Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareNinja | Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests. |
| T1001 Data Obfuscation |
MalwareSystemBC | SystemBC has encoded with XOR and encrypted with RC4 its beacon. |
| T1001 Data Obfuscation |
MalwareFlawedAmmyy | FlawedAmmyy may obfuscate portions of the initial C2 handshake. |
| T1001 Data Obfuscation |
MalwareRDAT | RDAT has used encoded data within subdomains as AES ciphertext to communicate from the host to the C2. |
| T1001 Data Obfuscation |
MalwareOkrum | Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests. |
| T1001 Data Obfuscation |
MalwareDarkGate | DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining. |
| T1001 Data Obfuscation |
MalwareStrelaStealer | StrelaStealer encrypts the payload of HTTP POST communications using the same XOR key used for the malware's DLL payload. |
| T1001 Data Obfuscation |
MalwareFRAMESTING | FRAMESTING can send and receive zlib compressed data within `POST` requests. |
| T1001 Data Obfuscation |
MalwareTrailBlazer | TrailBlazer can masquerade its C2 traffic as legitimate Google Notifications HTTP requests. |
| T1001 Data Obfuscation |
MalwareFunnyDream | FunnyDream can send compressed and obfuscated packets to C2. |
| T1001 Data Obfuscation |
MalwareSideTwist | SideTwist can embed C2 responses in the source code of a fake Flickr webpage. |
| T1001 Data Obfuscation |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has hashed a string containing system information prior to exfiltration via POST requests. |
| T1001 Data Obfuscation |
Toolevilginx2 | evilginx2 can modify the Origin and Referrer fields in HTTPS headers it relays between intended victims and legitimate websites to comply with cross-origin resource sharing (CORS) restrictions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.