Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.001 Symmetric Cryptography |
MalwareFALLCHILL | FALLCHILL encrypts C2 data with RC4 encryption. |
| T1573.001 Symmetric Cryptography |
ToolSliver | Sliver can use AES-GCM-256 to encrypt a session key for C2 message exchange. |
| T1573.001 Symmetric Cryptography |
ToolFRP | FRP can use STCP (Secret TCP) with a preshared key to encrypt services exposed to public networks. |
| T1573.001 Symmetric Cryptography |
ToolQuasarRAT | QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication. |
| T1573.001 Symmetric Cryptography |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has encrypted collected data using a hybrid AES-256 and RSA-4096 encryption prior to exfiltration over 'curl`. |
| T1573.001 Symmetric Cryptography |
MalwareDuqu | The Duqu command and control protocol's data stream can be encrypted with AES-CBC. |
| T1573.002 Asymmetric Cryptography |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used SSL for network communication. |
| T1573.002 Asymmetric Cryptography |
CampaignC0021 | During C0021, the threat actors used SSL via TCP port 443 for C2 communications. |
| T1573.002 Asymmetric Cryptography |
CampaignAPT41 DUST | APT41 DUST used HTTPS for command and control. |
| T1573.002 Asymmetric Cryptography |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used HTTPS for command and control of compromised Versa Director servers. |
| T1573.002 Asymmetric Cryptography |
CampaignOperation Wocao | During Operation Wocao, threat actors' proxy implementation "Agent" upgraded the socket in use to a TLS socket. |
| T1573.002 Asymmetric Cryptography |
GroupFIN6 | FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupRedEcho | RedEcho uses SSL for network communication. |
| T1573.002 Asymmetric Cryptography |
GroupTA2541 | TA2541 has used TLS encrypted C2 communications including for campaigns using AsyncRAT. |
| T1573.002 Asymmetric Cryptography |
GroupOilRig | OilRig used the PowerExchange utility and other tools to create tunnels to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupTropic Trooper | Tropic Trooper has used SSL to connect to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupRedCurl | RedCurl has used HTTPS for C2 communication. |
| T1573.002 Asymmetric Cryptography |
GroupMedusa Group | Medusa Group has used HTTPS for command and control. |
| T1573.002 Asymmetric Cryptography |
GroupAPT42 | APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. |
| T1573.002 Asymmetric Cryptography |
GroupCobalt Group | Cobalt Group has used the Plink utility to create SSH tunnels. |
| T1573.002 Asymmetric Cryptography |
GroupVelvet Ant | Velvet Ant has used a reverse SSH shell to securely communicate with victim devices. |
| T1573.002 Asymmetric Cryptography |
GroupFIN8 | FIN8 has used the Plink utility to tunnel RDP back to C2 infrastructure. |
| T1573.002 Asymmetric Cryptography |
MalwareBRICKSTORM | BRICKSTORM has communicated with C2 infrastructure via TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareNICECURL | NICECURL has used HTTPS for C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareCOATHANGER | COATHANGER connects to command and control infrastructure using SSL. |
| T1573.002 Asymmetric Cryptography |
MalwareSardonic | Sardonic has the ability to send a random 64-byte RC4 key to communicate with actor-controlled C2 servers by using an RSA public key. |
| T1573.002 Asymmetric Cryptography |
Malwareadbupd | adbupd contains a copy of the OpenSSL library to encrypt C2 traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareCASTLETAP | CASTLETAP can initiate a C2 connection over an SSL socket. |
| T1573.002 Asymmetric Cryptography |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can communicate over SSL using the private key from the Ivanti Connect Secure web server. |
| T1573.002 Asymmetric Cryptography |
MalwareStrongPity | StrongPity has encrypted C2 traffic using SSL/TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareTinyTurla | TinyTurla has the ability to encrypt C2 traffic with SSL/TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareJ-magic | J-magic can communicate back to send a challenge to C2 infrastructure over SSL. |
| T1573.002 Asymmetric Cryptography |
MalwareGreyEnergy | GreyEnergy encrypts communications using RSA-2048. |
| T1573.002 Asymmetric Cryptography |
MalwareGomir | Gomir uses reverse proxy functionality that employs SSL to encrypt communications. |
| T1573.002 Asymmetric Cryptography |
MalwareBOLDMOVE | BOLDMOVE uses the WolfSSL library to implement SSL encryption for command and control communication. |
| T1573.002 Asymmetric Cryptography |
MalwareBADHATCH | BADHATCH can beacon to a hardcoded C2 IP address using TLS encryption every 5 minutes. |
| T1573.002 Asymmetric Cryptography |
MalwareMachete | Machete has used TLS-encrypted FTP to exfiltrate data. |
| T1573.002 Asymmetric Cryptography |
MalwareWellMess | WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates. |
| T1573.002 Asymmetric Cryptography |
MalwareWoody RAT | Woody RAT can use RSA-4096 to encrypt data sent to its C2 server. |
| T1573.002 Asymmetric Cryptography |
MalwareSombRAT | SombRAT can SSL encrypt C2 traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareVolgmer | Some Volgmer variants use SSL to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareMispadu | Mispadu contains a copy of the OpenSSL library to encrypt C2 traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareREPTILE | REPTILE can use TLS over raw TCP for secure C2. |
| T1573.002 Asymmetric Cryptography |
MalwareDoki | Doki has used the embedTLS library for network communications. |
| T1573.002 Asymmetric Cryptography |
MalwareIcedID | IcedID has used SSL and TLS in communications with C2. |
| T1573.002 Asymmetric Cryptography |
MalwareRising Sun | Rising Sun variants can use SSL for encrypting C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareHi-Zor | Hi-Zor encrypts C2 traffic with TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareSnappyTCP | SnappyTCP can use OpenSSL and TLS certificates to encrypt traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareGoldMax | GoldMax has RSA-encrypted its communication with the C2 server. |
| T1573.002 Asymmetric Cryptography |
MalwarePOSHSPY | POSHSPY encrypts C2 traffic with AES and RSA. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.