ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareNinja

Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests.

T1001
Data Obfuscation
MalwareSystemBC

SystemBC has encoded with XOR and encrypted with RC4 its beacon.

T1001
Data Obfuscation
MalwareFlawedAmmyy

FlawedAmmyy may obfuscate portions of the initial C2 handshake.

T1001
Data Obfuscation
MalwareRDAT

RDAT has used encoded data within subdomains as AES ciphertext to communicate from the host to the C2.

T1001
Data Obfuscation
MalwareOkrum

Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests.

T1001
Data Obfuscation
MalwareDarkGate

DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining.

T1001
Data Obfuscation
MalwareStrelaStealer

StrelaStealer encrypts the payload of HTTP POST communications using the same XOR key used for the malware's DLL payload.

T1001
Data Obfuscation
MalwareFRAMESTING

FRAMESTING can send and receive zlib compressed data within `POST` requests.

T1001
Data Obfuscation
MalwareTrailBlazer

TrailBlazer can masquerade its C2 traffic as legitimate Google Notifications HTTP requests.

T1001
Data Obfuscation
MalwareFunnyDream

FunnyDream can send compressed and obfuscated packets to C2.

T1001
Data Obfuscation
MalwareSideTwist

SideTwist can embed C2 responses in the source code of a fake Flickr webpage.

T1001
Data Obfuscation
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has hashed a string containing system information prior to exfiltration via POST requests.

T1001
Data Obfuscation
Toolevilginx2

evilginx2 can modify the Origin and Referrer fields in HTTPS headers it relays between intended victims and legitimate websites to comply with cross-origin resource sharing (CORS) restrictions.

T1001.001
Junk Data
MalwareDowndelph

Downdelph inserts pseudo-random characters between each original character during encoding of C2 network requests, making it difficult to write signatures on them.

T1001.001
Junk Data
MalwareUPSTYLE

UPSTYLE retrieves a non-existent webpage from the command and control server then parses commands from the resulting error logs to decode commands to the web shell.

T1001.001
Junk Data
MalwareTurian

Turian can insert pseudo-random characters into its network encryption setup.

T1001.001
Junk Data
MalwareWellMess

WellMess can use junk data in the Base64 string for additional obfuscation.

T1001.001
Junk Data
MalwareGoldMax

GoldMax has used decoy traffic to surround its malicious network traffic to avoid detection.

T1001.001
Junk Data
MalwareBeaverTail

BeaverTail has added junk data or a dummy character prepended to a string to hamper decoding attempts.

T1001.001
Junk Data
MalwareLODEINFO

LODEINFO can append C2 communication with randomly generated junk data.

T1001.001
Junk Data
MalwareP8RAT

P8RAT can send randomly-generated data as part of its C2 communication.

T1001.001
Junk Data
MalwareMori

Mori has obfuscated the FML.dll with 200MB of junk data.

T1001.001
Junk Data
MalwareBendyBear

BendyBear has used byte randomization to obscure its behavior.

T1001.001
Junk Data
MalwareUroburos

Uroburos can add extra characters in encoded strings to help mimic DNS legitimate requests.

T1001.001
Junk Data
MalwareSUNBURST

SUNBURST added junk bytes to its C2 over HTTP.

T1001.001
Junk Data
MalwareP2P ZeuS

P2P ZeuS added junk data to outgoing UDP packets to peer implants.

T1001.001
Junk Data
MalwarePLEAD

PLEAD samples were found to be highly obfuscated with junk code.

T1001.001
Junk Data
MalwareTrailBlazer

TrailBlazer has used random identifier strings to obscure its C2 operations and result codes.

T1001.001
Junk Data
MalwareGrimAgent

GrimAgent can pad C2 messages with random generated values.

T1001.001
Junk Data
MalwareKevin

Kevin can generate a sequence of dummy HTTP C2 requests to obscure traffic.

T1001.002
Steganography
MalwareLunarWeb

LunarWeb can receive C2 commands hidden in the structure of .jpg and .gif images.

T1001.002
Steganography
MalwareHAMMERTOSS

HAMMERTOSS is controlled via commands that are appended to image files.

T1001.002
Steganography
ToolSliver

Sliver can encode binary data into a .PNG file for C2 communication.

T1001.002
Steganography
MalwareZox

Zox has used the .PNG file format for C2 communications.

T1001.002
Steganography
MalwareLightNeuron

LightNeuron is controlled via commands that are embedded into PDFs and JPGs using steganographic methods.

T1001.002
Steganography
MalwareZeroT

ZeroT has retrieved stage 2 payloads as Bitmap images that use Least Significant Bit (LSB) steganography.

T1001.002
Steganography
MalwareDaserf

Daserf can use steganography to hide malicious code downloaded to the victim.

T1001.002
Steganography
MalwareRDAT

RDAT can process steganographic images attached to email messages to send and receive C2 commands. RDAT can also embed additional messages within BMP images to communicate with the RDAT operator.

T1001.002
Steganography
MalwareLunarMail

LunarMail can parse IDAT chunks from .png files to look for zlib-compressed and AES encrypted C2 commands.

T1001.002
Steganography
MalwareDuqu

When the Duqu command and control is operating over HTTP or HTTPS, Duqu uploads data to its controller by appending it to a blank JPG file.

T1001.002
Steganography
MalwareSUNBURST

SUNBURST C2 data attempted to appear as benign XML related to .NET assemblies or as a faux JSON blob.

T1001.003
Protocol or Service Impersonation
MalwareNinja

Ninja has the ability to mimic legitimate services with customized HTTP URL paths and headers to hide malicious traffic.

T1001.003
Protocol or Service Impersonation
MalwareBankshot

Bankshot generates a false TLS handshake using a public certificate to disguise C2 network communications.

T1001.003
Protocol or Service Impersonation
MalwareTONESHELL

TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3.

T1001.003
Protocol or Service Impersonation
MalwareBOOKWORM

BOOKWORM has modified HTTP POST requests to resemble legitimate communications.

T1001.003
Protocol or Service Impersonation
MalwarePUBLOAD

PUBLOAD has modified HTTP POST requests to resemble legitimate communications. PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03.

T1001.003
Protocol or Service Impersonation
MalwareInvisiMole

InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP.

T1001.003
Protocol or Service Impersonation
MalwareOkrum

Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests.

T1001.003
Protocol or Service Impersonation
MalwareKeyBoy

KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic.

T1001.003
Protocol or Service Impersonation
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE has used FakeTLS for session authentication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.