ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1560.001×

11 examples

TechniqueUsed byProcedure example
T1560.001
Archive via Utility
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group archived victim's data into a RAR file.

T1560.001
Archive via Utility
CampaignOperation Honeybee

During Operation Honeybee, the threat actors uses zip to pack collected files before exfiltration.

T1560.001
Archive via Utility
CampaignCutting Edge

During Cutting Edge, threat actors saved collected data to a tar archive.

T1560.001
Archive via Utility
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives.

T1560.001
Archive via Utility
CampaignFunnyDream

During FunnyDream, the threat actors used 7zr.exe to add collected files to an archive.

T1560.001
Archive via Utility
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the Makecab utility to compress and a version of WinRAR to create password-protected archives of stolen data prior to exfiltration.

T1560.001
Archive via Utility
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data.

T1560.001
Archive via Utility
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compressed stolen files into a zip file prior to exfiltration.

T1560.001
Archive via Utility
CampaignAPT41 DUST

APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration.

T1560.001
Archive via Utility
CampaignOperation Wocao

During Operation Wocao, threat actors archived collected files with WinRAR, prior to exfiltration.

T1560.001
Archive via Utility
CampaignC0026

During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.