cryptography |
MalwaremetaMain | metaMain can encrypt the data that it sends and receives from the C2 server using an RC4 encryption algorithm. |
| T1573.001 Symmetric Cryptography |
MalwareSideTwist | SideTwist can encrypt C2 communications with a randomly generated key. |
| T1573.001 Symmetric Cryptography |
MalwareLunarWeb | LunarWeb can send AES encrypted C2 commands. |
| T1573.001 Symmetric Cryptography |
MalwareXCSSET | XCSSET uses RC4 encryption over TCP to communicate with its C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareDipsind | Dipsind encrypts C2 data with AES256 in ECB mode. |
| T1573.001 Symmetric Cryptography |
Malwarehttpclient | httpclient encrypts C2 content with XOR using a single byte, 0x12. |
| T1573.001 Symmetric Cryptography |
MalwarePOWERTON | POWERTON has used AES for encrypting C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareStarProxy | StarProxy has leveraged two 256-byte XOR keys to encrypt and decrypt network packets using a custom algorithm. |
| T1573.001 Symmetric Cryptography |
MalwareBADNEWS | BADNEWS encrypts C2 data with a ROR by 3 and an XOR by 0x23. |
| T1573.001 Symmetric Cryptography |
MalwareQakBot | QakBot can RC4 encrypt strings in C2 communication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.