ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1573.001×

167 examples

TechniqueUsed byProcedure example
T1573.001
Symmetric Cryptography
MalwareHelminth

Helminth encrypts data sent to its C2 server over HTTP with RC4.

T1573.001
Symmetric Cryptography
MalwareDridex

Dridex has encrypted traffic with RC4.

T1573.001
Symmetric Cryptography
MalwareKomplex

The Komplex C2 channel uses an 11-byte XOR algorithm to hide data.

T1573.001
Symmetric Cryptography
MalwareComnie

Comnie encrypts command and control communications with RC4.

T1573.001
Symmetric Cryptography
MalwareH1N1

H1N1 encrypts C2 traffic using an RC4 key.

T1573.001
Symmetric Cryptography
MalwareAzorult

Azorult can encrypt C2 traffic using XOR.

T1573.001
Symmetric Cryptography
MalwareUPPERCUT

Some versions of UPPERCUT have used the hard-coded string “this is the encrypt key” for Blowfish encryption when communicating with a C2. Later versions have hard-coded keys uniquely for each C2 address. UPPERCUT has also used custom ChaCha20, XOR, and LZO algorithms for C2 communication.

T1573.001
Symmetric Cryptography
MalwareADVSTORESHELL

A variant of ADVSTORESHELL encrypts some C2 with 3DES.

T1573.001
Symmetric Cryptography
MalwareStrifeWater

StrifeWater can encrypt C2 traffic using XOR with a hard coded key.

T1573.001
Symmetric Cryptography
MalwareHiddenWasp

HiddenWasp uses an RC4-like algorithm with an already computed PRGA generated key-stream for network communication.

T1573.001
Symmetric Cryptography
MalwareWarzoneRAT

WarzoneRAT can encrypt its C2 with RC4 with the password `warzone160\x00`.

T1573.001
Symmetric Cryptography
MalwareFALLCHILL

FALLCHILL encrypts C2 data with RC4 encryption.

T1573.001
Symmetric Cryptography
ToolSliver

Sliver can use AES-GCM-256 to encrypt a session key for C2 message exchange.

T1573.001
Symmetric Cryptography
ToolFRP

FRP can use STCP (Secret TCP) with a preshared key to encrypt services exposed to public networks.

T1573.001
Symmetric Cryptography
ToolQuasarRAT

QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication.

T1573.001
Symmetric Cryptography
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has encrypted collected data using a hybrid AES-256 and RSA-4096 encryption prior to exfiltration over 'curl`.

T1573.001
Symmetric Cryptography
MalwareDuqu

The Duqu command and control protocol's data stream can be encrypted with AES-CBC.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.