ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1560.001×

39 examples

TechniqueUsed byProcedure example
T1560.001
Archive via Utility
GroupGALLIUM

GALLIUM used WinRAR to compress and encrypt stolen data prior to exfiltration.

T1560.001
Archive via Utility
GroupAPT3

APT3 has used tools to compress data before exfilling it.

T1560.001
Archive via Utility
GroupKimsuky

Kimsuky has used QuickZip to archive stolen files before exfiltration. Kimsuky has used the Send() function to compress all collected data into a zip file named init,.zip, then renames it to init.dat, before exfiltration.

T1560.001
Archive via Utility
GroupVolt Typhoon

Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip.

T1560.001
Archive via Utility
GroupAPT41

APT41 created a RAR archive of targeted files for exfiltration. Additionally, APT41 used the makecab.exe utility to both download tools, such as NATBypass, to the victim network and to archive a file for exfiltration.

T1560.001
Archive via Utility
GroupmenuPass

menuPass has compressed files before exfiltration using TAR and RAR.

T1560.001
Archive via Utility
GroupHAFNIUM

HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration.

T1560.001
Archive via Utility
GroupMuddyWater

MuddyWater has used the native Windows cabinet creation tool, makecab.exe, likely to compress stolen data to be uploaded.

T1560.001
Archive via Utility
GroupGallmaker

Gallmaker has used WinZip, likely to archive data prior to exfiltration.

T1560.001
Archive via Utility
GroupMustang Panda

Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration. Mustang Panda has used WinRAR “Rar.exe” to archive stolen files before exfiltration. Mustang Panda has also used TONESHELL and post-exploitation tools such as RemCom and Impacket to execute WinRAR `rar.exe` to archive files for exfiltration.

T1560.001
Archive via Utility
GroupAPT39

APT39 has used WinRAR and 7-Zip to compress an archive stolen data.

T1560.001
Archive via Utility
GroupUNC3886

UNC3886 has used Gzip and the Windows command `makecab` to compress files and stolen credentials from victim systems.

T1560.001
Archive via Utility
GroupAkira

Akira uses utilities such as WinRAR to archive data prior to exfiltration.

T1560.001
Archive via Utility
GroupSea Turtle

Sea Turtle used the tar utility to create a local archive of email data on a victim system.

T1560.001
Archive via Utility
GroupAquatic Panda

Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration.

T1560.001
Archive via Utility
GroupKe3chang

Ke3chang is known to use 7Zip and RAR with passwords to encrypt data prior to exfiltration.

T1560.001
Archive via Utility
GroupAPT1

APT1 has used RAR to compress files before moving them outside of the victim network.

T1560.001
Archive via Utility
GroupTurla

Turla has encrypted files stolen from connected USB drives into a RAR file before exfiltration.

T1560.001
Archive via Utility
GroupRedCurl

RedCurl has downloaded 7-Zip to decompress password protected archives.

T1560.001
Archive via Utility
GroupLotus Blossom

Lotus Blossom has used WinRAR for compressing data in RAR format.

T1560.001
Archive via Utility
GroupChimera

Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts.

T1560.001
Archive via Utility
GroupMirrorFace

MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration.

T1560.001
Archive via Utility
GroupBRONZE BUTLER

BRONZE BUTLER has compressed data into password-protected RAR archives prior to exfiltration.

T1560.001
Archive via Utility
GroupToddyCat

ToddyCat has leveraged xcopy, 7zip, and RAR to stage and compress collected documents prior to exfiltration.

T1560.001
Archive via Utility
GroupAgrius

Agrius used 7zip to archive extracted data in preparation for exfiltration.

T1560.001
Archive via Utility
GroupAPT28

APT28 has used a variety of utilities, including WinRAR, to archive collected data with password protection.

T1560.001
Archive via Utility
GroupAPT5

APT5 has used the JAR/ZIP file format for exfiltrated files.

T1560.001
Archive via Utility
GroupFox Kitten

Fox Kitten has used 7-Zip to archive data.

T1560.001
Archive via Utility
GroupINC Ransom

INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration.

T1560.001
Archive via Utility
GroupEarth Lusca

Earth Lusca has used WinRAR to compress stolen files into an archive prior to exfiltration.

T1560.001
Archive via Utility
GroupSowbug

Sowbug extracted documents and bundled them into a RAR archive.

T1560.001
Archive via Utility
GroupCopyKittens

CopyKittens uses ZPP, a .NET console program, to compress files with ZIP.

T1560.001
Archive via Utility
GroupWizard Spider

Wizard Spider has archived data into ZIP files on compromised machines.

T1560.001
Archive via Utility
GroupVOID MANTICORE

VOID MANTICORE has stored collected data in a password protected compressed file prior to exfiltration.

T1560.001
Archive via Utility
GroupPlay

Play has used WinRAR to compress files prior to exfiltration.

T1560.001
Archive via Utility
GroupMagic Hound

Magic Hound has used gzip to archive dumped LSASS process memory and RAR to stage and compress local folders.

T1560.001
Archive via Utility
GroupAPT33

APT33 has used WinRAR to compress data prior to exfil.

T1560.001
Archive via Utility
GroupFIN8

FIN8 has used RAR to compress collected data before exfiltration.

T1560.001
Archive via Utility
GroupFIN13

FIN13 has compressed the dump output of compromised credentials with a 7zip binary.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.