Real-world descriptions of how a group, tool or campaign used a technique.
39 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560.001 Archive via Utility |
GroupGALLIUM | GALLIUM used WinRAR to compress and encrypt stolen data prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupAPT3 | APT3 has used tools to compress data before exfilling it. |
| T1560.001 Archive via Utility |
GroupKimsuky | Kimsuky has used QuickZip to archive stolen files before exfiltration. Kimsuky has used the Send() function to compress all collected data into a zip file named init,.zip, then renames it to init.dat, before exfiltration. |
| T1560.001 Archive via Utility |
GroupVolt Typhoon | Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip. |
| T1560.001 Archive via Utility |
GroupAPT41 | APT41 created a RAR archive of targeted files for exfiltration. Additionally, APT41 used the makecab.exe utility to both download tools, such as NATBypass, to the victim network and to archive a file for exfiltration. |
| T1560.001 Archive via Utility |
GroupmenuPass | menuPass has compressed files before exfiltration using TAR and RAR. |
| T1560.001 Archive via Utility |
GroupHAFNIUM | HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration. |
| T1560.001 Archive via Utility |
GroupMuddyWater | MuddyWater has used the native Windows cabinet creation tool, makecab.exe, likely to compress stolen data to be uploaded. |
| T1560.001 Archive via Utility |
GroupGallmaker | Gallmaker has used WinZip, likely to archive data prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupMustang Panda | Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration. Mustang Panda has used WinRAR “Rar.exe” to archive stolen files before exfiltration. Mustang Panda has also used TONESHELL and post-exploitation tools such as RemCom and Impacket to execute WinRAR `rar.exe` to archive files for exfiltration. |
| T1560.001 Archive via Utility |
GroupAPT39 | APT39 has used WinRAR and 7-Zip to compress an archive stolen data. |
| T1560.001 Archive via Utility |
GroupUNC3886 | UNC3886 has used Gzip and the Windows command `makecab` to compress files and stolen credentials from victim systems. |
| T1560.001 Archive via Utility |
GroupAkira | Akira uses utilities such as WinRAR to archive data prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupSea Turtle | Sea Turtle used the tar utility to create a local archive of email data on a victim system. |
| T1560.001 Archive via Utility |
GroupAquatic Panda | Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupKe3chang | Ke3chang is known to use 7Zip and RAR with passwords to encrypt data prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupAPT1 | APT1 has used RAR to compress files before moving them outside of the victim network. |
| T1560.001 Archive via Utility |
GroupTurla | Turla has encrypted files stolen from connected USB drives into a RAR file before exfiltration. |
| T1560.001 Archive via Utility |
GroupRedCurl | RedCurl has downloaded 7-Zip to decompress password protected archives. |
| T1560.001 Archive via Utility |
GroupLotus Blossom | Lotus Blossom has used WinRAR for compressing data in RAR format. |
| T1560.001 Archive via Utility |
GroupChimera | Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts. |
| T1560.001 Archive via Utility |
GroupMirrorFace | MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupBRONZE BUTLER | BRONZE BUTLER has compressed data into password-protected RAR archives prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupToddyCat | ToddyCat has leveraged xcopy, 7zip, and RAR to stage and compress collected documents prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupAgrius | Agrius used 7zip to archive extracted data in preparation for exfiltration. |
| T1560.001 Archive via Utility |
GroupAPT28 | APT28 has used a variety of utilities, including WinRAR, to archive collected data with password protection. |
| T1560.001 Archive via Utility |
GroupAPT5 | APT5 has used the JAR/ZIP file format for exfiltrated files. |
| T1560.001 Archive via Utility |
GroupFox Kitten | Fox Kitten has used 7-Zip to archive data. |
| T1560.001 Archive via Utility |
GroupINC Ransom | INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupEarth Lusca | Earth Lusca has used WinRAR to compress stolen files into an archive prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupSowbug | Sowbug extracted documents and bundled them into a RAR archive. |
| T1560.001 Archive via Utility |
GroupCopyKittens | CopyKittens uses ZPP, a .NET console program, to compress files with ZIP. |
| T1560.001 Archive via Utility |
GroupWizard Spider | Wizard Spider has archived data into ZIP files on compromised machines. |
| T1560.001 Archive via Utility |
GroupVOID MANTICORE | VOID MANTICORE has stored collected data in a password protected compressed file prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupPlay | Play has used WinRAR to compress files prior to exfiltration. |
| T1560.001 Archive via Utility |
GroupMagic Hound | Magic Hound has used gzip to archive dumped LSASS process memory and RAR to stage and compress local folders. |
| T1560.001 Archive via Utility |
GroupAPT33 | APT33 has used WinRAR to compress data prior to exfil. |
| T1560.001 Archive via Utility |
GroupFIN8 | FIN8 has used RAR to compress collected data before exfiltration. |
| T1560.001 Archive via Utility |
GroupFIN13 | FIN13 has compressed the dump output of compromised credentials with a 7zip binary. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.