Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1572 Protocol Tunneling |
ToolFRP | FRP can tunnel SSH and Unix Domain Socket communications over TCP between external nodes and exposed resources behind firewalls or NAT. |
| T1572 Protocol Tunneling |
ToolBrute Ratel C4 | Brute Ratel C4 can use DNS over HTTPS for C2. |
| T1572 Protocol Tunneling |
ToolMythic | Mythic can use SOCKS proxies to tunnel traffic through another protocol. |
| T1572 Protocol Tunneling |
MalwareDuqu | Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols. |
| T1573 Encrypted Channel |
CampaignKV Botnet Activity | KV Botnet Activity command and control activity includes transmission of an RSA public key in communication from the server, but this is followed by subsequent negotiation stages that represent a form of handshake similar to TLS negotiation. |
| T1573 Encrypted Channel |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used cryptcat binaries to encrypt their traffic. |
| T1573 Encrypted Channel |
GroupTropic Trooper | Tropic Trooper has encrypted traffic with the C2 to prevent network detection. |
| T1573 Encrypted Channel |
GroupBITTER | BITTER has encrypted their C2 communications. |
| T1573 Encrypted Channel |
GroupAPT29 | APT29 has used multiple layers of encryption within malware to protect C2 communication. |
| T1573 Encrypted Channel |
GroupMagic Hound | Magic Hound has used an encrypted http proxy in C2 communications. |
| T1573 Encrypted Channel |
MalwareRCSession | RCSession can use an encrypted beacon to check in with C2. |
| T1573 Encrypted Channel |
MalwareNETWIRE | NETWIRE can encrypt C2 communications. |
| T1573 Encrypted Channel |
MalwareGomir | Gomir uses a custom encryption algorithm for content sent to command and control infrastructure. |
| T1573 Encrypted Channel |
MalwareEmotet | Emotet has encrypted data before sending to the C2 server. |
| T1573 Encrypted Channel |
MalwarePowerLess | PowerLess can use an encrypted channel for C2 communications. |
| T1573 Encrypted Channel |
MalwareChaes | Chaes has used encryption for its C2 channel. |
| T1573 Encrypted Channel |
Malwaregh0st RAT | gh0st RAT has encrypted TCP communications to evade detection. |
| T1573 Encrypted Channel |
MalwareCryptoistic | Cryptoistic can engage in encrypted communications with C2. |
| T1573 Encrypted Channel |
MalwareMacMa | MacMa has used TLS encryption to initialize a custom protocol for C2 communications. |
| T1573 Encrypted Channel |
MalwarePowGoop | PowGoop can receive encrypted commands from C2. |
| T1573 Encrypted Channel |
MalwareLizar | Lizar can support encrypted communications between the client and server. |
| T1573.001 Symmetric Cryptography |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used an AES key to communicate with their C2 server. |
| T1573.001 Symmetric Cryptography |
CampaignFrankenstein | During Frankenstein, the threat actors communicated with C2 via an encrypted RC4 byte stream and AES-CBC. |
| T1573.001 Symmetric Cryptography |
CampaignRedPenguin | During RedPenguin, UNC3886 malware used the RC4 cipher to encrypt outgoing C2 messages. |
| T1573.001 Symmetric Cryptography |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL communication module supports three commands to conduct the following actions: send implant data, execute shellcode, and terminate itself. |
| T1573.001 Symmetric Cryptography |
GroupVolt Typhoon | Volt Typhoon has used a version of the Awen web shell that employed AES encryption and decryption for C2 communications. |
| T1573.001 Symmetric Cryptography |
GroupMuddyWater | MuddyWater has used AES to encrypt C2 responses. |
| T1573.001 Symmetric Cryptography |
GroupMustang Panda | Mustang Panda has encrypted C2 communications with RC4. Mustang Panda has also leveraged encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO. |
| T1573.001 Symmetric Cryptography |
GroupZIRCONIUM | ZIRCONIUM has used AES encrypted communications in C2. |
| T1573.001 Symmetric Cryptography |
GroupContagious Interview | Contagious Interview has encrypted C2 traffic using RC4. |
| T1573.001 Symmetric Cryptography |
GroupHigaisa | Higaisa used AES-128 to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
GroupRedCurl | RedCurl has used AES-128 CBC to encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
GroupStealth Falcon | Stealth Falcon malware encrypts C2 traffic using RC4 with a hard-coded key. |
| T1573.001 Symmetric Cryptography |
GroupBRONZE BUTLER | BRONZE BUTLER has used RC4 encryption (for Datper malware) and AES (for xxmm malware) to obfuscate HTTP traffic. BRONZE BUTLER has also used a tool called RarStar that encodes data with a custom XOR algorithm when posting it to a C2 server. |
| T1573.001 Symmetric Cryptography |
GroupDarkhotel | Darkhotel has used AES-256 and 3DES for C2 communications. |
| T1573.001 Symmetric Cryptography |
GroupAPT28 | APT28 installed a Delphi backdoor that used a custom algorithm for C2 communications. |
| T1573.001 Symmetric Cryptography |
GroupLazarus Group | Several Lazarus Group malware families encrypt C2 traffic using custom code that uses XOR with an ADD operation and XOR with a SUB operation. Another Lazarus Group malware sample XORs C2 traffic. Other Lazarus Group malware uses Caracachs encryption to encrypt C2 payloads. Lazarus Group has also used AES to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
GroupInception | Inception has encrypted network communications with AES. |
| T1573.001 Symmetric Cryptography |
GroupAPT33 | APT33 has used AES for encryption of command and control traffic. |
| T1573.001 Symmetric Cryptography |
MalwareTrickBot | TrickBot uses a custom crypter leveraging Microsoft’s CryptoAPI to encrypt C2 traffic.Newer versions of TrickBot have been known to use `bcrypt` to encrypt and digitally sign responses to their C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareBLINDINGCAN | BLINDINGCAN has encrypted its C2 traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareNinja | Ninja can XOR and AES encrypt C2 messages. |
| T1573.001 Symmetric Cryptography |
MalwarePikabot | Earlier Pikabot variants use a custom encryption procedure leveraging multiple mechanisms including AES with multiple rounds of Base64 encoding for its command and control communication. Later Pikabot variants eliminate the use of AES and instead use RC4 encryption for transmitted information. |
| T1573.001 Symmetric Cryptography |
MalwareBumblebee | Bumblebee can encrypt C2 requests and responses with RC4 |
| T1573.001 Symmetric Cryptography |
MalwareTorisma | Torisma has encrypted its C2 communications using XOR and VEST-32. |
| T1573.001 Symmetric Cryptography |
MalwareStuxnet | Stuxnet encodes the payload of system information sent to the command and control servers using a one byte 0xFF XOR key. Stuxnet also uses a 31-byte long static byte string to XOR data sent to command and control servers. The servers use a different static key to encrypt replies to the implant. |
| T1573.001 Symmetric Cryptography |
MalwareDowndelph | Downdelph uses RC4 to encrypt C2 responses. |
| T1573.001 Symmetric Cryptography |
MalwareRotaJakiro | RotaJakiro encrypts C2 communication using a combination of AES, XOR, ROTATE encryption, and ZLIB compression. |
| T1573.001 Symmetric Cryptography |
MalwareSardonic | Sardonic has the ability to use an RC4 key to encrypt communications to and from actor-controlled C2 servers. |
| T1573.001 Symmetric Cryptography |
MalwareEmissary | The C2 server response to a beacon sent by a variant of Emissary contains a 36-character GUID value that is used as an encryption key for subsequent network communications. Some variants of Emissary use various XOR operations to encrypt C2 data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.