ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1573.002
Asymmetric Cryptography
MalwareDarkWatchman

DarkWatchman can use TLS to encrypt its C2 channel.

T1573.002
Asymmetric Cryptography
MalwareLumma Stealer

Lumma Stealer has used HTTPS for command and control purposes.

T1573.002
Asymmetric Cryptography
MalwareSykipot

Sykipot uses SSL for encrypting C2 communications.

T1573.002
Asymmetric Cryptography
MalwareKEYPLUG

KEYPLUG can use TLS-encrypted WebSocket Protocol (WSS) for C2.

T1573.002
Asymmetric Cryptography
MalwarePureCrypter

PureCrypter can send a TLS 1.2 encrypted infection message via Discord webhook.

T1573.002
Asymmetric Cryptography
MalwareXTunnel

XTunnel uses SSL/TLS and RC4 to encrypt traffic.

T1573.002
Asymmetric Cryptography
MalwareWannaCry

WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit.

T1573.002
Asymmetric Cryptography
MalwareGazer

Gazer uses custom encryption for C2 that uses RSA.

T1573.002
Asymmetric Cryptography
MalwarePay2Key

Pay2Key has used RSA encrypted communications with C2.

T1573.002
Asymmetric Cryptography
MalwareSagerunex

Sagerunex uses HTTPS for command and control communication.

T1573.002
Asymmetric Cryptography
MalwareUroburos

Uroburos has used a combination of a Diffie-Hellman key exchange mixed with a pre-shared key (PSK) to encrypt its top layer of C2 communications.

T1573.002
Asymmetric Cryptography
MalwareMetamorfo

Metamorfo's C2 communication has been encrypted using OpenSSL.

T1573.002
Asymmetric Cryptography
MalwareTrojan.Karagany

Trojan.Karagany can secure C2 communications with SSL and TLS.

T1573.002
Asymmetric Cryptography
MalwareAttor

Attor's Blowfish key is encrypted with a public RSA key.

T1573.002
Asymmetric Cryptography
MalwareSodaMaster

SodaMaster can use a hardcoded RSA key to encrypt some of its C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareGrandoreiro

Grandoreiro can use SSL in C2 communication.

T1573.002
Asymmetric Cryptography
MalwareWellMail

WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS.

T1573.002
Asymmetric Cryptography
MalwareBazar

Bazar can use TLS in C2 communications.

T1573.002
Asymmetric Cryptography
MalwareKobalos

Kobalos's authentication and key exchange is performed using RSA-512.

T1573.002
Asymmetric Cryptography
MalwareHiddenFace

HiddenFace can use RSA-2048 in addition to symmetric algorithms in C2.

T1573.002
Asymmetric Cryptography
MalwareZebrocy

Zebrocy uses SSL and AES ECB for encrypting C2 communications.

T1573.002
Asymmetric Cryptography
MalwareCobalt Strike

Cobalt Strike can use RSA asymmetric encryption with PKCS1 padding to encrypt data sent to the C2 server.

T1573.002
Asymmetric Cryptography
MalwareServHelper

ServHelper may set up a reverse SSH tunnel to give the attacker access to services running on the victim, such as RDP.

T1573.002
Asymmetric Cryptography
MalwareREvil

REvil has encrypted C2 communications with the ECIES algorithm.

T1573.002
Asymmetric Cryptography
MalwareOilBooster

OilBooster can use the OpenSSL library to encrypt C2 communications.

T1573.002
Asymmetric Cryptography
MalwareCyclops Blink

Cyclops Blink can encrypt C2 messages with AES-256-CBC sent underneath TLS. OpenSSL library functions are also used to encrypt each message using a randomly generated key and IV, which are then encrypted using a hard-coded RSA public key.

T1573.002
Asymmetric Cryptography
MalwareCarbon

Carbon has used RSA encryption for C2 communications.

T1573.002
Asymmetric Cryptography
MalwareBISCUIT

BISCUIT uses SSL for encrypting C2 communications.

T1573.002
Asymmetric Cryptography
MalwareLAMEHUG

LAMEHUG can use SSH to transfer information to C2.

T1573.002
Asymmetric Cryptography
MalwareMango

Mango can use TLS to encrypt C2 communications.

T1573.002
Asymmetric Cryptography
MalwareGrimAgent

GrimAgent can use a hardcoded server public RSA key to encrypt the first request to C2.

T1573.002
Asymmetric Cryptography
MalwarePoetRAT

PoetRAT used TLS to encrypt command and control (C2) communications.

T1573.002
Asymmetric Cryptography
MalwareCHOPSTICK

CHOPSTICK encrypts C2 communications with TLS.

T1573.002
Asymmetric Cryptography
MalwarePenquin

Penquin can encrypt communications using the BlowFish algorithm and a symmetric key exchanged with Diffie Hellman.

T1573.002
Asymmetric Cryptography
MalwarePITSTOP

PITSTOP has the ability to communicate over TLS.

T1573.002
Asymmetric Cryptography
MalwareComRAT

ComRAT can use SSL/TLS encryption for its HTTP-based C2 channel. ComRAT has used public key cryptography with RSA and AES encrypted email attachments for its Gmail C2 channel.

T1573.002
Asymmetric Cryptography
MalwareLunarWeb

LunarWeb can send short C2 commands, up to 512 bytes, encrypted with RSA-4096.

T1573.002
Asymmetric Cryptography
MalwarePOWERSTATS

POWERSTATS has encrypted C2 traffic with RSA.

T1573.002
Asymmetric Cryptography
MalwareDridex

Dridex has encrypted traffic with RSA.

T1573.002
Asymmetric Cryptography
MalwareADVSTORESHELL

A variant of ADVSTORESHELL encrypts some C2 with RSA.

T1573.002
Asymmetric Cryptography
MalwareSmall Sieve

Small Sieve can use SSL/TLS for its HTTPS Telegram Bot API-based C2 channel.

T1573.002
Asymmetric Cryptography
ToolCovenant

Covenant can utilize SSL to encrypt command and control traffic.

T1573.002
Asymmetric Cryptography
ToolSliver

Sliver can use mutual TLS and RSA cryptography to exchange a session key.

T1573.002
Asymmetric Cryptography
ToolDCRAT

DCRAT can use certificate-based authentication for C2 servers.

T1573.002
Asymmetric Cryptography
ToolEmpire

Empire can use TLS to encrypt its C2 channel.

T1573.002
Asymmetric Cryptography
ToolFRP

FRP can be configured to only accept TLS connections.

T1573.002
Asymmetric Cryptography
ToolRemcos

Remcos can use TLS to encrypt C2 communication.

T1573.002
Asymmetric Cryptography
ToolKoadic

Koadic can use SSL and TLS for communications.

T1573.002
Asymmetric Cryptography
ToolPupy

Pupy's default encryption for its C2 communication channel is SSL, but it also has transport options for RSA and AES.

T1573.002
Asymmetric Cryptography
ToolMythic

Mythic supports SSL encrypted C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.