ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1573.001
Symmetric Cryptography
MalwareFALLCHILL

FALLCHILL encrypts C2 data with RC4 encryption.

T1573.001
Symmetric Cryptography
ToolSliver

Sliver can use AES-GCM-256 to encrypt a session key for C2 message exchange.

T1573.001
Symmetric Cryptography
ToolFRP

FRP can use STCP (Secret TCP) with a preshared key to encrypt services exposed to public networks.

T1573.001
Symmetric Cryptography
ToolQuasarRAT

QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication.

T1573.001
Symmetric Cryptography
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has encrypted collected data using a hybrid AES-256 and RSA-4096 encryption prior to exfiltration over 'curl`.

T1573.001
Symmetric Cryptography
MalwareDuqu

The Duqu command and control protocol's data stream can be encrypted with AES-CBC.

T1573.002
Asymmetric Cryptography
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho used SSL for network communication.

T1573.002
Asymmetric Cryptography
CampaignC0021

During C0021, the threat actors used SSL via TCP port 443 for C2 communications.

T1573.002
Asymmetric Cryptography
CampaignAPT41 DUST

APT41 DUST used HTTPS for command and control.

T1573.002
Asymmetric Cryptography
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation used HTTPS for command and control of compromised Versa Director servers.

T1573.002
Asymmetric Cryptography
CampaignOperation Wocao

During Operation Wocao, threat actors' proxy implementation "Agent" upgraded the socket in use to a TLS socket.

T1573.002
Asymmetric Cryptography
GroupFIN6

FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers.

T1573.002
Asymmetric Cryptography
GroupRedEcho

RedEcho uses SSL for network communication.

T1573.002
Asymmetric Cryptography
GroupTA2541

TA2541 has used TLS encrypted C2 communications including for campaigns using AsyncRAT.

T1573.002
Asymmetric Cryptography
GroupOilRig

OilRig used the PowerExchange utility and other tools to create tunnels to C2 servers.

T1573.002
Asymmetric Cryptography
GroupTropic Trooper

Tropic Trooper has used SSL to connect to C2 servers.

T1573.002
Asymmetric Cryptography
GroupRedCurl

RedCurl has used HTTPS for C2 communication.

T1573.002
Asymmetric Cryptography
GroupMedusa Group

Medusa Group has used HTTPS for command and control.

T1573.002
Asymmetric Cryptography
GroupAPT42

APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS.

T1573.002
Asymmetric Cryptography
GroupCobalt Group

Cobalt Group has used the Plink utility to create SSH tunnels.

T1573.002
Asymmetric Cryptography
GroupVelvet Ant

Velvet Ant has used a reverse SSH shell to securely communicate with victim devices.

T1573.002
Asymmetric Cryptography
GroupFIN8

FIN8 has used the Plink utility to tunnel RDP back to C2 infrastructure.

T1573.002
Asymmetric Cryptography
MalwareBRICKSTORM

BRICKSTORM has communicated with C2 infrastructure via TLS.

T1573.002
Asymmetric Cryptography
MalwareNICECURL

NICECURL has used HTTPS for C2 communications.

T1573.002
Asymmetric Cryptography
MalwareCOATHANGER

COATHANGER connects to command and control infrastructure using SSL.

T1573.002
Asymmetric Cryptography
MalwareSardonic

Sardonic has the ability to send a random 64-byte RC4 key to communicate with actor-controlled C2 servers by using an RSA public key.

T1573.002
Asymmetric Cryptography
Malwareadbupd

adbupd contains a copy of the OpenSSL library to encrypt C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareCASTLETAP

CASTLETAP can initiate a C2 connection over an SSL socket.

T1573.002
Asymmetric Cryptography
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can communicate over SSL using the private key from the Ivanti Connect Secure web server.

T1573.002
Asymmetric Cryptography
MalwareStrongPity

StrongPity has encrypted C2 traffic using SSL/TLS.

T1573.002
Asymmetric Cryptography
MalwareTinyTurla

TinyTurla has the ability to encrypt C2 traffic with SSL/TLS.

T1573.002
Asymmetric Cryptography
MalwareJ-magic

J-magic can communicate back to send a challenge to C2 infrastructure over SSL.

T1573.002
Asymmetric Cryptography
MalwareGreyEnergy

GreyEnergy encrypts communications using RSA-2048.

T1573.002
Asymmetric Cryptography
MalwareGomir

Gomir uses reverse proxy functionality that employs SSL to encrypt communications.

T1573.002
Asymmetric Cryptography
MalwareBOLDMOVE

BOLDMOVE uses the WolfSSL library to implement SSL encryption for command and control communication.

T1573.002
Asymmetric Cryptography
MalwareBADHATCH

BADHATCH can beacon to a hardcoded C2 IP address using TLS encryption every 5 minutes.

T1573.002
Asymmetric Cryptography
MalwareMachete

Machete has used TLS-encrypted FTP to exfiltrate data.

T1573.002
Asymmetric Cryptography
MalwareWellMess

WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates.

T1573.002
Asymmetric Cryptography
MalwareWoody RAT

Woody RAT can use RSA-4096 to encrypt data sent to its C2 server.

T1573.002
Asymmetric Cryptography
MalwareSombRAT

SombRAT can SSL encrypt C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareVolgmer

Some Volgmer variants use SSL to encrypt C2 communications.

T1573.002
Asymmetric Cryptography
MalwareMispadu

Mispadu contains a copy of the OpenSSL library to encrypt C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareREPTILE

REPTILE can use TLS over raw TCP for secure C2.

T1573.002
Asymmetric Cryptography
MalwareDoki

Doki has used the embedTLS library for network communications.

T1573.002
Asymmetric Cryptography
MalwareIcedID

IcedID has used SSL and TLS in communications with C2.

T1573.002
Asymmetric Cryptography
MalwareRising Sun

Rising Sun variants can use SSL for encrypting C2 communications.

T1573.002
Asymmetric Cryptography
MalwareHi-Zor

Hi-Zor encrypts C2 traffic with TLS.

T1573.002
Asymmetric Cryptography
MalwareSnappyTCP

SnappyTCP can use OpenSSL and TLS certificates to encrypt traffic.

T1573.002
Asymmetric Cryptography
MalwareGoldMax

GoldMax has RSA-encrypted its communication with the C2 server.

T1573.002
Asymmetric Cryptography
MalwarePOSHSPY

POSHSPY encrypts C2 traffic with AES and RSA.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.