ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1132.001×

11 examples

TechniqueUsed byProcedure example
T1132.001
Standard Encoding
GroupPatchwork

Patchwork used Base64 to encode C2 traffic.

T1132.001
Standard Encoding
GroupHAFNIUM

HAFNIUM has used ASCII encoding for C2 traffic.

T1132.001
Standard Encoding
GroupMuddyWater

MuddyWater has used tools to encode C2 communications including Base64 encoding.

T1132.001
Standard Encoding
GroupSandworm Team

Sandworm Team's BCS-server tool uses base64 encoding and HTML tags for the communication traffic between the C2 server.

T1132.001
Standard Encoding
GroupTropic Trooper

Tropic Trooper has used base64 encoding to hide command strings delivered from the C2.

T1132.001
Standard Encoding
GroupBRONZE BUTLER

Several BRONZE BUTLER tools encode data with base64 when posting it to a C2 server.

T1132.001
Standard Encoding
GroupTA551

TA551 has used encoded ASCII text for initial C2 communications.

T1132.001
Standard Encoding
GroupAPT42

APT42 has encoded C2 traffic with Base64.

T1132.001
Standard Encoding
GroupLazarus Group

A Lazarus Group malware sample encodes data with base64.

T1132.001
Standard Encoding
GroupAPT33

APT33 has used base64 to encode command and control traffic.

T1132.001
Standard Encoding
GroupAPT19

An APT19 HTTP malware variant used Base64 to encode communications to the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.