ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1001.002×

11 examples

TechniqueUsed byProcedure example
T1001.002
Steganography
MalwareLunarWeb

LunarWeb can receive C2 commands hidden in the structure of .jpg and .gif images.

T1001.002
Steganography
MalwareHAMMERTOSS

HAMMERTOSS is controlled via commands that are appended to image files.

T1001.002
Steganography
ToolSliver

Sliver can encode binary data into a .PNG file for C2 communication.

T1001.002
Steganography
MalwareZox

Zox has used the .PNG file format for C2 communications.

T1001.002
Steganography
MalwareLightNeuron

LightNeuron is controlled via commands that are embedded into PDFs and JPGs using steganographic methods.

T1001.002
Steganography
MalwareZeroT

ZeroT has retrieved stage 2 payloads as Bitmap images that use Least Significant Bit (LSB) steganography.

T1001.002
Steganography
MalwareDaserf

Daserf can use steganography to hide malicious code downloaded to the victim.

T1001.002
Steganography
MalwareRDAT

RDAT can process steganographic images attached to email messages to send and receive C2 commands. RDAT can also embed additional messages within BMP images to communicate with the RDAT operator.

T1001.002
Steganography
MalwareLunarMail

LunarMail can parse IDAT chunks from .png files to look for zlib-compressed and AES encrypted C2 commands.

T1001.002
Steganography
MalwareDuqu

When the Duqu command and control is operating over HTTP or HTTPS, Duqu uploads data to its controller by appending it to a blank JPG file.

T1001.002
Steganography
MalwareSUNBURST

SUNBURST C2 data attempted to appear as benign XML related to .NET assemblies or as a faux JSON blob.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.