ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1560×

13 examples

TechniqueUsed byProcedure example
T1560
Archive Collected Data
GroupBlackByte

BlackByte compressed data collected from victim environments prior to exfiltration.

T1560
Archive Collected Data
GroupPatchwork

Patchwork encrypted the collected files' path with AES and then encoded them with base64.

T1560
Archive Collected Data
GroupDragonfly

Dragonfly has compressed data into .zip files prior to exfiltration.

T1560
Archive Collected Data
GroupmenuPass

menuPass has encrypted files and information before exfiltration.

T1560
Archive Collected Data
GroupAPT32

APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration.

T1560
Archive Collected Data
GroupFIN6

Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration.

T1560
Archive Collected Data
GroupKe3chang

The Ke3chang group has been known to compress data before exfiltration.

T1560
Archive Collected Data
GroupLeviathan

Leviathan has archived victim's data prior to exfiltration.

T1560
Archive Collected Data
GroupAxiom

Axiom has compressed and encrypted data prior to exfiltration.

T1560
Archive Collected Data
GroupEmber Bear

Ember Bear has compressed collected data prior to exfiltration.

T1560
Archive Collected Data
GroupLuminousMoth

LuminousMoth has manually archived stolen files from victim machines before exfiltration.

T1560
Archive Collected Data
GroupAPT28

APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks.

T1560
Archive Collected Data
GroupLazarus Group

Lazarus Group has compressed exfiltrated data with RAR and used RomeoDelta malware to archive specified directories in .zip format, encrypt the .zip file, and upload it to C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.