Real-world descriptions of how a group, tool or campaign used a technique.
114 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1132.001 Standard Encoding |
MalwareTrickBot | TrickBot can Base64-encode C2 commands. |
| T1132.001 Standard Encoding |
MalwareBLINDINGCAN | BLINDINGCAN has encoded its C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwarePikabot | Pikabot uses base64 encoding in conjunction with symmetric encryption mechanisms to obfuscate command and control communications. |
| T1132.001 Standard Encoding |
MalwareSpark | Spark has encoded communications with the C2 server with base64. |
| T1132.001 Standard Encoding |
MalwareBumblebee | Bumblebee has the ability to base64 encode C2 server responses. |
| T1132.001 Standard Encoding |
MalwareBRICKSTORM | BRICKSTORM has leveraged Base64 to encode C2 communications. |
| T1132.001 Standard Encoding |
MalwareTorisma | Torisma has encoded C2 communications with Base64. |
| T1132.001 Standard Encoding |
MalwareBackdoor.Oldrea | Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers. |
| T1132.001 Standard Encoding |
MalwareStuxnet | Stuxnet transforms encrypted binary data into an ASCII string in order to use it as a URL parameter value. |
| T1132.001 Standard Encoding |
MalwareRotaJakiro | RotaJakiro uses ZLIB Compression to compresses data sent to the C2 server in the `payload` section network communication packet. |
| T1132.001 Standard Encoding |
MalwarePOWRUNER | POWRUNER can use base64 encoded C2 communications. |
| T1132.001 Standard Encoding |
MalwareSardonic | Sardonic can encode client ID data in 32 uppercase hex characters and transfer to the actor-controlled C2 server. |
| T1132.001 Standard Encoding |
MalwareMisdat | Misdat network traffic is Base64-encoded plaintext. |
| T1132.001 Standard Encoding |
MalwareTAMECAT | TAMECAT has encoded C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareFelismus | Some Felismus samples use a custom method for C2 traffic that utilizes Base64. |
| T1132.001 Standard Encoding |
MalwarexCaon | xCaon has used Base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwareGomir | Gomir uses Base64-encoded content in HTTP communications to command and control infrastructure. |
| T1132.001 Standard Encoding |
MalwareEmotet | Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Additionally, Emotet has used Base64 to encode data before sending to the C2 server. |
| T1132.001 Standard Encoding |
MalwareMachete | Machete has used base64 encoding. |
| T1132.001 Standard Encoding |
MalwarePrikormka | Prikormka encodes C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareGootloader | Gootloader can retrieve a Base64 encoded stager from C2. |
| T1132.001 Standard Encoding |
MalwarePingPull | PingPull can encode C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareWellMess | WellMess has used Base64 encoding to uniquely identify communication to and from the C2. |
| T1132.001 Standard Encoding |
MalwareMafalda | Mafalda can encode data using Base64 prior to exfiltration. |
| T1132.001 Standard Encoding |
MalwareSquirrelwaffle | Squirrelwaffle has encoded its communications to C2 servers using Base64. |
| T1132.001 Standard Encoding |
MalwareHOPLIGHT | HOPLIGHT has utilized Zlib compression to obfuscate the communications payload. |
| T1132.001 Standard Encoding |
MalwareRDAT | RDAT can communicate with the C2 via base32-encoded subdomains. |
| T1132.001 Standard Encoding |
MalwareOkrum | Okrum has used base64 to encode C2 communication. |
| T1132.001 Standard Encoding |
MalwareRustyWater | RustyWater has encoded collected data with Base64. |
| T1132.001 Standard Encoding |
MalwareFysbis | Fysbis can use Base64 to encode its C2 traffic. |
| T1132.001 Standard Encoding |
MalwarePowerShower | PowerShower has the ability to encode C2 communications with base64 encoding. |
| T1132.001 Standard Encoding |
MalwareKazuar | Kazuar encodes communications to the C2 server in Base64. |
| T1132.001 Standard Encoding |
MalwareGLASSTOKEN | GLASSTOKEN has hexadecimal and Base64 encoded C2 content. |
| T1132.001 Standard Encoding |
MalwareFlagpro | Flagpro has encoded bidirectional data communications between a target system and C2 server using Base64. |
| T1132.001 Standard Encoding |
MalwareCORESHELL | CORESHELL C2 messages are Base64-encoded. |
| T1132.001 Standard Encoding |
MalwareDarkWatchman | DarkWatchman encodes data using hexadecimal representation before sending it to the C2 server. |
| T1132.001 Standard Encoding |
MalwareBisonal | Bisonal has encoded binary data with Base64 and ASCII. |
| T1132.001 Standard Encoding |
MalwareS-Type | S-Type uses Base64 encoding for C2 traffic. |
| T1132.001 Standard Encoding |
MalwareSeaDuke | SeaDuke C2 traffic is base64-encoded. |
| T1132.001 Standard Encoding |
MalwareBS2005 | BS2005 uses Base64 encoding for communication in the message body of an HTTP request. |
| T1132.001 Standard Encoding |
MalwareMongall | Mongall can use Base64 to encode information sent to its C2. |
| T1132.001 Standard Encoding |
MalwareLockBit 3.0 | LockBit 3.0 can Base64-encode C2 communication. |
| T1132.001 Standard Encoding |
MalwareCarbanak | Carbanak encodes the message body of HTTP traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareElise | Elise exfiltrates data using cookie values that are Base64-encoded. |
| T1132.001 Standard Encoding |
MalwareLatrodectus | Latrodectus has Base64-encoded the message body of a HTTP request sent to C2. |
| T1132.001 Standard Encoding |
MalwareSaint Bot | Saint Bot has used Base64 to encode its C2 communications. |
| T1132.001 Standard Encoding |
MalwareChaes | Chaes has used Base64 to encode C2 communications. |
| T1132.001 Standard Encoding |
MalwareCharmPower | CharmPower can send additional modules over C2 encoded with base64. |
| T1132.001 Standard Encoding |
MalwareSMOKEDHAM | SMOKEDHAM has encoded its C2 traffic with Base64. |
| T1132.001 Standard Encoding |
MalwareMori | Mori can use Base64 encoded JSON libraries used in C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.