Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.002 Asymmetric Cryptography |
MalwareDarkWatchman | DarkWatchman can use TLS to encrypt its C2 channel. |
| T1573.002 Asymmetric Cryptography |
MalwareLumma Stealer | Lumma Stealer has used HTTPS for command and control purposes. |
| T1573.002 Asymmetric Cryptography |
MalwareSykipot | Sykipot uses SSL for encrypting C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareKEYPLUG | KEYPLUG can use TLS-encrypted WebSocket Protocol (WSS) for C2. |
| T1573.002 Asymmetric Cryptography |
MalwarePureCrypter | PureCrypter can send a TLS 1.2 encrypted infection message via Discord webhook. |
| T1573.002 Asymmetric Cryptography |
MalwareXTunnel | XTunnel uses SSL/TLS and RC4 to encrypt traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareWannaCry | WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit. |
| T1573.002 Asymmetric Cryptography |
MalwareGazer | Gazer uses custom encryption for C2 that uses RSA. |
| T1573.002 Asymmetric Cryptography |
MalwarePay2Key | Pay2Key has used RSA encrypted communications with C2. |
| T1573.002 Asymmetric Cryptography |
MalwareSagerunex | Sagerunex uses HTTPS for command and control communication. |
| T1573.002 Asymmetric Cryptography |
MalwareUroburos | Uroburos has used a combination of a Diffie-Hellman key exchange mixed with a pre-shared key (PSK) to encrypt its top layer of C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareMetamorfo | Metamorfo's C2 communication has been encrypted using OpenSSL. |
| T1573.002 Asymmetric Cryptography |
MalwareTrojan.Karagany | Trojan.Karagany can secure C2 communications with SSL and TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareAttor | Attor's Blowfish key is encrypted with a public RSA key. |
| T1573.002 Asymmetric Cryptography |
MalwareSodaMaster | SodaMaster can use a hardcoded RSA key to encrypt some of its C2 traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareGrandoreiro | Grandoreiro can use SSL in C2 communication. |
| T1573.002 Asymmetric Cryptography |
MalwareWellMail | WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareBazar | Bazar can use TLS in C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareKobalos | Kobalos's authentication and key exchange is performed using RSA-512. |
| T1573.002 Asymmetric Cryptography |
MalwareHiddenFace | HiddenFace can use RSA-2048 in addition to symmetric algorithms in C2. |
| T1573.002 Asymmetric Cryptography |
MalwareZebrocy | Zebrocy uses SSL and AES ECB for encrypting C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareCobalt Strike | Cobalt Strike can use RSA asymmetric encryption with PKCS1 padding to encrypt data sent to the C2 server. |
| T1573.002 Asymmetric Cryptography |
MalwareServHelper | ServHelper may set up a reverse SSH tunnel to give the attacker access to services running on the victim, such as RDP. |
| T1573.002 Asymmetric Cryptography |
MalwareREvil | REvil has encrypted C2 communications with the ECIES algorithm. |
| T1573.002 Asymmetric Cryptography |
MalwareOilBooster | OilBooster can use the OpenSSL library to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareCyclops Blink | Cyclops Blink can encrypt C2 messages with AES-256-CBC sent underneath TLS. OpenSSL library functions are also used to encrypt each message using a randomly generated key and IV, which are then encrypted using a hard-coded RSA public key. |
| T1573.002 Asymmetric Cryptography |
MalwareCarbon | Carbon has used RSA encryption for C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareBISCUIT | BISCUIT uses SSL for encrypting C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareLAMEHUG | LAMEHUG can use SSH to transfer information to C2. |
| T1573.002 Asymmetric Cryptography |
MalwareMango | Mango can use TLS to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareGrimAgent | GrimAgent can use a hardcoded server public RSA key to encrypt the first request to C2. |
| T1573.002 Asymmetric Cryptography |
MalwarePoetRAT | PoetRAT used TLS to encrypt command and control (C2) communications. |
| T1573.002 Asymmetric Cryptography |
MalwareCHOPSTICK | CHOPSTICK encrypts C2 communications with TLS. |
| T1573.002 Asymmetric Cryptography |
MalwarePenquin | Penquin can encrypt communications using the BlowFish algorithm and a symmetric key exchanged with Diffie Hellman. |
| T1573.002 Asymmetric Cryptography |
MalwarePITSTOP | PITSTOP has the ability to communicate over TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareComRAT | ComRAT can use SSL/TLS encryption for its HTTP-based C2 channel. ComRAT has used public key cryptography with RSA and AES encrypted email attachments for its Gmail C2 channel. |
| T1573.002 Asymmetric Cryptography |
MalwareLunarWeb | LunarWeb can send short C2 commands, up to 512 bytes, encrypted with RSA-4096. |
| T1573.002 Asymmetric Cryptography |
MalwarePOWERSTATS | POWERSTATS has encrypted C2 traffic with RSA. |
| T1573.002 Asymmetric Cryptography |
MalwareDridex | Dridex has encrypted traffic with RSA. |
| T1573.002 Asymmetric Cryptography |
MalwareADVSTORESHELL | A variant of ADVSTORESHELL encrypts some C2 with RSA. |
| T1573.002 Asymmetric Cryptography |
MalwareSmall Sieve | Small Sieve can use SSL/TLS for its HTTPS Telegram Bot API-based C2 channel. |
| T1573.002 Asymmetric Cryptography |
ToolCovenant | Covenant can utilize SSL to encrypt command and control traffic. |
| T1573.002 Asymmetric Cryptography |
ToolSliver | Sliver can use mutual TLS and RSA cryptography to exchange a session key. |
| T1573.002 Asymmetric Cryptography |
ToolDCRAT | DCRAT can use certificate-based authentication for C2 servers. |
| T1573.002 Asymmetric Cryptography |
ToolEmpire | Empire can use TLS to encrypt its C2 channel. |
| T1573.002 Asymmetric Cryptography |
ToolFRP | FRP can be configured to only accept TLS connections. |
| T1573.002 Asymmetric Cryptography |
ToolRemcos | Remcos can use TLS to encrypt C2 communication. |
| T1573.002 Asymmetric Cryptography |
ToolKoadic | Koadic can use SSL and TLS for communications. |
| T1573.002 Asymmetric Cryptography |
ToolPupy | Pupy's default encryption for its C2 communication channel is SSL, but it also has transport options for RSA and AES. |
| T1573.002 Asymmetric Cryptography |
ToolMythic | Mythic supports SSL encrypted C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.