Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
MalwareLunarWeb | LunarWeb can receive C2 commands hidden in the structure of .jpg and .gif images. |
| T1001.002 Steganography |
MalwareHAMMERTOSS | HAMMERTOSS is controlled via commands that are appended to image files. |
| T1001.002 Steganography |
ToolSliver | Sliver can encode binary data into a .PNG file for C2 communication. |
| T1001.002 Steganography |
MalwareZox | Zox has used the .PNG file format for C2 communications. |
| T1001.002 Steganography |
MalwareLightNeuron | LightNeuron is controlled via commands that are embedded into PDFs and JPGs using steganographic methods. |
| T1001.002 Steganography |
MalwareZeroT | ZeroT has retrieved stage 2 payloads as Bitmap images that use Least Significant Bit (LSB) steganography. |
| T1001.002 Steganography |
MalwareDaserf | Daserf can use steganography to hide malicious code downloaded to the victim. |
| T1001.002 Steganography |
MalwareRDAT | RDAT can process steganographic images attached to email messages to send and receive C2 commands. RDAT can also embed additional messages within BMP images to communicate with the RDAT operator. |
| T1001.002 Steganography |
MalwareLunarMail | LunarMail can parse IDAT chunks from .png files to look for zlib-compressed and AES encrypted C2 commands. |
| T1001.002 Steganography |
MalwareDuqu | When the Duqu command and control is operating over HTTP or HTTPS, Duqu uploads data to its controller by appending it to a blank JPG file. |
| T1001.002 Steganography |
MalwareSUNBURST | SUNBURST C2 data attempted to appear as benign XML related to .NET assemblies or as a faux JSON blob. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.