Real-world descriptions of how a group, tool or campaign used a technique.
167 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1573.001 Symmetric Cryptography |
MalwareHelminth | Helminth encrypts data sent to its C2 server over HTTP with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareDridex | Dridex has encrypted traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareKomplex | The Komplex C2 channel uses an 11-byte XOR algorithm to hide data. |
| T1573.001 Symmetric Cryptography |
MalwareComnie | Comnie encrypts command and control communications with RC4. |
| T1573.001 Symmetric Cryptography |
MalwareH1N1 | H1N1 encrypts C2 traffic using an RC4 key. |
| T1573.001 Symmetric Cryptography |
MalwareAzorult | Azorult can encrypt C2 traffic using XOR. |
| T1573.001 Symmetric Cryptography |
MalwareUPPERCUT | Some versions of UPPERCUT have used the hard-coded string “this is the encrypt key” for Blowfish encryption when communicating with a C2. Later versions have hard-coded keys uniquely for each C2 address. UPPERCUT has also used custom ChaCha20, XOR, and LZO algorithms for C2 communication. |
| T1573.001 Symmetric Cryptography |
MalwareADVSTORESHELL | A variant of ADVSTORESHELL encrypts some C2 with 3DES. |
| T1573.001 Symmetric Cryptography |
MalwareStrifeWater | StrifeWater can encrypt C2 traffic using XOR with a hard coded key. |
| T1573.001 Symmetric Cryptography |
MalwareHiddenWasp | HiddenWasp uses an RC4-like algorithm with an already computed PRGA generated key-stream for network communication. |
| T1573.001 Symmetric Cryptography |
MalwareWarzoneRAT | WarzoneRAT can encrypt its C2 with RC4 with the password `warzone160\x00`. |
| T1573.001 Symmetric Cryptography |
MalwareFALLCHILL | FALLCHILL encrypts C2 data with RC4 encryption. |
| T1573.001 Symmetric Cryptography |
ToolSliver | Sliver can use AES-GCM-256 to encrypt a session key for C2 message exchange. |
| T1573.001 Symmetric Cryptography |
ToolFRP | FRP can use STCP (Secret TCP) with a preshared key to encrypt services exposed to public networks. |
| T1573.001 Symmetric Cryptography |
ToolQuasarRAT | QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication. |
| T1573.001 Symmetric Cryptography |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has encrypted collected data using a hybrid AES-256 and RSA-4096 encryption prior to exfiltration over 'curl`. |
| T1573.001 Symmetric Cryptography |
MalwareDuqu | The Duqu command and control protocol's data stream can be encrypted with AES-CBC. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.