Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareNinja | Ninja has the ability to mimic legitimate services with customized HTTP URL paths and headers to hide malicious traffic. |
| T1001.003 Protocol or Service Impersonation |
MalwareBankshot | Bankshot generates a false TLS handshake using a public certificate to disguise C2 network communications. |
| T1001.003 Protocol or Service Impersonation |
MalwareTONESHELL | TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3. |
| T1001.003 Protocol or Service Impersonation |
MalwareBOOKWORM | BOOKWORM has modified HTTP POST requests to resemble legitimate communications. |
| T1001.003 Protocol or Service Impersonation |
MalwarePUBLOAD | PUBLOAD has modified HTTP POST requests to resemble legitimate communications. PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03. |
| T1001.003 Protocol or Service Impersonation |
MalwareInvisiMole | InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP. |
| T1001.003 Protocol or Service Impersonation |
MalwareOkrum | Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests. |
| T1001.003 Protocol or Service Impersonation |
MalwareKeyBoy | KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic. |
| T1001.003 Protocol or Service Impersonation |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE has used FakeTLS for session authentication. |
| T1001.003 Protocol or Service Impersonation |
MalwareUroburos | Uroburos can use custom communication methodologies that ride over common protocols including TCP, UDP, HTTP, SMTP, and DNS in order to blend with normal network traffic. |
| T1001.003 Protocol or Service Impersonation |
MalwareBADCALL | BADCALL uses a FakeTLS method during C2. |
| T1001.003 Protocol or Service Impersonation |
MalwareCobalt Strike | Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic. |
| T1001.003 Protocol or Service Impersonation |
MalwareSUNBURST | SUNBURST masqueraded its network traffic as the Orion Improvement Program (OIP) protocol. |
| T1001.003 Protocol or Service Impersonation |
MalwareFakeM | FakeM C2 traffic attempts to evade detection by resembling data generated by legitimate messenger applications, such as MSN and Yahoo! messengers. Additionally, some variants of FakeM use modified SSL code for communications back to C2 servers, making SSL decryption ineffective. |
| T1001.003 Protocol or Service Impersonation |
MalwareFRAMESTING | FRAMESTING uses a cookie named `DSID` to mimic the name of a cookie used by Ivanti Connect Secure appliances for maintaining VPN sessions. |
| T1001.003 Protocol or Service Impersonation |
MalwareHARDRAIN | HARDRAIN uses FakeTLS to communicate with its C2 server. |
| T1001.003 Protocol or Service Impersonation |
MalwareStarProxy | StarProxy has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. StarProxy used FakeTLS to communicate with its C2 server. |
| T1001.003 Protocol or Service Impersonation |
MalwareFALLCHILL | FALLCHILL uses fake Transport Layer Security (TLS) to communicate with its C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.