Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560.001 Archive via Utility |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group archived victim's data into a RAR file. |
| T1560.001 Archive via Utility |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors uses zip to pack collected files before exfiltration. |
| T1560.001 Archive via Utility |
CampaignCutting Edge | During Cutting Edge, threat actors saved collected data to a tar archive. |
| T1560.001 Archive via Utility |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives. |
| T1560.001 Archive via Utility |
CampaignFunnyDream | During FunnyDream, the threat actors used 7zr.exe to add collected files to an archive. |
| T1560.001 Archive via Utility |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the Makecab utility to compress and a version of WinRAR to create password-protected archives of stolen data prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used built-in PowerShell capabilities ( |
| T1560.001 Archive via Utility |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compressed stolen files into a zip file prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignAPT41 DUST | APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignOperation Wocao | During Operation Wocao, threat actors archived collected files with WinRAR, prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignC0026 | During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.