ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1573.001×

14 examples

TechniqueUsed byProcedure example
T1573.001
Symmetric Cryptography
GroupVolt Typhoon

Volt Typhoon has used a version of the Awen web shell that employed AES encryption and decryption for C2 communications.

T1573.001
Symmetric Cryptography
GroupMuddyWater

MuddyWater has used AES to encrypt C2 responses.

T1573.001
Symmetric Cryptography
GroupMustang Panda

Mustang Panda has encrypted C2 communications with RC4. Mustang Panda has also leveraged encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO.

T1573.001
Symmetric Cryptography
GroupZIRCONIUM

ZIRCONIUM has used AES encrypted communications in C2.

T1573.001
Symmetric Cryptography
GroupContagious Interview

Contagious Interview has encrypted C2 traffic using RC4.

T1573.001
Symmetric Cryptography
GroupHigaisa

Higaisa used AES-128 to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
GroupRedCurl

RedCurl has used AES-128 CBC to encrypt C2 communications.

T1573.001
Symmetric Cryptography
GroupStealth Falcon

Stealth Falcon malware encrypts C2 traffic using RC4 with a hard-coded key.

T1573.001
Symmetric Cryptography
GroupBRONZE BUTLER

BRONZE BUTLER has used RC4 encryption (for Datper malware) and AES (for xxmm malware) to obfuscate HTTP traffic. BRONZE BUTLER has also used a tool called RarStar that encodes data with a custom XOR algorithm when posting it to a C2 server.

T1573.001
Symmetric Cryptography
GroupDarkhotel

Darkhotel has used AES-256 and 3DES for C2 communications.

T1573.001
Symmetric Cryptography
GroupAPT28

APT28 installed a Delphi backdoor that used a custom algorithm for C2 communications.

T1573.001
Symmetric Cryptography
GroupLazarus Group

Several Lazarus Group malware families encrypt C2 traffic using custom code that uses XOR with an ADD operation and XOR with a SUB operation. Another Lazarus Group malware sample XORs C2 traffic. Other Lazarus Group malware uses Caracachs encryption to encrypt C2 payloads. Lazarus Group has also used AES to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
GroupInception

Inception has encrypted network communications with AES.

T1573.001
Symmetric Cryptography
GroupAPT33

APT33 has used AES for encryption of command and control traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.